Patient data was stolen in a hack. Senators say no one told the patients about it
CNN
A bipartisan pair of senators is accusing a major health care firm that suffered a crippling cyberattack in February of not complying with federal law that requires patients be notified when their data is stolen.
A bipartisan pair of senators is accusing a major health care firm that suffered a crippling cyberattack in February of not complying with federal law that requires patients be notified when their data is stolen. In a letter sent to UnitedHealth Group CEO Andrew Witty this week, New Hampshire Democratic Sen. Maggie Hassan and Tennessee Republican Sen. Marsha Blackburn demanded that the health care giant “assume full and immediate responsibility” for giving patients and health providers information on the breach. Federal law known as the Health Information Portability and Accountability Act (HIPAA) generally requires health care providers to notify people within 60 days of discovering a breach affecting their personal health data. The Department of Health and Human Services is already investigating whether UnitedHealth is compliant with HIPAA obligations to protect patient data. The department can’t discuss ongoing investigations, an HHS spokesperson told CNN. HHS can use HIPAA to fine companies for failing to protect patient data. The department announced a $4.75 million settlement in February with a nonprofit hospital system in New York for “data security failures” that the department said resulted in an employee stealing and selling patient data. But the cleanup from the ransomware attack on Change Healthcare, a UnitedHealth subsidiary, has been unusually messy and complicated compared to other ransomware attacks on the health sector. The hack paralyzed computers that Change Healthcare uses to process medical claims across the country. Health care providers were cut off from billions of dollars in payments, according to one hospital association, and some health clinics were on the brink of bankruptcy because they couldn’t get paid.