Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Ransomware

Change Healthcare Restores Pharmacy Services Disrupted by Ransomware

Change Healthcare says it has made significant progress in restoring systems impacted by a recent ransomware attack.

Change Healthcare parent company UnitedHealth Group says it has restored pharmacy services disrupted by a BlackCat ransomware attack more than two weeks ago.

In an incident update on Thursday, the company revealed that it continues to work aggressively on restoring its systems and services and that key functionality is coming back online.

“Electronic prescribing is now fully functional with claim submission and payment transmission also available as of today. All major pharmacy claims and payment systems are back up and functioning,” the company said.

According to the company, electronic payment functionality will remain down for another week, but will become available for connection on March 15.

Systems related to medical claims, however, will take longer to restore, UnitedHealth Group said: “we expect to begin testing and reestablish connectivity to our claims network and software on March 18, restoring service through that week.”

“While we work to restore these systems, we strongly recommend our provider and payer clients use the applicable workarounds we have established—in particular, using our new iEDI claim submission system in the interest of system redundancy given the current environment,” UnitedHealth Group also said.

Advertisement. Scroll to continue reading.

The February 21 cyberattack took down the Change Healthcare claims and payment infrastructure with a devastating impact on the US health system, preventing over 7,000 pharmacies and hospitals from processing prescriptions.

On Monday, the US Department of Health and Human Services (HHS) announced the actions it was taking to assist healthcare providers impacted by the incident, which has been attributed to the BlackCat ransomware group.

BlackCat reportedly received a $22 million ransom payment from Change Healthcare and pulled an exit scam, refusing to share the proceeds with the affiliate who perpetrated the intrusion and who claims to be in the possession of four terabytes of data stolen from the healthcare technology company.

Related: Critical Infrastructure Organizations Warned of Phobos Ransomware Attacks

Related: German Steelmaker Thyssenkrupp Confirms Ransomware Attack

Related: LoanDepot Ransomware Attack Exposed 16.9 Million Individuals

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

GDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.