Change Healthcare cyberattack was due to a lack of multifactor authentication, UnitedHealth CEO says
The beginning of the Change Healthcare cyberattack happened when hackers entered a server that lacked multifactor authentication
By Tom Murphy
Published - May 01, 2024, 01:12 PM ET
Last Updated - May 27, 2024, 01:04 AM EDT
The Change Healthcare cyberattack that disrupted health care systems nationwide earlier this year started when hackers entered a server that lacked a basic form of security: multifactor authentication.
UnitedHealth CEO Andrew Witty said Wednesday in a U.S. Senate hearing that his company, which owns Change Healthcare, is still trying to understand why the server did not have the additional protection.
“This hack could have been stopped with cybersecurity 101,” Oregon Democratic Sen. Ron Wyden told Witty.