UnitedHealth CEO tells lawmakers the company paid hackers a $22 million ransom

UnitedHealth CEO Andrew Witty testifies before the Senate Finance Committee on Capitol Hill on May 1, 2024 in Washington, DC. Kent Nishimura | Getty Images

UnitedHealth Group CEO Andrew Witty confirmed for the first time that the company paid a $22 million ransom to hackers who breached its subsidiary Change Healthcare and caused widespread fallout across the health-care sector. Witty's comments were made during a Wednesday hearing before the U.S. Senate Committee on Finance.

Change Healthcare provides payment, revenue management and other solutions like e-prescription software. The company disconnected affected systems when the threat was detected, leaving many doctors temporarily unable to fill prescriptions or get paid for their services.

UnitedHealth told CNBC in April that it paid a ransom to try and protect patient data. Earlier reports had discovered a $22 million transfer on Bitcoin's blockchain, but the company had not confirmed the figure until now.

“The decision to pay a ransom was mine,” Witty said. “This was one of the hardest decisions I've ever had to make, and I wouldn't wish it on anyone.”

UnitedHealth is one of the largest companies in the world, with a roughly $450 billion market cap. Its business unit Optum — which provides care to 103 million customers — and Change Healthcare — which touches one in three patient records — merged in 2022.

Committee Chairman Sen. Ron Wyden, D-Ore., said in his opening remarks that the Change Healthcare breach serves as a “dire warning about the consequences of too-big-to-fail mega-corporations.”

“Companies that are so big have an obligation to protect their customers and to lead on this issue,” Wyden said.

Witty told the committee that cybercriminals accessed Change Healthcare through a server that was not protected by multi-factor authentication, or MFA, which requires users to verify their identity in at least two different ways. He said UnitedHealth now has MFA in place across all external-facing systems.

“As a result of this malicious cyberattack, patients and providers have experienced disruptions and people are worried about their private health data,” Witty said. “To all those impacted, let me be very clear: I am deeply, deeply sorry.”

Sen. Thom Tillis, R-N.C., held up a bright yellow copy of “Hacking for Dummies” during the hearing, saying the breach is UnitedHealth's responsibility to fix.

“This is some basic stuff that was missed, so shame on internal audit, external audit and your systems folks tasked with redundancy, they're not doing their job,” Tillis said.

A filing with the U.S. Securities and Exchange Commission said that UnitedHealth discovered that a cyber threat actor accessed part of Change Healthcare's information technology network in late February.

Witty said Change Healthcare's core systems are back online, though some of its secondary support functions are still being restored.

UnitedHealth said in February that the ransomware group Blackcat was behind the attack. Blackcat, which also goes by the names Noberus and ALPHV, steals sensitive data from institutions and threatens to publish it unless a ransom is paid, according to a December release from the U.S. Department of Justice.

UnitedHealth confirmed in April that files containing protected health information and personally identifiable information were compromised in the breach. The company said a data review is ongoing, so it could be months before the company can notify affected individuals.

Witty said Wednesday that UnitedHealth is working with regulators to assess the breach and to inform people if their information has been compromised “as soon as possible.”

Early in March, UnitedHealth launched a temporary funding assistance program to help support providers that have experienced cash flow disruptions due to the cyberattack. There are no fees, interest or other costs on top of the payments, and providers have 45 days to repay the funds once their standard payment operations resume.

During the hearing, Witty said the company has not yet asked anyone for loan repayments, and it will be up to providers to determine when their operations have officially returned to normal.

Witty did not directly disclose whether UnitedHealth will provide additional support to providers who may be contending with other loans and interest payments because of the breach.

Sen. Michael Bennet, D-Colo., pressed Witty to share how UnitedHealth is working to ensure something like the Change Healthcare breach will not happen again. Witty said the company plans to share what it discovers about the breach with others, adding that there's a need to focus on reducing the rate of cyberattacks on the health-care sector.

“We are clearly trying to take our responsibility in this attack. We are also trying to learn from it,” he said.

Don’t miss these exclusives from CNBC PRO

  • Wednesday's biggest analyst calls: Apple, Nvidia, Amazon, Tesla, 3M, Pinterest, AMD, Meta and more 
  • Apple reports earnings Thursday. Here's a no-cost options trade to capitalize on a possible bounce
  • Here's where to invest $1 million right now, according to the pros 
  • This bitcoin miner and Nvidia AI cloud partner's stock could go up 50%, Berenberg says

OTHER NEWS

3 hrs ago

I work at Walmart - here are the 8 shopping secrets that will save you $100s or more

3 hrs ago

'Devastated' Chris Pratt pays tribute to his Guardians of the Galaxy stunt double Tony McFarr following his 'unexpected and shocking' death aged 47

3 hrs ago

Video: Christina Hall and Heather El Moussa again tease their new HGTV series The Flip Off by joking 'you thought one bad b***h was trouble? Try two'

3 hrs ago

Video: Rosie Huntington-Whiteley shares sweet snaps with her children in her glam white outfit after attending Buckingham Palace garden party

3 hrs ago

Video: Kelly Clarkson recalls her impromptu karaoke session with Amy Winehouse whose voice blew her away just before the singer got famous

3 hrs ago

Family Crisis trailer: Mama June and her daughters Alana 'Honey Boo Boo' Thompson and Lauryn 'Pumpkin' Efrid  get emotional as they grieve the death of Anna 'Chickadee' Cardwell at age 29

3 hrs ago

Jane Lynch claims the Glee cast 'liked each other very much'... DESPITE feud between Lea Michele and Naya Rivera and toxic workplace allegations - as she reflects on deaths of co-stars

3 hrs ago

Madonna, 65, stuns in low-cut dress and dazzling necklace as she poses in glammed-up snaps... after ending Celebration Tour

3 hrs ago

Shogun is in the works for TWO more seasons after FX series received critical-acclaim and cult following

3 hrs ago

Apple's iMessage is DOWN: Thousands of people report outage

3 hrs ago

Video: Bridgerton series 3 makes huge leap into Netflix's top 10 most-watched shows list less than 24 hours after premiering

3 hrs ago

Michael Cohen is torn to shreds by Trump's attorneys in blistering cross-examination over Stormy Daniels' 'hush money' payments

3 hrs ago

NYS pushes to boot Boeing bigwigs, block executive raises using pension fund after series of company mishaps

3 hrs ago

Anti-Israel protesters aren’t really scared of COVID — they’re hiding shame of their prejudice

3 hrs ago

Owning a Frank Lloyd Wright home is now slightly less rare — but there’s a twist

3 hrs ago

MasterChef viewers accuse show of 'celebrating the murder and dismemberment of women' as fire-breathing contestant makes Jack The Ripper-inspired dish

3 hrs ago

Phil Foden picks up his FWA Footballer of the Year trophy after spearheading Man City's Premier League title tilt... as frontrunners sit in pole position ahead of the season's final day

3 hrs ago

Nathan Buckley's ex-wife Tania sparks engagement rumours as she flashes huge diamond ring while stepping out in Melbourne with new partner Marco Kelly

3 hrs ago

Pregnant Jenna Dewan puts her bump on display in figure-hugging dress amid battle over ex Channing Tatum's earnings from Magic Mike

3 hrs ago

Britain's Got Talent SPOILER: Judges get more than they bargained for as they are shocked by a group of raunchy stripping jugglers

3 hrs ago

California city becomes ground zero of America's border crisis with more crossings than any other region

3 hrs ago

Tyra Banks, 50, flashes her cleavage in gold dress in sizzling new video taken after she shot Sports Illustrated Swimsuit Issue comeback

3 hrs ago

ALISON BOSHOFF: Liz Taylor's shocking claim from beyond the grave...

3 hrs ago

Jessica Simpson, 43, shows off her very toned legs in short shorts and platform heels... after sharing she does 14K steps a day to stay thin

3 hrs ago

Jessica Biel talks how she finds time with Justin Timberlake amid his tour and her demanding Hollywood career: 'It's always a work in progress'

3 hrs ago

Joe Alwyn continues to put on a defiant display as he attends cocktail party during Cannes Film Festival - after ex Taylor Swift savaged him in new album

3 hrs ago

King Charles looks dapper as he attends special gala performance at the Royal Opera House for out-going Music Director Sir Antonio Pappano - who conducted the monarch's Coronation Orchestra

3 hrs ago

Universal unveils Five Nights At Freddy's 2 release date... as it pushes back sequels to fellow horror hits M3GAN and The Black Phone

3 hrs ago

White House's Jean-Pierre answers questions on Biden's executive privilege claim

3 hrs ago

‘Sleepy Joe’ versus ‘The Donald’: Letters to the Editor — May 17, 2024

3 hrs ago

DA Alvin Bragg lets NYC crime run rampant as he pursues empty case against Trump

3 hrs ago

Runaway goats and sheep invade Virginia interstate after mysterious escape: cops

3 hrs ago

Fani Willis investigated by GOP senators over alleged abuse of federal funds

3 hrs ago

The unspoken Glyndebourne dress code and how to get it right

3 hrs ago

Harry and Paul from The Traitors S2 walk the Bafta TV Awards carpet

3 hrs ago

Sen. Chuck Grassley calls Trump trial a 'political lynching' but says he's too busy to go

3 hrs ago

Chancellor promises further tax cuts if Tories win general election

3 hrs ago

Canada eases past Norway at hockey worlds, U.S. shuts out France

3 hrs ago

Common Problems A 2005 Jeep Grand Cherokee May Have (And The Cost To Fix Them)

3 hrs ago

Yankees' Hal Steinbrenner shares massive Juan Soto contract update