Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • Senate Prepares to Debate House Surveillance Bill
    • FTC to Settle Privacy Complaint Against Telehealth Firm
    • HOUSE NEWS—UnitedHealth’s ‘anticompetitive practices’ a key theme during House hearing on Change Health breach
    • Organizations Urge Administration to Oppose Digital Trade Barriers
    • U.K.’s ICO Offers Guidance on Health Care Data Transparency
    • Wisconsin Lawmakers Fail to Pass Data Privacy Bill
    • ‘Five Eyes’ Allies Warn of AI Security Threats
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, HOUSE NEWS—UnitedHealth’s ‘anticompetitive practices’ a key theme during House hearing on Change Health breach, (Apr 16, 2024)

    Organizations Mentioned:Change Healthcare | College of Healthcare Information Management Executives | Healthcare Sector Coordinating Council | Texas Spine Center | UnitedHealth

    By Sheila Lynch-Afryl, J.D., M.A.

    Several members of the House Energy and Commerce Committee also sent a letter to UnitedHealth with a list of detailed questions on the Change Healthcare cyberattack.

    With the health sector still recovering from the Change Healthcare cyberattack, membe ...

    By Sheila Lynch-Afryl, J.D., M.A.

    Several members of the House Energy and Commerce Committee also sent a letter to UnitedHealth with a list of detailed questions on the Change Healthcare cyberattack.

    With the health sector still recovering from the Change Healthcare cyberattack, members of the House Energy and Commerce Committee questioned how to prevent future attacks during an April 16 hearing, “Examining Health Sector Cybersecurity in the Wake of the Change Healthcare Attack.” A recurring theme throughout the Health Subcommittee hearing was how consolidation throughout the health system increases cybersecurity risks; Ranking Member Anna Eshoo (D-Cal.) commented that the attack shows that UnitedHealth’s “anticompetitive practices present a national security risk because its operations now extend through every point in our health care system.” While five industry experts testified, multiple representatives lamented UnitedHealth’s and Change Healthcare’s absence at the hearing.

    Witness Greg Garcia, Executive Director for Cybersecurity, Healthcare Sector Coordinating Council, made recommendations for staying ahead of future similar incidents and reducing their likelihood and impact: (1) perform a health infrastructure mapping and risk assessment; (2) assess consolidation proposals for mergers and acquisitions against their potential for increased cyber risk; (3) hold third-party product and service providers and business associates to a standard of “secure by design and secure by default” for technology used in health care infrastructure; (4) invest in a government-industry rapid response capability; and (5) invest in a cyber safety net for underserved providers.

    Scott MacLean, Board Chair, College of Healthcare Information Management Executives, recommended that the federal government provide funding for small and under resourced health care organizations to protect themselves against or respond to cybersecurity threats, as well as funding to help implement HHS’ Cyber Performance Goals. He also requested safe harbors for information sharing concerning a cybersecurity incident and that third parties and payers be required to share responsibility for cybersecurity incidents. In addition, he suggested that high-impact cyberattacks resulting in the disruption of care at safety net hospitals be designated as “all hazards” incidents to activate FEMA and other government response support services.

    Adam Bruggeman, MD, an orthopedic surgeon at the Texas Spine Center, testified about the challenges his practice faced in submitting claims, receiving electronic remittance advice from insurers, and reconciling payments with patient accounts after the Change cyberattack. He urged Congress to clarify agencies’ authority to respond to future disruptions and ensure that CMS and HHS “can quickly deploy financial lifelines to physician practices in times of emergency.” In addition, he urged Congress to examine the impact of market consolidation on patient care: “Now we are also seeing how consolidating more of our health care spending around a single point of failure can make the situation more severe, more costly, and harder to fix when something goes wrong.”

    Letter. In addition, on April 15 several members of the committee sent a letter to UnitedHealth with a list of detailed questions on various aspects of the cyberattack. Responses are due April 29.

    Companies: UnitedHealth; Change Healthcare; Healthcare Sector Coordinating Council; College of Healthcare Information Management Executives; Texas Spine Center

    MainStory: NewsStory HouseNews ComplianceNews BillingNews CMSNews DMENews DrugBiologicNews EHRNews IPPSNews PartANews PartBNews PartCNews PartDNews QualityNews CyberPrivacyFeed LegislativeRegulatoryActivity DataPrivacy DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use