Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • FCC Seeks Input on Boosting BGP Security
    • Australia Files Civil Penalty Proceeding Against Medibank
    • Canada’s OPC Report on Strategic Priorities
    • FCC Sets Up Schools, Libraries Cybersecurity Pilot Program
    • SENATE NEWS: Senate Finance Committee chair urges HHS to ‘take immediate, enforceable steps’ on health cybersecurity
    • Spain Highlights Its GDPR Compliance Tools
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, SENATE NEWS: Senate Finance Committee chair urges HHS to ‘take immediate, enforceable steps’ on health cybersecurity, (Jun 6, 2024)

    Organizations Mentioned:Change Healthcare | UnitedHealth Group

    By Sheila Lynch-Afryl, J.D., M.A.

    Senate Finance Committee Chair Ron Wyden (D-Ore.) said that HHS’ current approach of “allowing the health sector to self-regulate cybersecurity” is insufficient.

    In the wake of the Change Healthcare cyberattack, Senate Finance Com ...

    By Sheila Lynch-Afryl, J.D., M.A.

    Senate Finance Committee Chair Ron Wyden (D-Ore.) said that HHS’ current approach of “allowing the health sector to self-regulate cybersecurity” is insufficient.

    In the wake of the Change Healthcare cyberattack, Senate Finance Committee Chair Ron Wyden (D-Ore.) criticized HHS’ current approach to health care cybersecurity—which he described as self-regulation and voluntary best practices—as “woefully inadequate,” leaving the health care system “vulnerable to criminals and foreign government hackers.” He took particular issue with the fact that HHS does not require health care organizations to use multi-factor authentication, a “basic cybersecurity defense” required by other industries. He urged HHS to mandate minimum technical cybersecurity standards and resiliency requirements for “systemically important entities.”

    At a May 1 Senate Finance Committee hearing, Andrew Witty, CEO of UnitedHealth Group (UHG), testified that the compromised Change Healthcare Citrix portal did not have multi-factor authentication. He said that UHG’s policy is to have multi-factor authentication for externally facing systems, but when it acquired Change 1.5 years ago it had older technology that UHG was in the process of upgrading. In his letter, Wyden argued that the Change ransomware attack could have been prevented with the use of multi-factor authentication.

    Wyden recommended that HHS:

    • require minimum, mandatory technical cybersecurity standards for systemically important entities like large health systems, including as a condition of participation in Medicare;

    • require systemically important entities to meet resiliency requirements such that they are able to rebuild their information technology infrastructure from scratch and within 48 to 72 hours;

    • conduct periodic cybersecurity audits of covered entities and business associates as part of the audits required by section 13411 of the HITECH Act, prioritizing audits of systemically important entities; and

    • provide technical assistance on cybersecurity to health care providers, such as through quality improvement organizations and the Medicare Learning Network.

    On May 30 Wyden also requested that the Federal Trade Commission and the Securities and Exchange Commission investigate UHG for its cybersecurity lapses, including its failure to use multi-factor authentication.

    HHS has recently increased its scrutiny of cybersecurity issues. For example, earlier this year HHS established voluntary cybersecurity performance goals and indicated that CMS will propose new cybersecurity requirements for hospitals through Medicare and Medicaid. It has also worked to update the HIPAA Security Rule to include cybersecurity requirements.

    Companies: UnitedHealth Group; Change Healthcare

    IndustryNews: NewsStory SenateNews ComplianceNews BillingNews CMSNews EHRNews HIPAANews HITNews IPPSNews QualityNews CyberPrivacyFeed LegislativeRegulatoryActivity DataPrivacy DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use