Live data from Hacker News

UnitedHealth says data of 100M stolen in Change Healthcare hack

bleepingcomputer.com

21–30 of 41 posts

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#23
post #7

Are they obligated to notify specific customers? How can I know if my data was in the hack?

I got a mailer that states this.

At first, I didn't even know who Change was - they're well in the bowels of the stack.

Usual free credit monitoring etc.

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#24
post #8

I really don't understand how this level of consolidation has been allowed in the healthcare market. I was affected by this, couldn't get prescriptions filled for 4 days. Turns out I'm not alone -- 100m people? That's 1/3rd of America's population! There is no competition in the marketplace. We need to either nationalize them or break them up. These ransomware groups are small-time compared to a nation-state adversar…

There is competition in the marketplace, see Waystar and Availity.

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#25

I always wonder that maybe someone can convince these health companies, clinics, etc... to start using Qubes OS for their network connected office computers. Maybe that could prevent a sizeable number of these ransomware attacks? TLDR Qubes OS is a security focused operating system that is geared towards end users. It relies on isolation via the Xen hypervisor (has much less privileged code than Linux, Windows, or Ma…

Not sure using a different OS helps the issue, if not making it worse --

* These days hackers have a lot of resources and are often nation state actors. They utilize 0 day vulnerabilities. I don't see how an obscure OS will do any better than mainstream OS in terms of detecting and responding to exploits

* Many hacks actually start with social engineering, and human becomes the weakest point (well, in some sense, it always has been)

* Users, most of which are not computer experts, could make more mistakes when they are faced with software/interfaces they are not familiar with. (I'm just making this up, happy to see data that says otherwise.) "Open suspicious links in disposable VMs"? Sure, if they have received enough training and can do it perfectly, every single time, and never confuse the VM and the host environment. I'd say "never open suspicious links, forward the email to IT to help with you if needed", or even, just filtering untrusted domains in the email, is a much simpler and effective approach.

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#26
post #25

I always wonder that maybe someone can convince these health companies, clinics, etc... to start using Qubes OS for their network connected office computers. Maybe that could prevent a sizeable number of these ransomware attacks? TLDR Qubes OS is a security focused operating system that is geared towards end users. It relies on isolation via the Xen hypervisor (has much less privileged code than Linux, Windows, or Ma…

Not sure using a different OS helps the issue, if not making it worse -- * These days hackers have a lot of resources and are often nation state actors. They utilize 0 day vulnerabilities. I don't see how an obscure OS will do any better than mainstream OS in terms of detecting and responding to exploits * Many hacks actually start with social engineering, and human becomes the weakest point (well, in some sense, it…

I expect you could mitigate 9 out of 10 breeches by staff not giving out their teams shared admin password (which is password123) over the phone to someone who says they are Jim from the CEOs office who needs to check some numbers for the big presentation tomorrow.

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#27
post #19

Earlier quoted context omitted.

> Look at "inflation" - every business was able to blame "supply chain issues" (that they caused by removing redundancies) during COVID to extract unthinkable price increases out of the public. Are you implying there were no supply chain difficulties? China wasn't under heavy lockdown for months on end? There weren't ports with months of backlog? Factories weren't closed due to lockdowns or outbreaks all around the w…

"The biggest study of ‘greedflation’ yet looked at 1,300 corporations to find many of them were lying to you about inflation" – https://fortune.com/europe/2023/12/08/greedflation-study/

[deleted]

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#28
post #19

Earlier quoted context omitted.

> Look at "inflation" - every business was able to blame "supply chain issues" (that they caused by removing redundancies) during COVID to extract unthinkable price increases out of the public. Are you implying there were no supply chain difficulties? China wasn't under heavy lockdown for months on end? There weren't ports with months of backlog? Factories weren't closed due to lockdowns or outbreaks all around the w…

"The biggest study of ‘greedflation’ yet looked at 1,300 corporations to find many of them were lying to you about inflation" – https://fortune.com/europe/2023/12/08/greedflation-study/

Doesn’t everyone sell at the highest price they can, without regard for their COGS?

I don’t break out my household expenses when I negotiate pay at a new employer.

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#29
post #19

Earlier quoted context omitted.

Part of the neoliberal consensus that replaced progressive liberalism in the 1970s and 80s is a revisionist reframing of antitrust law in which all monopolies are judged solely by the yardstick of consumer welfare. Problem is, very few monopolies actually harm consumer welfare. Bigger businesses are able to deliver lower prices - at least initially - because they suck the redundancy out of the market. Ergo, consolida…

> Look at "inflation" - every business was able to blame "supply chain issues" (that they caused by removing redundancies) during COVID to extract unthinkable price increases out of the public. Are you implying there were no supply chain difficulties? China wasn't under heavy lockdown for months on end? There weren't ports with months of backlog? Factories weren't closed due to lockdowns or outbreaks all around the w…

> Are you implying there were no supply chain difficulties? China wasn't under heavy lockdown for months on end?

I think they were more stating that consolidation, which often results in a reduction in redundancies in the system, made the supply chain issues worse than they otherwise would have been. Consolidation can increase the instances of single points of failure.

For a smaller scale example: in 2016 flooding took a biscuit factory out of action for a time, and suddenly you couldn't get bourbon biscuits (and a few other varieties) anywhere. It turns out that all the UK supermarkets (except Sainsbury IIRC) and some big-name brands were supplied by that one factory¹, so they all had a stoppage of supply at the same time, and those being supplied from elsewhere were out of stock too because the remaining smaller supplies could not ramp up production to meet the new demand². The consolidation that brings more efficiency when all is well can make things worse when something goes wrong.

----

[1] This also lead to “I told you so” comments from some of us, to people who were suddenly asking “if the ones I buy come from the same place, exactly the same production line, why have I been paying 25p/pack more for them?”.

[2] And even if they could, it would have been a bad business decision because once that big factory was back online the market wouldn't bare the new excess of supply meaning prices would drop, potentially below cost where margins are tight.

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#30
post #8

I really don't understand how this level of consolidation has been allowed in the healthcare market. I was affected by this, couldn't get prescriptions filled for 4 days. Turns out I'm not alone -- 100m people? That's 1/3rd of America's population! There is no competition in the marketplace. We need to either nationalize them or break them up. These ransomware groups are small-time compared to a nation-state adversar…

They protect themselves by being publicly traded. Stop whining and start investing.
Post reply on HN