Buried among the festive Christmas cards and miscellaneous ads I received in the mail this week — season of joy — was a bulky envelope from Change Healthcare. Since I didn’t know I had a relationship with them, I figured it was likely more Medicare-related mail. Someone my age could disappear entirely under the flood of choose-our-plan pitches.

Nope.

Turns out that I do have a very close relationship with the company, which I had to Google to figure out what it even is. Change Healthcare processes health care payments. It’s a subsidiary of UnitedHealth Group — not my insurance company, by the way — and acts as a clearinghouse for roughly 15 billion annual medical claims. That means you may have a relationship with the company, too. They estimate 100 million people were affected.

The contents of the missive informed me the company had what appears to be an extraordinarily thorough data breach: full names, dates of birth, phone numbers, email addresses, “plus one or more of the following”: Social Security numbers, driver’s license or state ID numbers, medical records, doctors, diagnoses, medical test results, medications, insurance companies and all the related numbers, images, treatments, claim numbers, account numbers, payment cards, financial and banking numbers, and balances owed.

“The data that may have been seen and taken was not the same for everyone. Some of this data may be about the person who paid the bill for health care services,” the note added. Yay. We all know misery likes company. Oh, wait. That includes me.

It’s not the data breach that makes me so mad, though that certainly is mad-making.

I am livid that it took the company from March 7, when they learned that my data could have been seen by a cybercriminal, to Dec. 10 to let me know about it. They wrote that they started notifying their business customers in late June, which was still a dandy gap in time. But I, as a patient, had to wait nine months to find out.

This has been called health care’s largest-ever data breach. Forbes reported it had “cascading impact across the U.S. healthcare sector, disrupting billing, payment processing and even delaying patient care.”

In testimony before Congress this spring, Andrew Witty, CEO of UnitedHealth Group, “repeatedly apologized for the hack of subsidiary Change Healthcare, vowed that he and the company will not rest ‘until we fix this,’ and said the company was offering no-interest loans to affected hospitals and doctors and free credit monitoring to affected patients,” per The Washington Post.

Witty said UnitedHealth would add multifactor authentication to its systems within six months, as that was how the data was hacked. He told Congress the company had provided “more than $6.5 billion in no-interest loans to practices affected by the cyberattack” and that it had also paid $22 million ransom in bitcoin. And that all affected would be notified.

If I could sever my connection to Change Healthcare, I would, based on the time lag alone. But I didn’t know the clearinghouse had my information. So even hearing about the breach at a company I didn’t know raised no alarms. And I had — and have — absolutely no say in whether my medical providers use them. So I imagine we will continue to date in the world of data.

Related
Multifactor fail opens door for massive health care hack
Hackers breach 23andME, access personal info on nearly 7 million users

At this point, few of us have escaped being part of a data breach. It’s becoming so common it’s easy to shrug and figure that’s just part of life now. That’s wrong. We should demand that lawmakers and law enforcement boost efforts to find and punish those who try to benefit by slithering through computer systems and stealing information. I don’t care if the crime is committed by people a zillion miles away. It’s an international nightmare and countries’ officials should band together and do something about it. Penalties should be severe.

16
Comments

It might be time for new numbers for all of us for every kind of identifying information, though even in my rage I see that’s a nightmare task that’s not realistic.

But here’s something that shouldn’t be that hard: Don’t wait nine months to inform the individuals who might be harmed, even if they’re not your direct customers. They are, after all, the very reason you exist, dear company.

This data breach notice came with the offer of a comparatively generous two years of free data monitoring to spot identity theft, part of the breach remediation.

I would dearly have loved to see it start sooner. Or not be needed at all.

Related
How concerned are you about the AT&T data breach?
Join the Conversation
Looking for comments?
Find comments in their new home! Click the buttons at the top or within the article to view them — or use the button below for quick access.