UnitedHealth Hack Put Data of One in Three Americans at Risk

  • Ransomware hack paralyzed medical payments in February
  • CEO Says he doesn’t know why hacked server was unprotected

Andrew Witty, CEO of UnitedHealth Group Inc., arrives for a Senate Finance Committee hearing in Washington, DC, US, on Wednesday, May 1, 2024. 

Photographer: Al Drago/Bloomberg
Lock
This article is for subscribers only.

UnitedHealth Group Inc. Chief Executive Officer Andrew Witty told lawmakers his company is still trying to determine why its computer systems were left vulnerable to hackers who perpetrated a devastating cyberattack.

Lawmakers zeroed in on lax defenses during more than two hours of questioning by the Senate Finance Committee, in the first of two congressional hearings about the breach on Wednesday. The intruders got in through a server that didn’t have multifactor authentication — a basic cybersecurity measure used on consumer bank accounts — and got access to a hoard of health and personal data. Witty said the trove might cover one-third of Americans.