The RansomHub ransomware gang has begun leaking data , which it says is corporate and data patient stolen from United Health 's subsidiary , Change Healthcare .

In February, Change Healthcare suffered a cyberattack that caused massive disruptions to the entire US healthcare system, as it is the largest payment exchange platform used by doctors, healthcare, pharmacies, and patients in the US.
See also: Nexperia: Ransomware attack and data breach
“We cannot say it more clearly – the cyberattack on Change Healthcare is the most significant incident of its kind against the healthcare U.S.,” said Rick Pollack, President and CEO of the American Hospital Association.
The attack was eventually linked to the BlackCat/ALPHV, which later said it stole 6TB of data.
After coordinated law enforcement operations, the BlackCat ceased operations but attempted to return. However, it was later accused by affiliates of an exit scam involving the theft of$22 million in ransom money paid by Change Healthcare.
While Change Healthcare declined to comment on whether it had paid a ransom, the gang affiliate, known as “Notchy,” said he would blackmail Change Healthcare again as he still had the company’s data.
Change Healthcare: Double blackmail
After BlackCat was shut down, affiliate Notchy teamed up with the RansomHub to extort Change Healthcare again.
See also: Daixin ransomware gang responsible for Omni Hotels attack
A statement on the group's data leak website RansomHub said that all data would be made public unless Change Healthcare and United Health "reach an agreement" with them.
Now, it appears that the attackers have indeed begun leaking screenshots of files they claim were stolen from Change Healthcare . The screenshots include data sharing agreements between Change Healthcare and insurance providers, accounting data, and financial information.
Patient information has also been leaked, including amounts owed and bills for care services provided.
The attackers now say that Change Healthcare has five days to pay the ransom, otherwise all data will be sold.

Impact of a data breach
The implications for patients can be serious. The leakage of personal and medical data can lead to privacy breaches, with patients exposed to risks such as identity theft, fraud and extortion.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Furthermore, loss of trust in medical services may lead to a decrease in the use of these services by patients, with potential negative effects on health .
See also: Hoya: Ransomware group Hunters International demands $10 million
For the broader healthcare sector, data breaches can have significant financial implications, as healthcare organizations may face fines for violating data protection regulations, as well as costs to remediate security .
Finally, long-term damage may be caused to the image and reputation of Change Healthcare and healthcare organizations ,which may have implications for their ability to attract and retain customers.
Source: www.bleepingcomputer.com
