The AHA June 6 participated in a Wall Street Journal Tech Live Cybersecurity event to discuss the historic Feb. 21 cyberattack on Change Healthcare. Stacey Hughes, AHA executive vice president of government relations and public policy, spoke about the impact on hospitals and health systems, the government response to the attack, how UnitedHealth Group’s size was a factor in the incident and what’s next in federal cybersecurity policy in a discussion with Erik Decker, vice president and chief information security officer for Intermountain Health, and WSJ Reporter James Rundle. 

When asked about the response of government, Hughes said, “It took a while for some people to recognize the severity of this incident. One of the reasons for that was because there was a significant minimization of the impact from UnitedHealth Group early on. That minimization led policymakers to not react as quickly. There is room for improvement in how our government responded and in understanding how government steps in and what they can do when something like this happens.” 

Last week, the Department of Health and Human Services announced that hospitals and health systems could require UHG to notify patients if their data was stolen during the cyberattack.

Headline
A joint advisory released April 23 from U.S. and international cybersecurity agencies, including the Cybersecurity and Infrastructure Security Agency, FBI,…
Headline
FBI Co-deputy Director Andrew Bailey discussed a rise in cyber and physical threats impacting health care. He discussed health care as the top critical…
Headline
Health care and public health was the top sector targeted for cyberthreats in 2025, according to the FBI’s latest annual report on internet crimes. There were…
Headline
The Cybersecurity and Infrastructure Security Agency released an alert March 27 on a vulnerability in F5 BIG-IP Access Policy Manager software that is being…
Headline
The FBI released an alert March 20 warning of a technique used by cyber actors working on behalf of the Iranian government to conduct malicious cyber activity…
Headline
The Cybersecurity and Infrastructure Security Agency March 18 released an alert urging U.S. organizations to harden their endpoint management systems following…