UnitedHealth Group has paid more than $2B to providers following cyberattack
aol.com
aol.com
These are the payments owed by plans.
UnitedHealth is also advancing money to some providers as well.
See: https://www.unitedhealthgroup.com/ns/changehealthcare.html
They only make a 6% margin, but still. That's a ton of cash.
But the revenue is similar to Amazon. They buy something for $100 and sell it for $102. Revenues look high, but just because they are a middleman.
Revenue that is 95% paid to vendors and employees is not an interesting statistic, on a company level.
"To assist care providers whose finances have been disrupted by the cyberattack, the company has advanced more than $2 billion thus far through multiple initiatives. The company recognizes the high level of fragmentation of the U.S. health system can result in uneven experiences, therefore it continues to enhance and expand funding support to make it easier for care providers to access funding help at no cost. To further assist care providers, the company also suspended prior authorizations for most outpatient services and utilization review of inpatient admissions for Medicare Advantage plans."
https://www.unitedhealthgroup.com/newsroom/2024/2024-03-18-u...
* protection for our clients
* drum up business for the market as a whole
* make competitors look bad -- especially if they get attacked directly
After all, breaking a window makes money for the glaziers.
They provide DDoS protection to DDoS providers that would otherwise have taken each other down, so those providers can find clients for their services which further necessitates Cloudflare’s main product.
Given many DDOSs are originated by botnets, is this possible?
also I think there was a thing on krebs where a reputation defender company was also operating one of those mugshot search sites
https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-comp...
It wasn't, though. It was the largest, but never majority (except that I think it peaked with an absolute majority of CDs pressed by AOL CDs, which was an achievement, I guess.)
Expect there was too much traffic to the domain for the current owner to abandon.
The Wayback machine on it, through the decades, is fascinating if you're curious.
Of course the MBAs see this as a win as their names aren't on anything except the profits at the time. Parasites.
ah yeah, the old socializing losses and privatizing profits.
Let the coverup begin, well actually they probably started wiping days after the attack.
They have been migrating all their services for that business they bought to the cloud, and have already started turning up several services.
Money saved can be paid to these providers. That way, the money stays in the us. A 10k IQ move that no one will understand.
/s ov course
Look, "in principle" stuff is not how the real world works. AFAIK, hacks happen mostly because of carelessness. No one cares because no one cares if they care (and the compensations etc reflect that). I know enough such cases in fintech (forget about other verticals), which are mostly stupid like wrong RBAC, open firewall, AWS keys taken by roommate etc and not public of course.
https://www.nbcnews.com/tech/security/former-twitter-employe...
There are certain security measures which can minimize insider threats. But ultimately it's just hard to guard against agents who are willing to commit felonies in order to carry out their missions. Even defense industry companies which have tight security over classified information have been repeatedly penetrated.
The upper bound of security is unable to make attacks with a 10 M$ return unprofitable. Raising the lower bar just raises the barrier to entry for new participants, it does not stop existing ones.
Most attacks do use basic techniques since a 10 M$ payout on 10 K$ cost is still better than 10 M$ payout on 1 M$ cost. No point wasting the good stuff when the basic and cheap stuff works just as well. But if you get rid of all the cheap ways in they will still attack using the more expensive stuff since the payout is still wildly profitable.
I hope we can get out of that nonsense and tackle cyber issues with actual technological investments as it should and can be done.
We need come up with answers that work despite humans not being perfect. This is a hard problem. (what gets hard is sometimes someone will lose/forget a key and so you need to issue a replacement but only to the correct person)
UHG developers would be responsible for the infrastructure right? And wouldn't Change have been brought under the UHG network?
I would bet my life savings UHG developers pleaded with management for years to get the resources they desperately need to resolve these problems, but management ignored every request because it didn't have any external impact.
Management in healthcare tech is comprised entirely by some of the most mind boggling idiots on Earth, whose only qualification might be being an adult, since their ability to read, write, and comprehend information is universally worse than a child. This is without exception, in my experience.
Step two: avoid all accountability for anything that ever happens as the resources offered to you are finite
The systems built were designed for a business that evolved, and the assumptions and constraints changed in a way that sometimes requires redoing things. This can be as simple as an assumption about how sales will be acquiring new clients, and how those new clients affect overall system scalability. If there's a long pipeline of feature requests and sales supersedes product managers on roadmaps, doing the necessary work to scale the systems is going to be deprioritized to a point where anything other than downtime is acceptable from a business standpoint. Sales are made on features being built, not on an impending doom that has yet to happen. This extends to other aspects of systems, like security.