October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

What UnitedHealth’s CEO Actually Told the Senate About MFA After the Change Healthcare Hack

UnitedHealth CEO Andrew Witty told the Senate that MFA covered all external-facing systems after the Change Healthcare ransomware attack. The narrower wording matters: it was not a claim that every internal, legacy or acquired system had MFA.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On May 1, 2024, UnitedHealth Group CEO Andrew Witty told the Senate Finance Committee that all of the company’s external-facing systems had multi-factor authentication (MFA) enabled. That was not a claim that every UnitedHealth system, server, application, privileged account or acquired environment had MFA. His testimony followed an admission that attackers had used stolen credentials to enter a Change Healthcare server that lacked MFA.

What Witty told senators

Witty appeared at the Senate Finance Committee hearing Hacking America’s Health Care: Assessing the Change Healthcare Cyber Attack and What’s Next on Wednesday, May 1, 2024. Senator Ron Wyden pressed him on whether UnitedHealth would require MFA across the company.

Witty said that, “as of today,” MFA was enabled on all UnitedHealth Group external-facing systems and that an enforced policy covered those systems. The wording matters. External-facing systems are internet-accessible or otherwise reachable from outside the corporate network; they are not synonymous with every internal system, legacy server, service account, administrator account or vendor connection.

Witty’s written testimony is available from the Senate Finance Committee. The hearing page is at finance.senate.gov.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How the Change Healthcare attack unfolded

  1. February 21, 2024: Change Healthcare disclosed a cyberattack.
  2. Initial access: According to Witty’s testimony, attackers used stolen credentials to access a Change Healthcare portal or server that did not have MFA.
  3. Intrusion and ransomware: The attackers moved through the environment, removed data and deployed ransomware.
  4. Containment: Change Healthcare disconnected systems, interrupting its services.

Change Healthcare is part of UnitedHealth’s Optum business and operates as a major healthcare claims and payments intermediary. The account above comes from Witty’s testimony and congressional materials; the unprotected server should not be treated as the only weakness in the environment.

Why the missing MFA mattered

A password is one authentication factor. MFA adds another, such as a hardware security key, authenticator-app approval or one-time code. If an attacker steals a password, a correctly enforced second factor can block or complicate the login.

That does not make MFA a complete defense. Attackers can target session cookies, trick users into approving fraudulent prompts, compromise identity providers, exploit public-facing software, abuse privileged accounts or enter through a vendor. Phishing-resistant passkeys and hardware security keys generally provide stronger protection than SMS codes.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The accurate conclusion is therefore limited but important: the missing MFA removed a basic barrier to the use of stolen credentials. It does not prove MFA alone would have guaranteed prevention.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Policy on paper versus control in production

Witty said Change Healthcare’s technology had not yet been fully upgraded after UnitedHealth acquired the company in 2022. He described the unprotected server as technology being upgraded. Wyden’s criticism was that a written MFA policy is not enough if exceptions remain connected to the corporate environment.

The integration questions raised by the incident

  • Was every inherited asset identified and assigned an owner?
  • Were exceptions documented, time-limited and monitored?
  • Were privileged accounts, service accounts and remote-access portals covered?
  • Was acquired infrastructure segmented before it was linked to wider corporate networks?
  • Did technical checks verify MFA, rather than relying on policy attestations?

The hearing established the MFA gap and the subsequent external-system claim, but it did not answer all of those implementation questions. They are the difference between compliance language and demonstrable technical control.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Why the outage affected the wider healthcare system

Change Healthcare processes claims, payments and related transactions for providers, pharmacies, hospitals and insurers. Congressional statements described disruptions to claim submission, payment, prescription processing, eligibility checks and prior authorization.

Senator Wyden said Change processed about 15 billion healthcare transactions annually and that information involving roughly one-third of Americans passed through its systems. Those are descriptions of the company’s reach, not a confirmed count of people whose data was stolen. Transaction volume also is not the same as the number of unique patients.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Because providers depend on the intermediary for cash flow and administrative work, taking systems offline created operational and financial problems beyond UnitedHealth itself. Wyden’s statement is available at finance.senate.gov.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What data may have been taken

UnitedHealth said attackers exfiltrated data, but at the time of the hearing the company had not completed its review of whose information was involved. Witty reportedly estimated that “maybe a third” of Americans could have been affected; that was an early estimate, not a final breach count.

In an April 22 update, UnitedHealth said the review could take months and offered credit monitoring and identity-theft protection while warning that the offer was not yet an official breach notification. The company’s update is at unitedhealthgroup.com. Readers should rely on later direct notices for whether their own information was identified.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why UnitedHealth paid about $22 million

Witty testified that the ransom decision was his and that UnitedHealth paid approximately $22 million. A payment can be intended to obtain a decryptor or negotiate deletion of stolen data, but neither result is guaranteed. Payment does not reverse exfiltration and can finance criminal operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Companies may nevertheless weigh a ransom against the cost of a prolonged outage, especially when pharmacies, hospitals and medical practices cannot process essential transactions. Congressional Research Service material summarizes the payment and incident context at congress.gov. There is no basis in the cited testimony to claim that the payment restored every system or prevented publication of all stolen information.

What senators criticized

Wyden criticized UnitedHealth for failing to enforce a basic cybersecurity control. Senators also questioned preparedness, the integration of Change Healthcare, the ransom decision, effects on providers and the handling of patient information. The hearing treated the event as a systemic healthcare risk, not merely an isolated corporate IT problem.

Senator Mike Crapo’s statement is available at finance.senate.gov. Lawmakers argued that healthcare organizations may need stronger, enforceable federal cybersecurity requirements; the hearing itself did not settle what those requirements should be.

What organizations should take from the incident

  • Maintain a complete asset inventory: Include acquired servers, cloud workloads, remote-access tools, applications and machine identities.
  • Enforce MFA technically: Block access when MFA is absent instead of treating a policy document as proof of protection.
  • Prioritize privileged and remote access: Use phishing-resistant authentication where practical and tightly control administrator privileges.
  • Segment acquired environments: Limit lateral movement while legacy systems are modernized.
  • Monitor exceptions: Assign owners, expiration dates and compensating controls to every approved exception.
  • Prepare for recovery: Maintain tested offline or immutable backups, endpoint detection and practiced incident-response procedures.
  • Review third parties: Assess vendors, federated identity providers and connections that can bypass internal controls.
  • Communicate clearly: Distinguish preliminary exposure estimates from confirmed affected individuals and explain when official notifications will follow.

The precise takeaway

UnitedHealth’s Senate testimony supports a narrow headline: after the Change Healthcare attack, the company said MFA covered all of its external-facing systems. It does not support saying that every UnitedHealth system had MFA. The incident exposed the practical risk of inherited technology, incomplete modernization and controls that exist in policy but fail to cover a connected asset.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.