Thread regarding Optum layoffs

Texas Protects Your Medical Records. Your Job's Insurance Doesn't.

Texas Protects Your Medical Records. Your Job's Insurance Doesn't.

Somewhere outside the United States, a man with administrative access to an American health insurer's systems is looking at a screen full of patient records. Names. Dates of birth. Member identification numbers. Diagnoses. Years of claims.

He may be at his kitchen table, on home wifi, with his phone beside him. He may be in a windowless facility that took a badge and a fingerprint to enter, where the phone cameras are taped over and nothing reaches the outside internet.

No federal rule distinguishes between those two rooms. None has ever been written.

For nearly three decades, the Health Insurance Portability and Accountability Act has been the public's shorthand for medical privacy, invoked at every pharmacy counter and on every clipboard. What the law says about the physical circumstances in which health
records are actually viewed amounts to a single sentence, and that sentence requires almost nothing.

The provision is 45 CFR 164.310(b). It obliges a covered organization to maintain
policies describing "the physical attributes of the surroundings" of any workstation
that can reach electronic health information. It does not say what those attributes should be. It sets no minimum. It names no control. A secured operations center and a laptop on a sofa satisfy the requirement equally, so long as a document somewhere describes each arrangement.

The rule was written in 2003, when remote access to a health plan's production systems was rare and mostly stationary. It was last substantively amended in 2013. It has not been revisited since the work of maintaining American health data became something that can be done from anywhere on earth with a broadband connection.

What federal law does not require is easier to state than what it does. There is no
requirement for multi-factor authentication on systems holding patient records. No requirement for a controlled or supervised workspace. No restriction on access from a private residence, or from outside the United States, or on privileged administrative access from a foreign country. No prohibition on cameras in the room where records are displayed. And no obligation to tell patients, or even the insurer's own corporate customers, that their records can be reached from abroad.

Each of those decisions belongs entirely to the company. Some organizations impose all of them. Others impose none. Under current law, both are in compliance.

Nor does it matter, legally, who employs the person at the keyboard. Much of the
oversight that does exist was designed around outside vendors: the written agreements a hospital or insurer must sign with a business associate, the assessments it performs before hiring one, the attestations required when a Medicare plan hands work to a subcontractor abroad. None of that machinery engages when the person is on the company's
own payroll.

American insurers and health technology firms have spent two decades building wholly owned subsidiaries overseas, employing tens of thousands of engineers directly. Those engineers are workforce, not business associates. No agreement is required between a company and its own staff. The nationality of the employee is irrelevant to the law, as it should be. What is not irrelevant, and what no rule addresses, is that the entire apparatus of third-party scrutiny simply does not apply to the arrangement that has become the most common one.

There is one exception, and its origin is telling. The strictest rule anywhere in the
country governing where American health records may be handled was not written by a privacy regulator. It was written by a state purchasing office.

Texas requires, through the contract every managed care organization must sign to do business with its health and human services agency, that work be performed and information maintained inside the United States. The same contract bars remote access to the state's systems and data from offshore locations. It does not ask a company to describe its safeguards. It tells the company where the work may happen.

A handful of other states have reached similar conclusions by different routes, several of them through governors' executive orders barring state agencies and their subcontractors from sending work abroad. The restrictions are real, they are enforceable as contract terms, and they demonstrate that the question is neither novel nor unanswerable.

They also reveal the shape of the gap. These rules exist because a state was buying something and could set its terms. They protect the residents of those states, in those programs, and nobody else. A Texan enrolled in Medicaid is covered by a rule that a Texan with employer insurance is not, over the same records, in the same city, held by the same company. The protection follows the contract, not the patient.

There is one federal mechanism that touches the question, and it is regularly mistaken for supervision. Since a series of memoranda issued in 2007 and 2008, Medicare Advantage and prescription dr-g plan sponsors that use offshore subcontractors with access to
beneficiary health information have been required to file an attestation with the
Centers for Medicare and Medicaid Services. The form is more demanding than most people assume. A sponsor must describe the information involved, explain why sending it is necessary, and state what alternatives it considered and why it rejected them.

Then the form is filed, and nothing happens. The agency does not approve it. There is no review, no license, no conditions, and no authority to refuse. A company decides, and then reports what it decided. The requirement also reaches only Medicare plans. For commercial insurance, covering most working Americans, no comparable notification exists at all.

That the government is capable of writing a firmer rule is not in question, because it
recently did, on the same data, in a fraction of the time.

In February 2024, an executive order directed the Justice Department to restrict foreign access to Americans' bulk sensitive personal information. The resulting regulation took effect in April 2025 and became enforceable that July. It names the countries it covers. It sets numerical thresholds: health information on more than 10,000 Americans,
or genetic information on more than 100. It reaches employment and vendor arrangements explicitly, and one of its own published examples treats foreign technical staff with access to encrypted health data as a prohibited transaction. Records stripped of identifying details under HIPAA can still fall within its scope.

Fourteen months, from executive order to binding rule.

The distinction was never the data. It was the framing. Asked whether foreign
adversaries might obtain American medical records, the government wrote an enforceable prohibition in a little over a year. Asked whether patients' medical records are handled carefully, it has produced, in twenty-eight years, one form that nobody reviews.

If any event was going to change that, it should have been what happened at Change Healthcare.

The company processes a substantial share of the nation's medical claims. On February 12, 2024, intruders logged into a remote access portal using stolen credentials. The portal did not require a second form of authentication. They moved through the network
for nine days before anyone noticed. By the time the company confirmed that data had been taken, it was March.

Pharmacies could not fill prescriptions. Physician practices went months without being paid. Congressional committees convened hearings, and the chief executive of the parent company testified that security procedures had not been updated after the 2022 acquisition. The company reported to federal regulators that approximately 192.7 million
people were affected, close to two thirds of the United States population. It is the
largest medical data breach ever recorded.

Two details from the aftermath have drawn less attention than they deserve.

Before the breach, Change Healthcare held a HITRUST certification for its enterprise
infrastructure, an assessment the industry treats as evidence that an organization's
security is sound. The company had publicized it. It was certified, and the portal still
had no second factor of authentication. Certification is the principal way American
health care organizations satisfy themselves that a vendor's environment is adequate, including vendors operating overseas. It did not detect the failure that brought down a third of the nation's claims traffic.

And no federal penalty has been announced. For scale, the largest fine in the history of the medical privacy law remains a $16 million settlement reached in 2018 over a breach affecting 78.8 million people, about twenty cents a record. In the first part of this year, federal regulators closed six enforcement matters with penalties totaling roughly
$1.3 million across all of them.

The formal response to the largest breach in the sector's history was a proposal. In
January 2025, regulators published a draft update to the security rule that would, among other things, require multi-factor authentication. Public comment closed that March. The proposal has not been finalized. The federal regulatory agenda now lists July 2027 as
the target. A second initiative, a set of cybersecurity performance goals, is voluntary.

More than two years on, the missing control that caused the breach is still not required by law.

There is a structural reason none of this has generated sustained pressure, and it is
not indifference. Nobody is counting.

No law obliges a vendor to disclose that it permits access from outside the country, or from employees' homes. A hospital or insurer must have a contract with its business associates, but is not required to know, and often does not know, which country a subcontractor's subcontractor is working from, or what that room looks like. Patients cannot find out. Regulators do not collect the information outside the Medicare program.
Researchers cannot measure what is not recorded. The result is a category of risk that produces no statistics, and policy in the United States rarely moves against risks that produce no statistics.

Every legal obligation in American medical privacy law attaches to the information. Not one attaches to the room.

A health plan is fully responsible for records that an employee of a subsidiary, or a contractor three tiers below it, may be reading on a personal laptop in a country nobody
at the plan could name. No rule requires the plan to know this, to prevent it, or to
tell anyone that it is so.

The law punishes the theft after it happens. About the conditions that would make it easy, it says nothing at all, and has said nothing since 2003.


by
| 99 views | | 16 replies (last 14 days ago) | Reply
Post ID: @OP+1kzm1a027

16 replies (most recent on top)

@104 Stereotypes exist for a reason.

If I left my house every day, and I see a certain occurrence being performed by certain demographics every day, one would eventually come to those conclusions.

And before you say it, yes--there are exceptions. I have personally worked with some of the exceptions. But the exceptions PROVE the rule!

In my personal experience 10-20% are average or better at the job. That is crazy.

by
| | Reply
Post ID: @18v+1kzm1a027

@a1 that’s the funny thing about personal data. There are new ways to exploit and monitoze said data developed daily. What’s benign today is cancer tomorrow. But go ahead and assume sunshine and rainbows.

by
| | Reply
Post ID: @105+1kzm1a027

@jf please don’t stereotype, it’s not a good look

by
| | Reply
Post ID: @104+1kzm1a027

@j7 And don't you just love how they take like 123890234908209348 days off for all of their holidays, weddings, and funerals? Not to mentioning the mumbling of broken English on the calls.

It's incredibly insulting, and you have to always fix their work. ALWAYS. NOT ONE of them can be trusted to get the job done right the first time. NOT ONE.

by
| | Reply
Post ID: @jf+1kzm1a027

Another note. My current company has started mandating on-camera for all meetings, for all workers. Apparently there is a problem of offshore resources getting hired and then outsourcing their work to others .

by
| | Reply
Post ID: @j9+1kzm1a027

I’m no longer at Optum for several years now, but currently contracting for another large pharma corporation in tech-related field that interfaces directly with the business. I sit in a 1:15 hour long meeting every morning for a couple of years now. I literally hear chickens crowing, dogs barking, and children playing loudly in the background. This is a North American based company in the Fortune 10. It’s pretty much over for healthcare IT workers in North America.

by
| | Reply
Post ID: @j7+1kzm1a027

@gf wow, no! The leadership/asset owning classes, should NOT be allowed to skirt their responsibilities! It’s is NOT on the employee to ensure that proper guard rails exist. An employee, who is compensated a 1000th of what the asset/leadership classes are compensated, should NOT be held liable for the lack of sufficient training, oversight, and infrastructure.

by
| | Reply
Post ID: @j1+1kzm1a027

@f7 sounds like non compliant employees then. If the company has a policy and they don’t follow that, it’s on the employee

by
| | Reply
Post ID: @gf+1kzm1a027

@ae Yet no one does. Do you know that there are employees who work from their cars, there are employees who have catastrophic conditions and take their computers to the hospital and while sitting in a hospital bed are working, those who use their neighbors hotspot, what security. This company has no clue what most of their employees are doing with protected health information.

by
| | Reply
Post ID: @f7+1kzm1a027

@a1 yes it is. It’s used to gain trust and get into that persons bank accounts. They get an email, text or even physical mail talking about their very specific health background. Then they sell them some phony product or stating the have unpaid bills and ask for their bank account number. From there they steal their money, either by selling the account numbers or charging them but never delivering.

In reply to the original content of this post. The board doesn’t give a sh!t as long as they get their money. And offshore is now running through all major US corporations/government agencies and destroying them - taking the money, paying wages for work not done and destroying the US onshore consumers. If you step back and look at it, it looks like a BRICS attack on the US financial system. The US political/global elite are just so stupid they don’t see it.

by
| | Reply
Post ID: @de+1kzm1a027

Nothing was learned. Here is the proof, and it is not a rumor, it is on the record.

Sandeep Dadlani was UnitedHealth Group's EVP and Chief Digital and Technology Officer from September 2022. That is the top enterprise technology seat, and he was in it in February 2024 when intruders walked into Change Healthcare through a remote portal with no multi-factor authentication and sat in the network for nine days. 192.7 million people.

In September 2025 he was made CEO of Optum Insight. Optum Insight is the division that owns Change Healthcare.

Read that again. The technology executive on watch during the largest medical data breach in American history was given the division where it happened. No fine. No finding. No individual held to anything. A promotion.

That is the whole governance model in one line. There is no consequence, so there is no change, so the handling stays exactly as loose as it was.

And here is the question the company will not answer in public. What is the actual standard for access to US citizens' medical records from outside the United States? Not the marketing language about being certified. The standard. Publish it.

Is a person on home wifi in Hyderabad, on his own network, with a phone on the desk and nobody in the room, permitted to open a screen full of American patients' names, dates of birth, member IDs and diagnoses? Yes or no. If yes, say yes and let the customers and the members hear it. If no, publish the control that prevents it and who audits it.

There is no federal rule that forces an answer. 45 CFR 164.310(b) asks only that the surroundings be described in a document. So the company is free to say nothing, and it does.

This is not a layoff board story. This belongs in a newspaper.

by
| | Reply
Post ID: @aq+1kzm1a027

Two and a half years after Change Healthcare and nothing has changed.

192.7 million records. Nine days inside the network before anyone noticed. A remote portal with no second factor. The company was HITRUST certified at the time and the certification did not catch it. The multi-factor requirement that would have stopped it is still not law. It is sitting in a proposed rule with a target date of 2027.

No fine has been announced. The largest HIPAA penalty ever is still 16 million dollars for 78.8 million records, which works out to about twenty cents a record. That is not a deterrent. That is a rounding error.

Now look at where the deterrent actually lands. Enforcement runs against the covered entity, not against the individual with admin access. If that person is sitting in another country, working for a wholly owned subsidiary, no US regulator is realistically reaching them. The chain of accountability stops at the company, and the company just demonstrated it can lose two thirds of the country's medical records and pay nothing.

So there is no consequence at either end. Not for the person with the access, not for the company that granted it. Whether the room is controlled is entirely up to whoever is writing the policy that quarter, and they can rewrite it next quarter without telling you.

That is what loose means. Not that anyone is careless. That nothing requires anyone not to be.

by
| | Reply
Post ID: @ap+1kzm1a027

That is the argument. UHG requires it. No law does.

A policy is a company decision. It can be revised at the next cost review, and nobody outside the company has to be told. 45 CFR 164.310(b) only asks for a document describing the surroundings of the workstation. It sets no minimum, so a locked private office and a kitchen table both comply as long as each is written down somewhere.

A locking door is also a workspace standard, not a location standard. The post is about which country the room is in, whether the access is privileged admin access, and whether anyone outside the company is required to know. A locked door satisfies the same policy sentence in either place.

by
| | Reply
Post ID: @an+1kzm1a027

@ae you must be an anti-American corporate shill. GFY

by
| | Reply
Post ID: @ag+1kzm1a027

UHG says you need to have a private workspace with a locking door. Idk what your argument is.

by
| | Reply
Post ID: @ae+1kzm1a027

I wonder. Is our healthcare records even useful for foreign workers? If they know I have diabetes what can they do with that info?

by
| | Reply
Post ID: @a1+1kzm1a027

Post a reply

: