Wyden wrote in the letter that the incident was “completely preventable and the direct result of corporate negligence,” noting that UnitedHealth Group confirmed that a remote access server that was breached by the hackers was not protected with multifactor authentication (MFA)