The Change Healthcare Attack: Lessons for Every Small Practice and Business

Written by

in

,

By J. Mesa

For three weeks, medical practices across the United States have struggled to get paid. Pharmacies have had trouble checking insurance coverage. Billing staff have gone back to paper forms and phone calls. None of those practices was hacked. Their vendor was. The attack on Change Healthcare is the clearest lesson in years about what happens when a business depends on a single outside company.

What happened to Change Healthcare?

Change Healthcare, a unit of UnitedHealth Group’s Optum division, operates one of the largest clearinghouses for medical claims and pharmacy transactions in the country. On February 21, 2024, the company discovered an intruder in its systems and disconnected them to contain the damage.

The shutdown cut the link between providers and insurers. Claims could not be submitted. Payments stopped flowing. Pharmacies could not process prescriptions through insurance in the usual way, and some patients paid cash or went without.

Who is behind the attack?

UnitedHealth has attributed the attack to the ransomware group known as ALPHV, or BlackCat. In early March, news outlets and blockchain researchers reported that a payment of about $22 million in bitcoin had moved to a wallet tied to the group. UnitedHealth has not confirmed whether it paid a ransom.

What is the impact so far?

  • Hospitals, physician groups, dentists, therapists, and pharmacies nationwide have reported delayed claims and payments.
  • Small practices, which hold little cash in reserve, have borrowed money or delayed their own bills to make payroll.
  • The federal government has offered advance payments to Medicare providers, and UnitedHealth has set up a temporary funding assistance program.
  • On March 13, the Office for Civil Rights at the Department of Health and Human Services opened an investigation into the incident, citing its unprecedented scale.

The company is restoring services in stages. The full count of affected patients and the method of entry have not been made public as of this writing.

Why did one vendor’s outage hurt so many?

Concentration. Change Healthcare sits in the middle of an enormous share of the country’s medical claims. Thousands of practices relied on it, often through their practice management software, without ever choosing it by name. Many did not know they depended on it until the day it stopped.

Security people call this a single point of failure. When one supplier handles a function that nothing else can perform, its bad day becomes yours.

I do not work in healthcare. Why should I care?

Because every business has its own Change Healthcare. Ask yourself what would happen if one of these went dark for a month:

  • Your payment processor
  • Your payroll service
  • Your accounting or invoicing platform
  • Your email and file storage provider
  • Your scheduling or point-of-sale system
  • Your IT provider
  • The one supplier whose portal you order everything through

If the honest answer is “we could not take money” or “we could not pay staff,” you have found a dependency worth planning for.

How do I find my critical vendor dependencies?

Spend an hour on this exercise.

  1. List your core business functions: getting paid, paying staff, serving customers, ordering supplies, communicating.
  2. For each function, write down every outside company it relies on.
  3. Ask the vendors that matter most which companies they rely on. The clearinghouse behind your billing software, the cloud host behind your records system.
  4. Mark any function with only one path and no backup.
  5. For each one, estimate how many days you could operate without it.

How do I prepare for a vendor outage?

  • Identify a backup. For claims, enroll with a second clearinghouse now. For payments, keep a second processor or a manual method ready. Setting up an alternative during a crisis takes weeks.
  • Write the manual procedure. How do you take a payment, record an appointment, or submit a claim on paper? Store the forms and the instructions where staff can find them.
  • Build a cash cushion or a credit line. The practices suffering least this month had reserves or an open line of credit. Arrange the credit before you need it.
  • Keep your own copy of your data. Export customer lists, schedules, and financial records on a schedule, so a vendor outage does not leave you blind.
  • Know your contacts. Keep vendor support numbers, account numbers, and your insurance agent’s number on paper.
  • Check your insurance. Ask whether your cyber policy includes contingent or dependent business interruption coverage, which pays when a vendor’s outage halts your income. Many policies limit or exclude it.

What should I ask my vendors?

  1. What is your plan if you suffer a ransomware attack?
  2. How long would it take to restore service, and have you tested that?
  3. Do you require multi-factor authentication on every remote access system?
  4. How and when will you notify us of an incident?
  5. Do you hold our data, and how is it protected?
  6. Which other companies do you depend on to deliver our service?
  7. What does our contract say about outages and data breaches?

A vendor that can’t answer has told you how prepared it is.

What should I do if a vendor of mine is attacked?

  1. Disconnect from the vendor’s systems until it confirms the connection is safe. Many providers cut their links to Change Healthcare within hours, which protected their own networks.
  2. Change the passwords and keys tied to that vendor.
  3. Switch to your backup process.
  4. Get facts in writing and watch the vendor’s official status page. Be wary of emails and calls that claim to come from the vendor. Scammers exploit every major outage with fake “support” and “payment update” messages.
  5. Call your insurance carrier and your attorney.
  6. Document your losses from the first day: lost revenue, extra labor, loan costs.
  7. Tell your customers or patients what is happening and what you are doing about it.

What does HIPAA say about a breach at a business associate?

Change Healthcare acts as a business associate for many providers and as a clearinghouse in its own right. Under HIPAA, a business associate must notify the covered entity of a breach, and the covered entity carries the duty to notify affected patients, though the two can agree that the business associate will send the notices. The Office for Civil Rights has said its investigation centers on Change Healthcare and UnitedHealth, and it reminded providers of their obligations to have business associate agreements in place and to make sure breach notifications happen.

If you are a provider, find your business associate agreements now and talk with your attorney about how notification will work once the facts are known.

What security lessons apply to my own systems?

The public does not yet know how the attackers entered. The basics that stop most ransomware remain the same:

  • Multi-factor authentication on every remote access point
  • Prompt patching, starting with internet-facing systems
  • Offline, tested backups
  • Endpoint detection and response on servers and workstations
  • A written incident response plan
  • Trained staff

Your next step

Write down the one vendor whose outage would stop your income. Then call a competitor of that vendor and ask what it takes to set up a standby account. Cerberus Cybersecurity helps small businesses and practices map vendor dependencies, write continuity procedures, and meet HIPAA requirements. See our services or contact us.