Skip to main content
Subscribe
  • Login
  • My Account
  • Logout
  • Register For Free
  • Subscribe
  • News
    • Current News
    • Providers
    • Insurance
    • Government
    • Finance
    • Technology
    • Safety & Quality
    • Digital Health
    • Transformation
    • ESG
    • People
    • Regional News
    • Digital Edition (Web Version)
    • Patients
    • Operations
    • Care Delivery
    • Payment
    • Midwest
    • Northeast
    • South
    • West
  • Blogs
    • AI
    • Deals
    • Layoff Tracker
    • HLTH 2024
    • Sponsored Content: Vital Signs Blog
  • Opinion
    • Letters
    • From the Editor
  • Events & Awards
    • Awards
    • Conferences
    • Galas
    • Virtual Briefings
    • Webinars
    • Nominate/Eligibility
    • 100 Most Influential People
    • 50 Most Influential Clinical Executives
    • 40 Under 40
    • Best Places to Work in Healthcare
    • Healthcare Marketing Impact Awards
    • Innovators Awards
    • Diversity Leaders
    • Leading Women
    • Best in Business Awards
    • The 2030 Playbook Conference
    • Innovations in Patient Experience
    • Leading Women Conference & Awards Luncheon
    • Leadership Summit
    • Workforce Summit
    • Best Places to Work Awards Gala
    • Diversity Leaders Gala
    • - Looking Ahead to 2025
    • - Financial Growth
    • - Hospital of the Future
    • - Value Based Care
    • - Looking Ahead to 2026
  • Multimedia
    • Podcast - Beyond the Byline
    • Sponsored Podcast - Healthcare Insider
    • Sponsored Video Series - One on One
    • Sponsored Video Series - Checking In with Dan Peres
  • Data & Insights
    • Data & Insights Home
    • Hospital Financials
    • Staffing & Compensation
    • Quality & Safety
    • Mergers & Acquisitions
    • Skilled Nursing Facilities
    • Data Archive
    • Resource Guide: By the Numbers
    • Surveys
    • Data Points
  • Newsletters
  • MORE+
    • Contact Us
    • Advertise
    • Media Kit
    • Jobs
    • People on the Move
    • Reprints & Licensing
    • Sponsored Content
MENU
Breadcrumb
  1. Home
  2. Cybersecurity
February 29, 2024 05:00 AM

Change Healthcare attack: What to know about cybersecurity

Gabriel Perna
  • Tweet
  • Share
  • Share
  • Email
  • More
    Reprints Print
    data cybersecurity medical
    MH Illustration/Adobe Stock

    The cyberattack on Change Healthcare is the latest sign that the healthcare industry is under siege from bad actors.

    Change Healthcare, a division of UnitedHealth Group, has experienced outages since last Wednesday following a cybersecurity issue. The company pointed to a "nation-state associated" threat, while Reuters reported a ransomware collective known as BlackCat, also called ALPHV or Noberus, is to blame. The network disruptions have hindered electronic transactions between pharmacies and payers and led the American Hospital Association to recommend that its member hospitals disconnect from Change’s systems. 

    LATEST UPDATE: Change outage caused by ransomware group, UnitedHealth says

    The incident comes only a few weeks after a hack by a known criminal actor caused significant disruption at Chicago-based Lurie Children’s Hospital. Lurie took its network offline Jan. 31 in response to the threat, with the outage lasting more than two weeks. 

    The breaches are the most recent evidence of a growing cybersecurity problem facing the healthcare industry. Here’s what you should know about how the issues have escalated and what experts believe is coming next for the sector.

    Data breaches in healthcare: How many have been exposed?

    A record 133 million individuals were potentially affected by healthcare data breaches reported in 2023, more than double the previous year. The number is equivalent to almost 40% of the U.S. population.

    The number of reported breaches affecting 500 or more individuals also hit a new high of 739 in 2023 compared with 720 in 2022, according to the latest data posted to the Health and Human Services Department's Office for Civil Rights breach portal.

    This year is already off to an ominous start. As of Feb. 21, about 11.6 million people had their data exposed in 2024 from 79 reported breaches affecting 500 or more individuals, according to the OCR portal's most recent update. The number doesn’t include the Change Healthcare and Lurie Children’s breaches. 

    Not every breach stems from a cyberattack, such as when a bad actor holds information ransom or steals it to sell. An accidental exposure of protected health information by a third-party vendor can also be classified as a breach, as can a physical theft like a laptop being stolen. Still, roughly 80% of the data breaches last year were from a hacking or IT incident. Breach-related network outages aren't always directly the result of hackers, either, but from companies disconnecting systems until detected threats are contained.

    Why have threats against health organizations worsened? 

    Cliff Steinhauer, director of information security and engagement at the nonprofit organization National Cybersecurity Alliance, said hackers’ attitudes have gotten worse and the healthcare industry has suffered.

    “We have seen the ethics of the hackers really reach new lows,” Steinhauer said. “There is no organization that they won't attack when it comes to innocent people. We're talking about children's hospitals, kids’ cancer organizations, it doesn't seem to matter anymore. They used to not attack hospitals, but now there’s really nothing holding them back.”

    John Riggi, AHA national adviser for cybersecurity and risk, previously told Modern Healthcare third-party vendors and tech companies operating in the U.S. healthcare system are becoming targets for hacking groups or criminal organizations based primarily in Russia, China, North Korea and Iran. Change Healthcare blamed its incident on a foreign government-associated actor.

    How much have health systems spent on cybersecurity?  

    Until recently, many healthcare organizations have not given information security executives the resources and staffing necessary to build out better cybersecurity programs, experts said.

    A December survey of 100 health system chief information security officers conducted by executive search firm WittKieffer found half of organizations spent between 5% and 9% of their IT or other departmental budgets on information security.

    But even these results represent a step in the right direction, said Zachary Durst, an information security consultant at WittKieffer. 

    “About 20% of your IT budget should be on cybersecurity depending on the metric you use,” Durst said. “If you went back a few years, those numbers wouldn't be as high as they are even today.” 

    Only 4% of respondents said their organizations spent more than 15% of their IT budgets on cybersecurity.

    Leaders are starting to recognize the need for better defenses, however. Health system C-Suite executives are making cybersecurity their top IT budget priority this year, according to a November survey from consulting company Guidehouse. 

    Many companies will still face challenges, Steinhauer said.

    “If you're a smaller organization, you may not have the resources to invest in establishing a robust cybersecurity program,” he said.

    How has the government responded to increased threats? 

    Several departments within the federal government have offered help to the healthcare industry. In October, HHS and the Cybersecurity and Infrastructure Security Agency released a cybersecurity toolkit for healthcare organizations. A few months later, HHS issued a healthcare-specific guidance and a voluntary performance goal framework.

    The Federal Bureau of Investigation, CISA and HHS on Tuesday shared an updated advisory regarding BlackCat ransomware and its effect on the healthcare sector.

    Can the attack on Change Healthcare lead to change? 

    The Change Healthcare cybersecurity incident should help more organizations understand no one is immune to this problem, experts said. When a company the size of Change Healthcare, which manages 15 billion transactions a year, gets hacked, it will force many healthcare organizations to look at their own cybersecurity protocols, said Nicholas Giannas, principal at WittKieffer. 

    Steinhauer said victimized organizations need to be more transparent about how these incidents occur and what people can learn from their mistakes. 

    Still, he's not hopeful the Change Healthcare cyberattack will spur an industry-wide transformation in terms of attitudes or resources.

    “A lot of security people that have been doing this for a long time are pessimistic. Unfortunately, I'm starting to cross over into that side of things,” Steinhauer said. “I would love to see real progress made but it’s been really slow.”

    Correction: An earlier version of this article incorrectly said CISA, FBI, HHS issued the advisory regarding BlackCat ransomware Wednesday. 

    Related Articles
    Change Healthcare outage lingers as AHA urges caution
    Network disruptions persist after Change Healthcare cyberattack
    HHS task force wants cybersecurity treated as a patient safety issue
    Healthcare data breaches caused by hacks are on the rise
    Letter
    to the
    Editor

    Send us a letter

    Have an opinion about this story? Click here to submit a Letter to the Editor, and we may publish it in print.

    Recommended for You
    Hospital data breach 0724
    Ascension vendor data breach affects patients in 5 states
    data-hacking-cybersecurity-0125
    Yale New Haven Health hack affects more than 5.5M people
    Most Popular
    1
    UnitedHealth under criminal investigation for Medicare fraud: WSJ
    2
    States, providers face brunt of GOP Medicaid cuts plan
    3
    UnitedHealth Group to cut Medicare drug plan commissions
    4
    Federal dementia pilot has rocky rollout for some providers
    5
    'Legendary' Hemsley takes over at UnitedHealth amid rough seas
    Sponsored Content
    Get Newsletters

    Sign up for enewsletters and alerts to receive breaking news and in-depth coverage of healthcare events and trends, as they happen, right to your inbox.

    Subscribe Today
    MH Magazine Cover

    MH magazine offers content that sheds light on healthcare leaders’ complex choices and touch points—from strategy, governance, leadership development and finance to operations, clinical care, and marketing.

    Subscribe
    Connect with Us
    • LinkedIn
    • Twitter
    • Facebook
    • RSS

    Our Mission

    Modern Healthcare empowers industry leaders to succeed by providing unbiased reporting of the news, insights, analysis and data.

    Contact Us

    (877) 812-1581

    Email us

     

    Resources
    • Contact Us
    • Help Center
    • Advertise with Us
    • Ad Choices
    • Sitemap
    Editorial Dept
    • Submission Guidelines
    • Code of Ethics
    • Awards
    • About Us
    Legal
    • Terms and Conditions
    • Privacy Policy
    • Privacy Request
    Modern Healthcare
    Copyright © 1996-2025. Crain Communications, Inc. All Rights Reserved.
    • News
      • Current News
      • Providers
      • Insurance
      • Government
      • Finance
      • Technology
      • Safety & Quality
      • Digital Health
      • Transformation
        • Patients
        • Operations
        • Care Delivery
        • Payment
      • ESG
      • People
      • Regional News
        • Midwest
        • Northeast
        • South
        • West
      • Digital Edition (Web Version)
    • Blogs
      • AI
      • Deals
      • Layoff Tracker
      • HLTH 2024
      • Sponsored Content: Vital Signs Blog
    • Opinion
      • Letters
      • From the Editor
    • Events & Awards
      • Awards
        • Nominate/Eligibility
        • 100 Most Influential People
        • 50 Most Influential Clinical Executives
        • 40 Under 40
        • Best Places to Work in Healthcare
        • Healthcare Marketing Impact Awards
        • Innovators Awards
        • Diversity Leaders
        • Leading Women
        • Best in Business Awards
      • Conferences
        • The 2030 Playbook Conference
        • Innovations in Patient Experience
        • Leading Women Conference & Awards Luncheon
        • Leadership Summit
        • Workforce Summit
      • Galas
        • Best Places to Work Awards Gala
        • Diversity Leaders Gala
      • Virtual Briefings
        • - Looking Ahead to 2025
        • - Financial Growth
        • - Hospital of the Future
        • - Value Based Care
        • - Looking Ahead to 2026
      • Webinars
    • Multimedia
      • Podcast - Beyond the Byline
      • Sponsored Podcast - Healthcare Insider
      • Sponsored Video Series - One on One
      • Sponsored Video Series - Checking In with Dan Peres
    • Data & Insights
      • Data & Insights Home
      • Hospital Financials
      • Staffing & Compensation
      • Quality & Safety
      • Mergers & Acquisitions
      • Skilled Nursing Facilities
      • Data Archive
      • Resource Guide: By the Numbers
      • Surveys
      • Data Points
    • Newsletters
    • MORE+
      • Contact Us
      • Advertise
      • Media Kit
      • Jobs
      • People on the Move
      • Reprints & Licensing
      • Sponsored Content