Change Healthcare’s Mega Attack: 1 Year Later

Ransomware Attack Taught Lessons on Health Sector Resiliency, Vendor Redundancy
It’s been one year since Russian-speaking hackers unleashed ransomware on UnitedHealth Group’s Change Healthcare IT services unit.
“The incident was an eye-opener because no one in the industry really realized how entrenched Change was in healthcare delivery,” said Denise Anderson, president of the Health Information Sharing and Analysis Center (Health-ISAC.)
Unfortunately, concentration risk is a huge issue – and not just in healthcare – as illustrated by other incidents such as the July 2024 CrowdStrike outage – caused by a faulty software update, she said.
“A lot of healthcare organizations rely on the same vendor or set of vendors to deliver services – and if that vendor is impacted by an incident, it can have cascading effects across the sector,” she said.
“Prevention strategies include MFA, endpoint protection, offline backups, regular patching, email security and network segmentation,” Anderson said.
“But C-suite buy-in is critical – investing in security upfront saves millions in recovery costs,” she said.
Read the full article in Healthcare InfoSecurity. Click Here
Topics include:
- Falling Through the Cracks
- Data Retention Blunders
- Here Come the Feds
- Related Resources & News
- 2025 Newsletter – March
- Health-ISAC 2024 Annual Report
- Healthcare Cyberattacks Continue to Escalate in 2025
- Trump’s CISA Cutbacks Worry Cybersecurity Pros
- Top 5 cybersecurity concerns for healthcare in 2025
- Health Systems Must Develop Plans to Assume Cyber Responsibility for Medical Devices When Manufacturer Support Wanes
- Health-ISAC Finds Ransomware & Third-Party Breaches Dominate 2025 Threats
- ISAC chief on CISA security rollbacks: ‘The sky isn’t falling, yet’
- Building a Collective Defense: Collaborative Threat Intelligence and Information Sharing for Critical Infrastructure
- Healthcare Heartbeat 2024 Q4