Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Critical Infrastructure Security - Beyond the Breach: The Ongoing Impact of the Change Healthcare Attack
Critical Infrastructure Security Articles Business and Policy Business Continuity and Disaster Recovery Security

Beyond the Breach: The Ongoing Impact of the Change Healthcare Attack

Michael GrayBy Michael GrayApril 10, 20256 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Change Healthcare Attack
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In February 2024, Change Healthcare was the target of a massive ransomware attack that is now known as the most significant data breach in American history.

Thousands of healthcare providers across the country rely on Change Healthcare’s solutions and services, including the exchange of healthcare data and financial transactions between healthcare providers, insurers, and patients. The fallout from the attack led to months of outages for these organizations, and healthcare providers had to turn away patients and cancel appointments until they could recoup their systems. Eventually, United Health Group, the parent company of Change Healthcare, was forced to pay the attackers a $22 million ransom to prevent patient data from leaking.

The Change Healthcare data breach demonstrated how much an indirect attack can impact an organization and the critical need for having the right cybersecurity protocols in place. Organizations both in and outside of healthcare rely on third-party vendors, opening new vulnerabilities that could have an immense impact on operations if not addressed. Luckily, every company can learn from the Change Healthcare attack and use those lessons to build more substantial and secure operations.

Carefully Assess Third-Party Vendors

Healthcare providers often rely on third-party vendors for various services, including patient-facing applications, telemedicine services, billing, and secure data processing. Smaller organizations, especially, would not be able to offer these services without the help of a third-party provider, which makes these vendors, like Change Healthcare, a necessity to get patients what they need and keep operations running.

However, despite their benefits, going into business with another entity always presents risks. Because these partners become integrated into systems, they also have access to sensitive patient data and the healthcare organization’s financial transactions. Giving another organization access to this data requires extra security measures.

This is not unique to healthcare—other industries that consumers rely on every day use third-party vendors for different services as well. This makes it imperative for organizations to evaluate potential third-party vendors and partners before engaging with them. Undergoing an evaluation ensures that third-party organizations can be trusted to keep sensitive data safe and are relied on for continuous operations. Organizations should know that their vendor can be trusted with their data, their services are reliable, and the organization follows their industry’s regulatory requirements.

To ensure they cover their bases before entering an agreement with a partner vendor, organizations must take the appropriate steps to check that this third party has experience working in their industry and meets a security standard that aligns with theirs. These preemptive steps should also include auditing security practices, identifying vulnerabilities, and having proper measures and protocols in place for times of crisis. This type of business relationship should be viewed as a long-term, continuous effort to keep data and operations safe and secure from rising threats.

Keys to a Successful Security Audit

Security audits assess an organization’s cybersecurity strengths and weaknesses. Using this information, organizations can change security policies, address vulnerabilities, and decide whether to work with a third-party organization. 

Businesses should have defined objectives when conducting a third-party audit. These goals focus the audit on specific areas of the organization, whether that’s critical business applications that handle sensitive information or security-related processes. The employees performing the audit should be well-versed in the areas under review, whether it’s staff members or external consultants. They should review system activity logs and security documents and interview staff members before documenting all information gathered on systems, processes, and technical assessments.

The audit team should use the information to assess risk, identify vulnerabilities, and forecast the impact a potential cybersecurity attack could have. Once information gathering and assessments are complete, the team should identify problems and evaluate whether the third-party organization meets regulatory and security standards to a sufficient level and whether improvements should be made through solutions or new processes.  

Business Continuity Plans Are Critical

No cybersecurity solution or vendor can guarantee that there will never be a breach, and no solution or environment is completely secure. This is why organizations should treat attacks as an eventuality. Having this mindset will help them prepare for the worst-case scenario and build the right plans to address a crisis swiftly.

Disaster recovery and business continuity plans help organizations be resilient and navigate tough waters. Every company should have a business continuity plan in place before a crisis occurs. This plan should be highly structured, approved by senior management, and prioritize critical operations during a crisis. Organizations should map out critical processes to continue productivity and fast recovery during downtime. Can an organization schedule appointments, process transactions, or retrieve patient information? If not, what can they do instead to operate? Assessing the impact disruptions can have on service delivery will help determine how long business processes can continue without them.

It’s imperative for all employees involved to be on the same page by detailing and documenting workaround plans. They must know what to do and how their roles may change during a breach. Organizations should hold mock scenarios during training sessions of critical systems going down and have staff members practice what to do in accordance with their business continuity plan playbook. Then, organizations can improve and adjust their processes even further based on these mock scenarios.

Always Be Aware of Risk

Change Healthcare fully displayed the lasting damage just one attack can have on an entire industry. There are longstanding consequences, including financial and reputational damage. Not only did this attack immediately impact productivity and the organization’s bottom line, but it also made the brand name synonymous with data breaches, even today. Any organization, large or small, could be the next Change Healthcare and be impacted by a severe attack.

But organizations, including healthcare providers, are not on an island fighting off cyberthreats. There is a community within the industry to help each other learn from past challenges, communicate trends and best practices, and prepare for the future. Collaboration and dialogue among industry peers toward a common goal and shared cause will help organizations of any industry stay safe. As cybersecurity threats continue to grow in tenacity and volume, it’s more important than ever for organizations to stay prepared and continuously work on cybersecurity standards. 

Michael Gray
Michael Gray

Michael Gray has been a strong technology leader at Thrive over the past decade, contributing to consulting, network engineering, and managed services and product development groups while continually being promoted up the ladder. Michael has a degree in Business Administration from Northeastern University, and he also maintains multiple technical certifications, including Fortinet, Sonicwall, Microsoft, ITIL, and Kaseya, and maintains his Certified Information Systems Security Professional (CISSP).

  • Michael Gray
    Rethinking the Security Estate: Why IT Spend Isn’t the Same as Cybersecurity Readiness
  • Michael Gray
    The Biggest Cybersecurity Threats to Watch Out For in 2025
  • Michael Gray
    Educate, Prepare, & Mitigate: The Keys to Unlocking Cyber Resilience

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The evolution of cyber risk: Addressing geopolitical threats

May 13, 20265 Mins Read

“Recovery Is the New Prevention”: a Q&A with CSO of Health-ISAC, Errol Weiss

May 7, 20266 Mins Read

Pro-Russian threat actors target Swedish heat and power plant in failed cyberattack

April 20, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}