Change Healthcare cyberattack sounds alarm for cybersecurity in the healthcare industry
The Change Healthcare cyberattack has continued to impact the healthcare industry for over a month, prompting deep reflection on cybersecurity and business continuity. Experts urge healthcare organizations to conduct risk analyses, establish vendor redundancies, and pay attention to the federal government's upcoming cybersecurity incentives and penalties.

Following the cyberattack on Change Healthcare, the healthcare industry must take cybersecurity and resilience planning seriously, as attacks may continue to plague the sector, experts told Healthcare Dive.
The disruption at the UnitedHealth Group subsidiary has left the industry struggling for over a month. Providers reported various challenges after the attack, ranging from payment interruptions to delays in prior authorization requests.
"Hospitals have really reported to us that their teams are working weekends and nights," said Molly Smith, vice president of public policy at the American Hospital Association. "They have been working a lot of overtime over the past month."
The financial impact can be severe, especially for smaller providers or those heavily reliant on Change for claims processing. Some hospitals have delayed payments to vendors, drawn on credit lines, or prioritized payroll, Smith said.
But even as Change begins to restore its systems, cyberattacks will remain a challenge for the industry as healthcare digitizes, creating more potential vulnerabilities for cybercriminals to exploit, experts said.
The healthcare industry needs to learn from the widespread impact of the Change attack—and prepare for the next one.
"As an industry, cybersecurity has come a long way, but we are still far behind where we should be," said Steve Cagle, CEO of Clearwater, a healthcare cybersecurity company. "We need to face reality that this problem is here to stay."
Risk analysis and redundancy protect providers
Health systems need to assess their most vulnerable points and how disruptions could affect their finances and operations, experts told Healthcare Dive.
Many providers have not fully mapped their critical business or patient care operations to the IT products that support them, making it difficult to protect these systems or detect intrusions, said Deron Grzetich, cybersecurity business lead at West Monroe.
"If you don't understand what is critical to patient care and the IT, applications, and systems that support that, how do you ensure that you are appropriately protecting them with the right preventive controls?" he said.
Health systems need to conduct risk analyses to determine where data is stored, potential threats and vulnerabilities in systems, implemented controls, the likelihood of an attack, and its potential impact on the organization, Cagle said. This will help them prioritize where to invest resources.
They should also assess third parties and question vendors' cybersecurity protocols to determine what measures should be taken to mitigate high risks. For example, if an organization cannot push a vendor to improve security, the system could consider switching vendors or establishing backups, he said.
Having alternative vendor options for critical operations is often a wise strategy, experts said. Smaller providers with weaker financial positions were more likely to struggle during the Change disruption, according to a March report from Moody's Ratings. Many larger and geographically dispersed organizations used multiple claims clearinghouses, mitigating some revenue losses.
"If you don't understand what is critical to patient care and the IT, applications, and systems that support that, how do you ensure that you are appropriately protecting them with the right preventive controls?"
—Deron Grzetich, cybersecurity business lead at West Monroe
The financial impact of a disruption at a vendor like Change—which processes billions of healthcare transactions annually and touches one-third of medical records—also demonstrates the importance of business planning, experts said. Nearly 60% of hospitals reported revenue impacts of $1 million or more per day due to the Change attack, according to a survey conducted by the American Hospital Association (AHA) in March.
Health systems should evaluate software and service vendors to understand which are critical to their cash flow and what the impact would be if one of those products went down due to a cyberattack, said Kate Festle, partner in West Monroe's healthcare M&A practice.
Small and mid-sized systems may only have 30 to 60 days of cash reserves, which may not be enough in a prolonged disruption.
"The lesson I hope is taken away is that every provider, regardless of size, should do a full diagnostic to determine 'If any of my service or software vendors disappeared or were compromised, how much cash would I need on hand?'" Festle said.
Why providers struggle with cybersecurity investment
In an era of increasing attacks on the healthcare industry, cybersecurity is critical to operations, but many providers have not invested enough resources to prevent incidents or prepare for consequences, experts said.
In healthcare, cybersecurity investment often shows a divide between the haves and have-nots, said Greg Garcia, executive director of cybersecurity at the Health Sector Coordinating Council, an industry group that advises the federal government.
Large health systems may be more advanced in implementing cybersecurity protocols, while smaller or safety-net providers may struggle to find funding or talent to elevate their preparedness.
"There are a lot of hospitals that operate at negative margins on a regular basis. So their ability to access resources is much more difficult," Smith of the AHA said. "And frankly, even getting technology or cybersecurity personnel can be very challenging, especially for independent, smaller facilities."
By the numbers
- 49%: Share of hospitals in 2021 that said they had adequate coverage in supply chain risk management
- 42%: Share of healthcare organizations in a January 2023 survey that had incident response, recovery, and testing plans with vendors and third-party providers
- 755,743: Open positions for cybersecurity professionals nationwide as of March 2023
Sources: HHS 405(d) Program "Hospital Cyber Resiliency Initiative Landscape Analysis"; Ponemon Institute and HSCC "Healthcare Supply Chain Risk Status"
Building vendor redundancy can also be difficult for some providers. Many health systems already want to reduce the number of third parties they contract with to lower costs and management burden.
Establishing relationships with new vendors requires effort, managing more contracts, and continuously paying additional invoices, said Andrew Hajde, director of content and consulting at the Medical Group Management Association.
It may also be difficult to find vendors interested in taking on backup work, he added.
"A lot of vendors don't want to just wait to be paid when they are needed," Hajde said.
There may not even be enough vendors to build redundancy, or their contracts may not allow vendors to work with other companies offering competing products, Smith said.
Additionally, many tools—or most of them—are customized, so switching to a new system or training staff on other products is a challenge, she added.
Federal government pushes cybersecurity investment
Federal regulators have signaled plans to strengthen cybersecurity and resilience in the healthcare industry, eventually imposing financial penalties on hospitals. HHS released voluntary cybersecurity goals earlier this year, divided into essential and enhanced protections, including assessing third-party risks and incident planning and preparation.
The Biden administration's fiscal 2025 budget proposal includes funding for hospitals to implement cyber protections and will roll out penalties in the coming years. The Senate has also recently introduced legislation to allow advance and accelerated payments to providers in the event of an incident, provided that providers and their vendors meet minimum cybersecurity standards.
HHS has been strengthening its cybersecurity strategy for years, said Garcia of HSCC. The performance goals are not mysterious or new—they are basic requirements.
"Now, long-term projects may take years to get right," he said. "Tear up the floorboards, look at the pipes underneath, and see where the leaks are. That is important for us right now."
