After the CommonSpirit ransomware attack: Why healthcare M&A poses a 'huge' cybersecurity risk
CommonSpirit Health is still dealing with the aftermath of a ransomware attack three weeks later. Security experts note that M&A and integration in the healthcare industry significantly increase cybersecurity risks, as system integration takes years, supply chains are weak, and executive attention is diverted during M&A. Experts recommend conducting rigorous cybersecurity due diligence before transactions and planning incident response processes in advance.

CommonSpirit Health, formed in 2019 by the merger of Dignity Health and Catholic Health Initiatives, is still dealing with the aftermath three weeks after a ransomware attack. Security experts say such mergers and acquisitions can make healthcare systems more vulnerable to security breaches.
Mergers and acquisitions in the healthcare industry "create enormous risk" and "a great opportunity for ransomware," said Israel Barak, chief information security officer at cybersecurity company Cybereason. The company helps businesses defend against attacks.
Barak added that healthcare deals pose a higher risk of cybersecurity attacks because the systems involved often have weaker supply chains.
Systems like CommonSpirit rely on a vast network of healthcare providers. Most of them are smaller organizations with "very low maturity," but they need to share large amounts of data among themselves, Barak said.
"This leads to a situation where a threat entering from one point of the network can affect a very wide range of entities within that network," Barak said.
Security experts point out that companies undergoing mergers or acquisitions are ideal targets for attackers because executives often focus on other priorities and may not be vigilant enough.
"Whenever there is chaos or uncertainty, attackers will try to take advantage and launch an attack," said Anneka Gupta, chief product officer at data security company Rubrik. Rubrik's clients include some of the largest U.S. companies.
The FBI has warnedthat ransomware attackers tend to target companies undergoing significant financial events, including mergers and acquisitions.
Fitch Ratings analysts said last week that CommonSpirit is in the process of a large debt issuance.
For an entity of this size, integrating onto the same IT platform and systems is not something that can be done overnight.
"Often, IT teams may take years to merge or unify onto a specific technology stack," said Allie Mellen, senior analyst for security and risk at research and consulting firm Forrester.
Although some of CommonSpirit's affiliated systems did not show the same signs of the attack, that does not necessarily mean they have different practices, Mellen said.
"They may have made design decisions to keep them fairly separate from an IT perspective," which could be a potential defense measure, Mellen added.
Due diligence needed before signing merger agreements
Experts say risk assessment needs to begin before the two companies are integrated. Before signing a merger agreement, companies need to scrutinize the cybersecurity risks of the deal with the same critical eye as other factors.
"Cyber due diligence should be included in the analysis along with financial analysis to determine whether merging with a particular entity poses a risk to the organization," said John Riggi, cybersecurity and risk advisor at the American Hospital Association. He declined to comment directly on the CommonSpirit Health incident.
Cybereason's Barak noted that part of this work also involves ensuring that companies do not inherit an attack, which can be difficult because companies are often reluctant to disclose too much information before a deal is completed.
Nevertheless, failures in due diligence should serve as a warning, and PayPal's acquisition in 2017 is a classic example of what not to do before a merger, Barak said.
The digital payments company acquired Canadian payment processing company TIO for $238 million in 2017. Just months after the deal closed, PayPal announced it was suspending TIO's operations after discovering a security vulnerability that exposed the personal information of 1.6 million customers. The company disclosed in its 2017 annual report thatit expected to write down $168 million by 2022, which was a significant portion of the original purchase price.
Hotel chain Marriott International, when it acquired Starwood Hotels & Resorts in 2016,inadvertently inherited a massive data breach. Two years later, Marriott said it learned that hackers had accessed sensitive customer information for four years, affecting 500 million people. The hack did not affect Marriott's properties; hackers breached Starwood's reservation database. According toreports, for a period after the merger, Marriott and Starwood's reservation databases remained separate.
Rubrik's Gupta said the most difficult obstacle is not necessarily technology, but having the right people and processes.
Who is responsible when something goes wrong? Gupta said this is a key question companies need to address before an attack occurs.
This can pose a challenge for healthcare companies that weave together the operations and management of legacy systems across different regions and states across the country.
"Many times, organizations are not prepared. Maybe they have the technology, but they don't even have the response ready for the organization," Gupta said.
A cyberattack is an extremely high-pressure and crisis situation, and it should not be the first time some leaders interact, Gupta said.
If companies have not refined these processes, they may face greater pressure to pay the ransom demanded by attackers to regain access to information or systems.
"From a people, process, and technology perspective, a lot of preparation must be done for organizations to stop paying ransoms," Gupta said.
CommonSpirit was born from a large merger
CommonSpirit is only three years old.
The system was formed in 2019 after a large merger between San Francisco's Dignity Health and Colorado-based Catholic Health Initiatives.
The deal stitched together Dignity's operations in the West with CHI's systems primarily in the Midwest and South.
The merger created one of the largest healthcare systems in the U.S., with 142 hospitals across 21 states and combined revenue of nearly $29 billion in 2019.
At the time, executives claimed CommonSpirit aimed to address pressing national health issues, requiring greater scale and scope to have an impact nationwide.
According to its latest annual report, CommonSpirit now has more than 25,000 physicians and clinicians, as well as more than 2,200 care sites. This does not include all the providers who interact and share information with the system as independent providers.
Healthcare Dive found that affiliated health systems in seven states displayed banners on their websites warning of ongoing IT issues, which may provide clues to the scope of the problem. With one exception, these warnings appeared on CHI websites.
List of website warnings:
- CHI Saint Joseph Health - Kentucky
- CHI Health - Nebraska
- CHI Health - Iowa
- CHI St. Alexius Health - North Dakota
- CHI St. Gabriel's Health - Minnesota
- CHI St. Luke's - Texas
- CHI Baylor St. Luke's - Texas
- Virginia Mason Franciscan Health - Washington
CommonSpirit appears to confirm that the other half of its network, Dignity Health, did not experience the same disruption.
The system said in a recent statement that outpatient or patient care at its Dignity Health affiliated systems, as well as TriHealth and Centura Health facilities, was not affected.
Combined with this statement and online warnings, the attack appears to be more severe for CHI Health entities.
The attack comes at a difficult time for healthcare providers.
CommonSpirit said in its 2022 financial results that the impact of the pandemic continues to weigh on hospital operators. Staffing shortages have driven up more expensive labor costs. The system lost $1.8 billion in 2022.
However, Fitch Ratings said it does not expect a rating adjustment for the system due to the cyberattack. Fitch reported that CommonSpirit has cybersecurity insurance.