Change Healthcare
A remote access portal nobody owned took down a third of US patient records
- 1 in 3
- US patient records touched by the company's transactions
- 94%
- of hospitals surveyed reported a financial impact
- 74%
- reported a direct impact on patient care
- 60%
- needed two to three months to return to normal operations
In February 2024, attackers used stolen credentials to reach a Change Healthcare remote access portal that had no multi-factor authentication on it. UnitedHealth's chief executive told a congressional committee that the company had acquired Change Healthcare in October 2022 and had not finished upgrading its older technology when the attack happened.
The seam. The gap was not a technology decision or a risk decision. It was both at once, sitting in the space between an acquisition and the systems it brought along, and it belonged to nobody in particular until it failed.
Why it is your problem too. Almost no organization has a system that half the country runs through. Most have the smaller version: a vendor inherited from a merger, a portal set up years ago by someone who has since left, a login that never got the same treatment as the rest. The scale differs. The seam does not.
Sources: American Hospital Association, hospital impact survey; AHA report on the congressional hearings