Organizations should fix internet-facing remote access first by requiring phishing-resistant multifactor authentication and continuously tracking every exposed service. They should then limit lateral movement, prepare tested recovery paths, centralize logs, and include critical vendors in incident drills. The Change Healthcare breach showed why these controls belong to one resilience program. A stolen credential became a nationwide disruption affecting healthcare payments, provider cash flow, and the privacy of roughly 190 million people.
Table of Contents
- How one exposed portal led to a crisis
- Fix remote access before less urgent gaps
- Contain intruders and preserve essential operations
- Treat vendor concentration as an operational risk
- Separate confirmed impact from unresolved risk
How one exposed portal led to a crisis
Change healthcare processes healthcare transactions involving patients, providers, and payers. According to UnitedHealth Group's May 2024 testimony, criminals used compromised credentials to enter a Citrix remote-desktop portal on February 12, 2024. The portal did not require multifactor authentication. The attackers moved laterally through Change's environment and removed data.
Nine days after the initial access, ALPHV/BlackCat deployed ransomware. UnitedHealth severed data-center connectivity to contain the attack and reported no evidence that it spread to external organizations or other UnitedHealth environments. That sequence exposes three separate control failures: an account could reach an external service with one factor, the intruders could move beyond the entry point, and the compromise continued before ransomware made it visible. Preventing the first step matters, but organizations must also assume that some credentials and controls will fail.
Fix remote access before less urgent gaps
Every internet-accessible remote service should require phishing-resistant MFA. Unlike weaker methods, phishing-resistant authentication is designed to stop users from surrendering a reusable login factor to a fraudulent site. Organizations also need a continuously maintained inventory of remote services.
An MFA policy cannot protect a portal that security teams do not know exists or mistakenly believe is covered. HHS identifies remote-access MFA and asset inventory as important protections for accounts and systems exposed to the internet in its Healthcare Cybersecurity Performance Goals. A practical first review should cover: Treat any unexplained MFA exception as a time-bound risk decision. Assign an owner, document the operational need, restrict the account's reach, and set a deadline to remove the exception.
- Remote desktops, virtual private networks, support portals, and administrative consoles.
- Accounts exempted from MFA, including vendor, legacy, emergency, and service accounts.
- Authentication methods vulnerable to phishing or push-notification fatigue.
- Systems accessible through forgotten hostnames, old contracts, or vendor-managed infrastructure.
- Ownership, patching responsibility, logging status, and retirement dates for each exposed service.
Contain intruders and preserve essential operations
Segmentation should prevent a compromised remote-access account from becoming a route into mission-critical systems. Separate administrative paths, user environments, sensitive data, and care-critical transaction systems. Access between segments should be limited to necessary, monitored connections. Centralized logs must give responders enough visibility to reconstruct activity across identity systems, remote services, endpoints, and network boundaries. Alerts are useful only if staff can connect them quickly and preserve the records needed to determine what attackers accessed.
Recovery planning must address business operations, not merely server restoration. Change Healthcare's outage disrupted the movement of funds so severely that CMS relaxed certain Medicaid enforcement conditions to help maintain services, avoid negative health outcomes, and reduce provider-solvency risk. UnitedHealth later reported more than $9 billion in interest-free provider loans, $2.2 billion in direct 2024 response costs, and $867 million in business-disruption impact in its 2024 Form 10-K. Recovery exercises should therefore test concrete dependencies: how claims or payments continue, how providers obtain working capital, who authorizes isolation decisions, and which minimum services must return first. Backups must be separate, restorable, and tested against defined recovery targets.
Treat vendor concentration as an operational risk
A critical vendor can become a single point of failure even when an organization's own network remains uncompromised. Map which outside services handle sensitive data, payments, authorizations, or other essential workflows. Then identify what stops when each service becomes unavailable. Incident exercises should include those vendors rather than assuming they will participate smoothly during a crisis.
Test notification routes, decision authority, secure information sharing, manual alternatives, and restoration priorities. Contracts and business-associate agreements should assign responsibilities clearly, but paperwork does not replace an executable fallback. Organizations covered by HIPAA also retain duties when a business associate suffers a breach. HHS OCR opened prioritized investigations into Change Healthcare and UnitedHealth and reminded affected covered entities about appropriate business-associate agreements and timely notifications in its Change Healthcare incident guidance.
Separate confirmed impact from unresolved risk
UnitedHealth estimated that approximately 190 million people were affected. The population principally at risk includes patients, providers, and payers whose information passed through Change Healthcare. UnitedHealth reported no known misuse and said reviewed data did not include electronic medical-record databases. Those are important limits, but they are company-reported findings.
They do not mean that exposed information was harmless or that affected organizations can ignore their own investigation and notification duties. Organizations should preserve that distinction in public statements. State what evidence confirms, identify what remains under review, and avoid presenting "no known misuse" as proof that misuse cannot occur. HHS has also proposed stronger HIPAA Security Rule requirements involving MFA, segmentation, backup and recovery controls, recurring testing, and defined restoration procedures. The proposal signals regulatory direction, but it was not finalized in the supplied evidence and should not be described as current binding law.
You Might Also Like
- Cybersecurity — Identity Theft: What Organizations Should Fix Next
- My Child Received a Healthcare Data Breach Letter: What Records Should I Keep?
- Healthcare Data Breach News Explained for 2026: Who It Affects, Key Evidence, and What to Do Next