Skip to main content

Change Healthcare suffers ransomware attack with healthcare impact

Reuters reported that BlackCat/ALPHV was behind the outage at Change Healthcare, a technology unit of UnitedHealth.

CybersecuritySeintec Team2-3 min read
Change Healthcare suffers ransomware attack with healthcare impact

News summary

Reuters reported that BlackCat/ALPHV was behind the outage at Change Healthcare, a technology unit of UnitedHealth. The incident affected prescription, payment and healthcare service processes for days; subsequent investigations pointed to the use of compromised credentials.

When a provider occupies a central position in a service chain, its failure can cascade to thousands of clients. Critical dependencies, recoverable backups and alternative procedures are part of business continuity.

Source: Reuters — 26 February 2024

What happened

On 21 February 2024 Change Healthcare, the UnitedHealth subsidiary that processes payments and prescriptions for much of the US healthcare system, was hit by ransomware attributed to BlackCat/ALPHV. Pharmacies, clinics and hospitals struggled to bill and dispense for weeks.

Testifying before the US Congress, UnitedHealth's CEO acknowledged that the attackers used stolen credentials on a remote-access portal without multi-factor authentication, and that the company paid a USD 22 million ransom.

What it teaches any organisation

A single remote access point without MFA was enough to paralyse a central provider relied on by thousands of customers. It's a reminder that basic controls, applied without exceptions, remain the most effective.

For sectors such as health and social care, it also shows the knock-on effect of relying on a single technology intermediary.

What to review

Checks directly linked to this incident:

  • That every remote access, without exception, requires MFA.
  • An inventory of portals, VPNs and remote desktops exposed to the internet.
  • Recoverable, isolated backups of billing and management systems.
  • Fallback procedures if a critical supplier stops working.

Frequently Asked Questions

How did the attackers get in?
According to UnitedHealth, with stolen credentials on a remote-access portal without MFA.
Did paying the ransom solve the problem?
Not entirely: recovery took weeks and the company continued dealing with the data consequences.
What is the first control to check?
That no remote access to the corporate network exists without MFA.

Concepts mentioned in this article: Backup · Business continuity · Ransomware

If you wish to strengthen the security, continuity and performance of your infrastructure, Seintec can support you from diagnosis through to implementation. Contact us to speak with a specialist.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.