Change Healthcare: Ransomware Resilience Lessons
The February 2024 attack on Change Healthcare disrupted pharmacy, claims, and payment services across the United States. UnitedHealth Group's restoration updates described phased recovery and financial support for care providers affected by the interruption.
The event showed how a cyber incident at a concentrated service provider can become a continuity problem for organizations that were not themselves directly compromised.
Dependency concentration amplified the disruption
Healthcare organizations relied on connected clearinghouse and payment functions to deliver care and maintain cash flow. When those services became unavailable, local continuity depended on alternative workflows, current contact routes, and the ability to reconcile delayed transactions.
A vendor risk register that records only questionnaire scores will not reveal this operational dependency. Teams need to know which business process stops, how quickly, and what safe workaround exists.
Plan continuity with critical suppliers
Map vendors to business services, data flows, authentication, transaction volume, recovery objectives, and substitutes. Require incident notification and recovery communication routes that remain available when the normal portal is down.
Exercise manual or alternate processes with operations, finance, privacy, legal, and customer-facing teams. After restoration, reconcile transactions, access changes, temporary exceptions, and data handling before declaring recovery complete.
- Identify single-provider and single-interface dependencies.
- Document minimum viable operations during supplier outages.
- Protect emergency changes with expiry and review.
- Include cash-flow and customer-impact decisions in cyber tabletops.
Put the lesson into practice
- Map critical third parties to service and data dependencies.
- Set recovery and notification expectations contractually.
- Create safe alternative operating procedures.
- Exercise a multi-day supplier outage.
- Reconcile temporary workarounds after service restoration.
Related Outfaze guidance
- Security incident and crisis support
- Anti-ransomware services
- Compliance as a Service
- Data loss prevention
- Incident response plan for small IT teams
