CyberVitals: Learning from Change

Contributor: Vidya Murthy, WEMBA’42 
To learn more about Vidya, click here.

 

Change Healthcare captured headlines after suffering a cybersecurity attack in late February 2024 that crippled the ability to process medical claims for hundreds of healthcare providers.  Less discussed is that 74% of hospitals said the incident resulted in “direct patient care impact.” At times as many as 2 in every 5 hospitals reported patients couldn’t get access to care due to the inability to get prior authorization.  

The CEO of parent company UnitedHealthcare testified in front of Congress in April, stating a $22 million ransom payment was made for a breach that ultimately began from a failure to enable multi-factor authentication for remote access to a server.  Change Healthcare was a single point of failure for one third of the U.S. population’s data - it’s being called “the Colonial Pipeline incident of healthcare.” 

Multi-factor technology began to get commercialized in the 1990s and really became popular in the mid-2000s. And while healthcare is known to be a decade behind in technology adoption, the global pandemic accelerated adoption to enable the workforce to work safely. And while other industries may be exploring passwordless futures, the continued lag in and insufficient prioritization of security in healthcare are shocking. The notion of attackers being ‘ahead of the game’ is almost moot when the basics of known good security practices have not been implemented. 

This is even more starkly contrasted with the promise of data at scale enabling novel care development, such as the use of artificial intelligence for diagnostic purposes and ‘paving the way to the future.’  

It used to be that cybersecurity in healthcare meant patient health data, which many thought was benign and that sharing information like glucose level readings wouldn’t matter. Then that evolved into insurance account fraud. Now we’re facing a world in which patients cannot get treatment. In other words, we went from the initial concerns about the confidentiality of medical information to concerns about the availability of health services due to system and data availability. 

As outlined in a recent paper, patient survivability for favorable neurological activity dropped ten-fold when the healthcare delivery organization experienced a cyberattack. The quality of care delivery, and consequently the outcome of patients undergoing treatment, is being impacted by poor security practices. 

When will our community say this is enough? 

Government intervention has been ramping up on all sides of the healthcare equation, with particular attention on device manufacturers and hospitals. While many cite the absence of a comprehensive consumer protection plan - which absolutely should be developed - it’s a bit reactive for my tastes. Patients should not be burdened with needing to be educated on security considerations when choosing care. Instead, the complex web of related parties must deliver better to those in need. 

Where can you start to change today? 

  1. Look at your global cybersecurity risk management program. From this review, you should understand the exposure in your organization, the type of data that is riskiest, and the related mitigations. But also think about which functions and processes that data supports - it is not merely a breach of information; it is the assurance of timely and quality care. If that thread of questions can’t be answered, you know where to start. 
  2. Once you’ve defined the scope of highest concern, apply the Pareto Principle and focus on threat modeling, third party management, and trusted communication. 
  3. Lastly, look to your leadership. If there is not active discussion about both the opportunity and threats that come from connectivity in your organization, that’s a big gap. Take the opportunity to raise the importance of cyber resilience and the need for business continuity/disaster recovery planning. 

The entire Change Healthcare experience should serve as a wake-up call to the healthcare industry, highlighting the urgency and importance of managing risks through both proactive and reactive measures.


Contact Vidya at: [email protected]