Multi-CloudCIO BriefingsRetrospectives

CIO Brief: Change Healthcare and the Systemic Risk of One Missing Control

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from February 2024, written in 2026 with the benefit of hindsight.

The short version: In February 2024, ransomware shut down Change Healthcare, disrupting pharmacies and medical billing across the US for weeks. The attackers reportedly got in through a remote access system that didn't require multi-factor authentication. The company paid a $22 million ransom, and costs reached billions.

Why one missing control can be systemic

Change Healthcare processed a huge share of US medical claims. When it went down, thousands of providers and pharmacies couldn't get paid or process prescriptions normally. A single gap in one system affected an entire sector.

The business impact

  • Operational disruption across customers and partners.
  • Massive data breach affecting a large portion of the US population.
  • Congressional scrutiny of leadership decisions.
  • Costs in the billions.

Questions to ask your team

  • Does every way into our network require multi-factor authentication — no exceptions?
  • How do we confirm acquired companies meet our security baseline?
  • Which of our suppliers would cause a business crisis if they went down for a month?
  • Do we have contingency plans for those suppliers?

What good looks like

MFA everywhere, verified by regular testing; acquisition integration that includes security baselines; and continuity plans for critical suppliers.

The decision

Ask your team for written confirmation that every remote access path requires MFA, including systems from acquisitions. If the answer includes exceptions, close them first.

change healthcare cyber attack impactChange Healthcare2024

More on this story