The US Department of Health and Human Services (HHS) is increasing scrutiny of third-party service provider cybersecurity in the healthcare sector following the 2024 Change Healthcare cyberattack, which HHS officials describe as having threatened the “liquidity” of the broader healthcare system. HHS’s Charlee Hess (Administration for Strategy Preparedness and Response) said the incident exposed previously underappreciated systemic risk from external vendors that can have outsized sector-wide impact, and noted HHS is working through a methodology—alongside industry—to identify where those critical third-party dependencies and risk concentrations exist.
Reporting reiterated that the Change Healthcare intrusion began with attackers exploiting the lack of multi-factor authentication (MFA) on a remote access portal and ultimately exposed data affecting roughly 190 million people. The breach has also driven broader government and industry responses, including proposals for mandatory cybersecurity requirements on hospitals (which healthcare organizations have opposed as burdensome, arguing the Change Healthcare compromise originated with an external vendor) and remediation actions by UnitedHealth Group (Change Healthcare’s parent) to “start over” on aspects of its systems and technology environment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By February 2026, HHS said it was prioritizing the security of third-party service providers and working with industry on a methodology to identify critical dependencies. Officials said the Change Healthcare attack revealed previously underrecognized third-party risks with potentially systemic impact.
In the wake of the Change Healthcare incident, multiple proposals were introduced to impose mandatory cybersecurity requirements on hospitals. Parts of the healthcare industry opposed the measures, arguing the Change Healthcare compromise stemmed from an external vendor rather than hospitals themselves.
The breach prompted additional scrutiny from U.S. government officials and Congress over cybersecurity risks in the healthcare sector. It also fueled policy debate over how to address systemic cyber risk tied to major service providers.
Following the attack, UnitedHealth Group, Change Healthcare's parent company, rebuilt or restarted its use of computer systems. This response reflected the severity of the compromise and recovery effort.
The Change Healthcare breach had broad sector-wide consequences, reportedly threatening healthcare system liquidity and exposing data affecting about 190 million people. The scale of the incident highlighted how a compromise at a single vendor could have outsized effects across the industry.
In 2024, attackers compromised Change Healthcare by exploiting the absence of multifactor authentication on a remote access portal. The incident became a major cyberattack affecting a critical third-party provider in the U.S. healthcare sector.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.