EPISODE · Jun 2, 2026 · 9 MIN
How One Reused Password Cost Change Healthcare $2.5 Billion (Healthcare Security, Part 1)
from Ignition by RocketTools · host Dan McCoy, MD
In February 2024, hackers walked into the largest healthcare clearinghouse in America through a Citrix portal that didn't have multi-factor authentication. They used credentials stolen from a previous breach — someone, somewhere, had reused their password. Within hours they had ransomware running. Within days, pharmacies across the country couldn't fill prescriptions.The ransom payment was $22 million in Bitcoin. The total cost to UnitedHealth Group is now over $2.457 billion. The number of Americans whose data was exposed is 192.7 million — roughly 58% of the country. And it all started with one reused password.This is Part 1 of an 8-part Healthcare Security series. In this episode I walk through why your password habits are probably just as dangerous, why "47 logins" understates the reality for healthcare executives, and the four password managers I actually recommend — with the honest tradeoff on each, and no affiliate links. I also explain why a single patient record sells for $250 on the dark web while a credit card goes for $5, and why your AI tool account in 2026 holds more sensitive information than most of your work files.In this episode:The Change Healthcare breach timeline and what Andrew Witty admitted under oath to CongressWhy password patterns ("FirstName2024!" and friends) are now exactly what attackers test firstThe 47-logins-on-average problem for healthcare execs and why the real number is higherThe four password managers I'd recommend: Dashlane, 1Password, Proton Pass, and Bitwarden — pricing, tradeoffs, who each is right forA four-step action plan you can run this week, starting with one email to your IT team📺 Watch on YouTube: https://youtu.be/N62kieISWiI📝 Read the director's cut companion post on Substack (deeper on Witty's Senate testimony, the dark web pricing texture, and the AI tool risk section I had to cut for time): https://open.substack.com/pub/danmccoymd/p/the-872m-password-mistake-was-actuallyNext week, Part 2: why CISA and the FBI told Americans to stop using SMS-based MFA, the authenticator app I switched to after leaving Microsoft Authenticator, and the small piece of hardware I added on top.I'm Dan McCoy. Ignition by RocketTools is the podcast for healthcare executives, physicians, and AI builders trying to think clearly about where this is all going.
Embed this episode
What this episode covers
In February 2024, hackers walked into the largest healthcare clearinghouse in America through a Citrix portal that didn't have multi-factor authentication. They used credentials stolen from a previous breach — someone, somewhere, had reused their password. Within hours they had ransomware running. Within days, pharmacies across the country couldn't fill prescriptions. The ransom payment was $22 million in Bitcoin. The total cost to UnitedHealth Group is now over $2.457 billion. The number of ...
Ready to play
How One Reused Password Cost Change Healthcare $2.5 Billion (Healthcare Security, Part 1)
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.