I'm Mary Ann Kolbesec-McGee, Executive Editor at Information Security Media Group. Today, I'm speaking with attorney Sarah Goldstein of the law firm Baker Hostetler. We're going to be discussing the impact of the recent Change Healthcare cyberattack and similar incidents on the healthcare sector. So, Sarah, just set the stage for our listeners.
Change Healthcare, which Optum, a subsidiary of UnitedHealth Group, acquired in 2022, disconnected its IT systems on February 21st following a cyberattack that the company said it believed involved a nation-state threat actor. Ransomware group Blackcat has since claimed responsibility for the attack. More than 100 Change Healthcare IT software products, including revenue cycle management and pharmacy claims processing applications, have been offline since the attack, affecting retail pharmacy chains, military hospital and clinic pharmacies, and many other healthcare sector entities. So, Sarah, just to set the stage for our listeners, Change Healthcare, which Optum, a subsidiary of UnitedHealth Group, acquired in 2022, disconnected its IT systems on February 21st following a cyberattack that the company said it believed involved a nation-state threat actor.
Ransomware group Blackcat has since claimed responsibility for the attack. More than 100 Change Healthcare IT software products, including revenue cycle management and pharmacy claims processing applications, have been offline since the attack, affecting retail pharmacy chains, military hospital and clinic pharmacies, and many other healthcare sector entities. So, based on what you're hearing from clients and others in the healthcare sector, how extensive is this impact of the Change Healthcare attack so far on the healthcare sector? My law firm, Baker Hostetler, we're representing dozens of entities in healthcare, ranging from healthcare providers, healthcare systems, healthcare plans.
And this incident is just having a tremendous widespread impact on the entire industry. As you mentioned, Change Healthcare provides many different services to healthcare organizations. And I read that according to Change Healthcare, they handle 15 billion transactions a year. And those transactions involve at least one in three U.S.
patient records. So, the volume of information that's transferred to them and that's transferred out, as well as sort of the role that they have in healthcare, is tremendous. So, some of our clients have some disruption to their operations and others, this is really substantial because they utilize many of Change Healthcare's services, whether it's for eligibility checks to determine whether a patient's insurance is going to cover treatment, or they utilize it for their pharmacy claims, payments, provider payments. So, the impact on this has been substantial.
So, Sarah, with that said, what kind of questions are you getting from health sector entities that have been disrupted or somehow otherwise affected by the Change Healthcare outage? Are they concerned about potential compromises involving their patients' data? Are they having to fall back on manual processes? And what are you telling them?
Yeah, so there are many questions that our clients have. They are, of course, concerned about whether this incident involved unauthorized access to or acquisition of protected health information because that could potentially trigger breach notification obligations under HIPAA. So, that's, of course, in a concern to all of our clients. Our clients are also wanting more information about when services will be restored and the type of assurances that they're going to receive from Change Healthcare as to confirming that there is no ongoing intrusion in their environment and that's safe to reconnect.
Clients are also looking for information about workarounds that they can do in the meantime, as well as communications that are being had with regulators and payers. Many of our clients are concerned about deadlines and also rules requiring that documentation be submitted within a certain time period. And under normal circumstances, if you don't comply with those rules, there could be some sort of penalty. And so, there's a lot of concerns about whether there is going to be exceptions made to these rules.
I know that some of my clients have spoken directly with regulators and, unfortunately, some of them have not been flexible or understanding of the situation. So, our hope is that Change, as well as the American Hospital Association and other groups representing providers as well as plans, can connect with regulators and we can find a way to move forward without these providers and plans being penalized for a situation that is out of their control. Now, Sarah, you mentioned some of the regulatory aspects of this. Does this attack also have the impact of affecting the revenue streams or bottom line of change clients that might be disrupted in terms of being able to process claims or, you know, do the other services that it needs for its customers?
Yes, so right now many healthcare providers, they cannot process claims payments to patient billing. They can't provide patient cost estimation services. And, you know, without these services and being able to generate revenue, it's really going to create a precarious financial situation for many healthcare systems and healthcare providers. So, Sarah, at this point, do you think this incident has the potential for being one of the more or most significant hacking incidents that we see this year in healthcare?
It's still early in the year, but it seems to have sort of a far range in terms of the impact. Yes, so at this time, I'm not aware of any public statement issued by Change or any Change customer notice stating that they identified or confirmed unauthorized access to or acquisition of data. But if that were to happen, and depending on the scope of how much data may have been accessed or acquired, this could have the potential to be a large notification event, just given what I said before, if they process 15 billion transactions a year that involves protected health information. So we will have to see the findings from the investigation to determine what those notification obligations look like.
So what lessons are emerging from this incident so far, especially as it relates to vendor and business associate risk management issues? This has just been tremendously challenging because even entities that don't have a direct contracting relationship with Change, they may have vendors that do, or they work with plans that have a relationship with Change. And so they are also impacted by this. And it's challenging to develop workarounds for services that are so prolific and where there's maybe one or two main providers of those services.
So I think one thing that is being flagged is about sort of the downside of consolidation of these types of vendors in healthcare. So that has been a challenge. So in terms of, you know, things that organizations can learn from this, this is pretty catastrophic. You know, other than having a complete alternative means of processing claims, which most healthcare organizations just don't have the means of setting that up, what organizations can do learning from this is talk to other crucial vendors, whether it's payroll or other vendors that provide really vital services to understand, okay, if there was some sort of outage or disruption, what's the workaround?
What's the process that we would utilize in order to move forward with the vital services that we need from a business operations perspective? So having those conversations are important. Obviously, organizations know that they should be vetting their vendors, having security questionnaires filled out, doing their due diligence, especially if they're transferring protected health information to them. But at the end of the day, unfortunately, we see incidents like this where organizations can do their best and try to mitigate risk, but this is outside of their control.
So Sarah, there was an alert the other day by the FBI and HHS about BlackCat. And in that advisory, it did not mention Change Healthcare, but it did sort of establish that social engineering and phishing is sort of a common vector for BlackCat attacks, but also, as we know from many attacks. Why does this continue to be such a problem for so many organizations, especially in healthcare, when it comes to social engineering and phishing and falling for those scams? Yeah, I think the issue is that these threat actors are becoming more and more sophisticated.
There's a few ways that they're doing that. There have been so many cyber attacks in the past few years and so much data that has been acquired from organizations that we've heard from law enforcement that they believe that some of these threat actors are combing through this data, gathering intelligence to utilize to create targeted campaigns. So very sophisticated looking phishing emails. We're seeing an increase in the number of calls to help desks asking for password resets.
And a lot of organizations have protocols in place for the type of information the caller needs to provide for the call help desk agent to verify before they do a password reset or provide any information. And unfortunately, with so much data out there, a lot of times these threat actors, they have the information that the help desk needs. So a lot of organizations are now taking extra precautions and asking for extra information when there are help desk requests for password resets or for transferring accounts to new devices. So, for example, I know organizations that are requiring that any password resets are performed either on a FaceTime or Zoom or team call where it's video so that the help desk can see the person that is asking for this information.
Because with these social engineering, we're seeing threat actors gain access to accounts by tricking the help desk. So the way to combat this, of course, is to continue to provide training to employees, whether it's phishing email training or social engineering testing, calling employees that have important roles in the organization related to payments or the disclosure of sensitive information, pretending to be someone else and making sure that you test them, that they are verifying who they're speaking to before they disclose any information or make any payments based off of information that's being provided over the phone. And, Sarah, overall, based on what we do know so far about the Change Healthcare incident, what's your top advice for entities that use the company's products or services and they've been disrupted or otherwise affected in this incident, but they don't want to have a similar fate in case another major vendor has a similar problem? What's your advice?
I think having those conversations with your vendors about what the workarounds would be if there was some sort of disruption, whether it's on the health organization side or on the vendor side. How could they work around that disruption to continue receiving With regard to BlackCat, they have sort of an interesting history in that the first week of December, the FBI announced that they had taken down BlackCat's operation, they had obtained a decryptor tool that they made available to BlackCat's victims. And then shortly thereafter, after that announcement, we started to see BlackCat again reconstituted. And so historically, they were a ransomware group where they would gain access to the environment, usually access and exfiltrate data from the environment, and then encrypt files on systems, making them inaccessible, and then reaching out to victim organizations, demanding a ransom payment in exchange for the decryptor tool and assurances that the data that was taken would not be published or further disclosed.
So here it will be interesting to see whether this was in fact a ransomware attack. And it will also be interesting to see whether there was in fact data access or exfiltration. One other important thing to note about BlackCat is they have a reputation amongst threat actors to be noisy, as we would say. So they're known to send emails to executives, employees, and others to induce ransom payment.
They may also try to regain access repeatedly to gain attention from an organization. And we've also heard of them trying to disrupt operations through denial-of-service attacks, DDoS attacks, on victims' websites. So in terms of prevention steps, patching is very important. Workforce training, making sure that people are not downloading suspicious files, they're not opening suspicious email, clicking on links in those emails, and making sure that you have endpoint monitoring running on all the workstations and servers and other systems in your environment to detect suspicious activity so it can be stopped before spreading.
Well, thank you very much, Sarah. I've been speaking to Sarah Goldstein. I'm Maria Etoukobosek-McGee of Information Security Media Group. Thanks for joining us.