Cybersecurity Disruption at Change Healthcare

Change Healthcare faced a significant cybersecurity disruption, which commenced on Wednesday, February 21. The company took swift action by isolating its systems to mitigate any further impact.

Notably, this incident did not affect Optum, UnitedHealthcare, and UnitedHealth Group (UHG) systems, as confirmed by UHG. They have assured that necessary measures have been implemented to contain the situation, ensuring minimal disruption to customers and partners.

However, cybersecurity experts alongside the HHS Administration for Strategic Preparedness and Response (ASPR) advise organizations to carefully evaluate the risks associated with utilizing Optum, UnitedHealthcare, and UHG systems amidst this cyber incident.

In light of this situation, healthcare organizations have been urged to take proactive steps to safeguard their networks. Evaluating the risk of utilizing systems associated with the incident and ensuring adequate measures are in place to protect sensitive information is paramount. Despite assurances from UHG regarding system safety, it’s imperative for organizations to conduct thorough risk assessments to make informed decisions regarding network connectivity.

Additionally, Representatives Mariannette Miller-Meeks and Robin Kelly, along with 94 bipartisan members of the House of Representatives, have raised concerns to HHS Secretary Xavier Becerra regarding ongoing challenges faced by physicians and patients due to the cyberattack. They’ve emphasized the impact on physician practices, including the inability to file claims and receive payments, urging CMS to provide clarity on repayment terms and address the financial burden on patients.

Furthermore, CMS has introduced various initiatives to aid affected physicians, including the reopening of the MIPS Extreme and Uncontrollable Circumstances (EUC) hardship application. This extension allows physicians impacted by the cyberattack to apply for exemptions until April 15, 2024.

In response to the disruption, CMS has announced opportunities for physicians to request advance Medicare payments to alleviate cash flow disruptions. Additionally, the AMA has urged CMS to provide financial relief from MIPS penalties for affected physicians and encouraged the National Association of Insurance Commissioners to take action to protect physician practices from the breach’s widespread impact.

As organizations navigate the aftermath of the cyber incident, it’s crucial to stay vigilant against potential threats. The joint announcement by the FBI, CISA, and HHS provides valuable insights and guidance to enhance cybersecurity measures and strengthen organizational defenses against cyber threats.

The AMA acknowledges the efforts of federal agencies and urges continued support for physicians facing financial struggles as a result of the disruption. While initial measures have been implemented, further assistance, such as advance payments, is deemed essential to ensure the viability of medical practices, particularly smaller ones serving vulnerable populations.

As the situation unfolds, organizations are advised to stay informed through credible sources and remain proactive in addressing cybersecurity concerns. Collaboration between stakeholders and adherence to recommended protocols will be instrumental in mitigating the impact of cyber incidents on healthcare operations and patient care.