Healthcare organizations everywhere were put on high alert when Change Healthcare disclosed a massive data breach in late February 2024 impacting over 7 million patients and plan members. This incident once again emphasized how threat actors continue heavily targeting the healthcare industry and its treasure trove of lucrative personal data.
What Happened in the Latest Change Healthcare Attack? In late February 2024, Change Healthcare detected and revealed that an unauthorized party had gained access to certain systems within their IT environment over a multi-week period. The cybercriminals deployed malware and conducted reconnaissance activities to harvest user credentials, ultimately breaching databases storing sensitive patient information.
The compromised data spanned across tens of Change Healthcare’s healthcare provider customers and included names, dates of birth, Social Security numbers, medical diagnoses, treatment details and health insurance information for approximately 7.2 million individuals.
While the investigation into the full scope and attack methods is still ongoing, Change Healthcare indicated the threat actors leveraged tactics like phishing, credential abuse, lateral movement, and data exfiltration to carry out this large-scale breach.
How Edge Technology Group’s Security Services Could Have Prevented It As a leading provider of cybersecurity and IT services for healthcare organizations, Edge Technology Group employs a powerful array of preventative controls that could have detected and stopped the Change Healthcare attack at multiple points:
AI-Based Email Threat Protection Our partnership with Ironscales equips us with advanced AI/machine learning models to analyze all incoming emails in real-time. This blocks even the most sophisticated phishing attempts, malware delivery, and credential harvesting campaigns which were likely initial attack vectors.
Comprehensive Endpoint Security Edge Technology Group implements industry-leading endpoint detection and response (EDR) solutions to stop malware execution, unauthorized processes/scripts, and behavioral indicators of attacks across all user devices and servers.
Rigorous Identity Management We deploy robust identity and access management controls including privileged access monitoring, multi-factor authentication enforcement, and continuous credential risk analytics to prevent tactics like account/password compromises utilized in this breach.
24/7 Managed Detection & Response
Through our Cynet partnership, we provide round-the-clock managed security services with centralized monitoring, analytics, and automated response capabilities. This vigilance enables our team to rapidly detect and contain threats before widespread lateral movement and data theft occurs.
Regulatory-Focused Policies & Training In addition to technical safeguards, our services emphasize robust risk assessments, security awareness programs, HIPAA/HITECH compliance validation, and cultivating an organization-wide culture focused on protection of patient data.
The February 2024 Change Healthcare breach is yet another wake-up call that healthcare companies must implement a comprehensive, defense-in-depth cybersecurity strategy. Edge Technology Group has the expertise and services portfolio to reinforce your critical data against even the most sophisticated threat actors.
Contact us today to discuss how our team can enhance your healthcare organization’s overall security posture.