Axis Insurance Services Blog

Healthcare provider dealing with massive cyberbreach fallout

Written by Drew Smith | Apr 4, 2024 2:48:28 PM

The Healthcare industry was rocked by a massive cyber breach in late February and the fallout continues to be felt a month later. UnitedHealthcare, one of the largest healthcare insurance providers was breached and it has taken several weeks to even get their services online, throwing the industry into chaos.

The problems began in February when one of their subsidiaries, Change Healthcare, was breached. This breach while affecting one company, had in fact started a chain reaction that disrupted many pharmacies throughout the nation. The breach itself targeted the distribution center for pharmacies in which they could get prescription strength drugs. While seemingly innocuous, the mere fact that pharmacies could not only access their network to distribute their products but also the inability to process payments. In the days post breach, they could not fill orders for various prescriptions and were delayed in getting cash to their stores, resulting in a cash crunch and temporary closures of affected pharmacies.

Only in the last two weeks, after the Department of Health and Human Services got involved, have they even come close to a fix. But the damage is immense. Over half of US pharmacies use this system to process payments. Change Healthcare processes about 50% of medical claims in the U.S. for around 900,000 physicians, 33,000 pharmacies, 5,500 hospitals and 600 laboratories.(1)

Just recently they announced that the backlog over $14 Billion in claims and other orders would start filing through as of March 22nd. Before then, they could only process the claims made before February 21st. UnitedHealth said it has made payments of upwards of $2.5 billion so far to offer assistance to healthcare providers impacted by the disruption. “We recognize the event has caused different levels of impact among providers; therefore, we continue to offer temporary funding assistance at no cost,” the company said. “We know many providers, especially smaller practices, are struggling, and we encourage those who need further assistance to access these resources.”(2) The sheer size meant they could not inform everyone within the regulated amount of time and thus will probably face more fines on top of the projected costs

All of this raises a big question, what would happen in the future? Healthcare is one of the biggest targets for hackers. The reason is simple, the healthcare industry handles a lot of personal information, and many servers are not secured enough to contain this type of breach. In a statistics compilation done by tech target.com:

  1. The volume of reported vulnerabilities continues to rise. The "Vulnerability and Threat Trends Report 2023" from Skybox Security reported a 25% year-over-year increase in the number of new vulnerabilities in the U.S. government's National Vulnerability Database from 2021 to 2022.
  2. It takes an average of 277 days for security teams to identify and contain a data breach, according to "Cost of a Data Breach Report 2023," released by IBM and Ponemon Institute.
  3. Ransomware attacks are a constant threat affecting all sectors, and it's only getting worse. Ransomware affected 66% of respondents' organizations, according to Sophos' "The State of Ransomware 2023" report.
  4. The average total cost of data breaches in 2023 was $4.45 million, according to the IBM/Ponemon Institute report mentioned above. Breaches in the healthcare industry were the costliest at $10.93 million on average versus $5.90 million for financial services. To this last point, the United Healthcare breach will exceed both of these numbers.(3)

 

This breach should serve as a wake up call for to anyone who does not take cyber security seriously, they are much easier targets than something like UnitedHealthcare. Brush up on your cybersecurity measures and prevention, including vigilance, multifactor authentication, and regular training.

 

About Axis

Celebrating its 25th year anniversary in 2024, Axis Insurance Services, LLC, is proud of our reputation in building highly customized insurance solutions for all types of professional service companies and their employees. We believe our diverse product options and outstanding customer service help us earn our clients’ trust and loyalty.

Formed in 1999, Axis Insurance Services, LLC is a nationwide leader in the professional and management liability insurance industry, developing innovative risk management solutions for today’s evolving businesses. We offer insurance programs to a broad array of professionals and industries, including insurance agents/brokers, attorneys, commercial real estate firms, technology, healthcare/medical, financial institutions, architects/engineers, consulting firms, media, and many others.

In 2014, we launched PLRisk in 2014 and today the two firms provide retail and wholesale coverage solutions for Cyber Liability & Privacy/Network Security, Errors and Omissions, Directors and Officers, Employment Practices Liability, Commercial Crime and Fiduciary coverage.

For more information about our company, please click here.