The Clearinghouse Became Critical Infrastructure

July 26, 2026

13 Minute read

By
Anando Chavez

Change Healthcare shows how one weak remote-access path can become a nationwide continuity failure.

Change Healthcare was not merely a vendor outage. One weak remote-access path reached a platform whose loss disrupted claims, payments, pharmacies, provider liquidity, and patient care.

  • Memo code: TV-AM-2026-07-26-02
  • Sector: Healthcare
  • Memo type: Historical case and operational pattern analysis
  • Source freeze: July 26, 2026
  • Estimated read time: 13 minutes
Holding: The Change Healthcare incident demonstrates that a concentrated healthcare clearinghouse must be governed as critical infrastructure. A remote-access service without multifactor authentication was not merely a local access weakness; it was an entry point into a platform whose failure disrupted claims, payments, pharmacy services, provider liquidity, and patient care at national scale.
  • Determination: Control failure demonstrated
  • Evidence sufficiency: Sufficient for access-control and continuity findings
  • Severity: Critical
  • Confidence: High
  • Causation status: Initial foothold through a remote-access service without MFA is supported by CEO testimony; full attack chain is not reconstructed here

The control and impact findings are supported by federal oversight, HHS, GAO, and UnitedHealth statements. This memorandum does not make a legal-compliance determination.

Executive Triage

Executive: TAKEAWAY A system that processes health claims and payments for a substantial portion of the country cannot be protected or recovered as if it were an ordinary internal application.

Who this is for

Healthcare clearinghouses, health plans, hospitals, medical groups, pharmacies, revenue-cycle teams, business associates, identity teams, incident-response leaders, and executives responsible for vendor concentration and continuity.

What to do if this sounds like your environment

Identify every remote-access path, privileged identity, service account, and external support channel connected to claims, payment, pharmacy, eligibility, and prior-authorization operations. Require MFA now and map the business processes that fail if the platform is isolated.

What to check now

  • Are all remote-access services, including legacy and acquired-company systems, protected by MFA and monitored for credential reuse?
  • Can the organization continue eligibility checks, pharmacy transactions, claims submission, remittance, and provider payments when the primary clearinghouse is unavailable?
  • Are identity and network boundaries segmented so one remote-access compromise cannot reach the entire processing platform?
  • Do customers know how to disconnect and later revalidate supplier trust paths without waiting for the supplier to recover?
  • Are contingency plans tested with real business owners, financial teams, pharmacies, and clinical operations?

What appears to have gone wrong

  • Congressional oversight records state that the attackers used a remote-access service that was not protected by MFA.
  • The platform concentration meant that defensive isolation and recovery actions disrupted claims, payments, pharmacy services, and provider cash flow across the healthcare sector.
  • HHS later recorded approximately 192.7 million individuals as impacted, while GAO cited estimated losses of $874 million and widespread effects on providers and patient care.
  • The incident exposed both an identity-control failure and a continuity architecture that lacked sufficiently independent alternatives at sector scale.

Who to involve internally

  • IAM and privileged access
  • Security operations and incident response
  • Revenue cycle and finance
  • Pharmacy and clinical operations
  • Business continuity / disaster recovery
  • Vendor management and legal/privacy
  • Executive risk and board oversight

Why continue reading

This case shows how identity risk, supplier concentration, and healthcare continuity combine. The key lesson is not only to add MFA, but to design an operating model that can survive the loss of a nationally significant trust hub.

Quick Facts and Scope

  • Incident discovered: February 21, 2024.
  • Initial access condition: A remote-access service lacked MFA, according to congressional testimony and hearing summaries.
  • Operational impact: Claims, payment, pharmacy, eligibility, and related healthcare workflows were disrupted.
  • Financial support: UnitedHealth reported advancing more than $2 billion to providers by March 18, 2024.
  • Reported population impact: HHS reported approximately 192.7 million individuals affected as of July 31, 2025.
  • GAO impact statement: GAO cited estimated losses of $874 million and widespread impact on providers and patient care.
Scope: BOUNDARY This memorandum evaluates access control, authentication, platform concentration, supplier trust, and continuity. It does not determine HIPAA liability, negligence, board liability, or the complete technical attack chain.

Cross-source commonalities

  • Federal and company sources agree that the attack produced unprecedented or widespread healthcare disruption.
  • The initial access path involved a remote service without MFA.
  • System isolation was necessary for containment but amplified the operational consequences because so many workflows depended on Change Healthcare.
  • Recovery proceeded in stages and required financial assistance, workarounds, attestations, and customer reconnection.

Material unknowns and disputes

  • The complete internal lateral-movement sequence and all affected systems are not reconstructed in the public sources used here.
  • The extent to which individual customers had tested independent fallback processing before the incident varies and is not established.
  • This memorandum does not determine whether any specific HIPAA standard was violated.
  • The final long-term cost across providers, patients, regulators, and litigation remains broader than the figures cited here.

Issue

Whether a nationally concentrated healthcare clearinghouse satisfied appropriate identity and continuity expectations when a remote-access service lacked MFA and the platform had no immediately substitutable path for critical claims, payment, and pharmacy operations.

Rules and Authorities

HIPAA Security Rule: Regulated entities must implement access control, authentication, audit controls, security-incident procedures, and contingency plans that preserve critical business processes and ePHI security during emergencies.

HHS and CISA Cybersecurity Performance Goals: High-impact practices include MFA, asset and identity inventory, incident response, tested recovery, segmentation, and governance of critical services.

TensileVue critical supplier baseline: A supplier that functions as a sector-wide trust and transaction hub requires privileged-access protection, concentration-risk treatment, staged reconnection, customer-visible evidence, and tested independent operating paths.

Analysis

1. The missing MFA control was small in footprint and enormous in consequence.

A remote-access service without MFA allowed valid credentials to function as sufficient proof of identity. In a less concentrated system, that might remain a serious but bounded intrusion. At Change Healthcare scale, the path sat upstream of claims, payments, pharmacy, and other functions used across the national health system.

The severity therefore comes from control-plane amplification: a single authentication weakness opened a route into a platform with authority over many downstream processes.

2. Acquisition and legacy technology created an unmanaged trust transition.

UnitedHealth testimony described Change Healthcare as an acquired company with older technologies still being upgraded. That context does not excuse the control gap. It identifies the governance failure mode: inherited systems can remain connected to enterprise trust before their identity controls are brought to the acquiring organization's required baseline.

Acquisition integration must inventory every remote service, privileged path, service account, and exception before the acquired platform is treated as fully trusted.

3. Containment exposed concentration risk.

Disconnecting Change Healthcare reduced further attacker access, but the same action removed services that providers depended on to verify coverage, submit claims, receive payments, and process pharmacy transactions. The security response and continuity response were inseparable.

A critical supplier must therefore have predesigned isolation modes, alternative transaction routes, manual procedures, financial liquidity plans, and a documented sequence for re-establishing trust.

4. Recovery required more than bringing systems back online.

UnitedHealth described staged restoration, third-party attestations, financial advances, and phased customer reconnection. Those steps recognize that availability is not equivalent to trust. Credentials, interfaces, data integrity, and customer dependencies must be revalidated before normal connectivity resumes.

The same principle applies to every health system relying on a clearinghouse: supplier recovery does not eliminate the customer's duty to verify its own identities, interfaces, and fallback operations.

5. Sector-scale impact changes the governance standard.

HHS and GAO describe widespread effects on patient care and providers. A platform with that level of dependency should be governed with board-visible concentration metrics, minimum identity controls, external assurance, and continuity exercises involving actual transaction partners.

The lesson is not that every healthcare vendor is critical infrastructure. It is that dependency and consequence, not corporate label, determine the required assurance level.

Conclusion

Holding: The Change Healthcare incident demonstrates that a concentrated healthcare clearinghouse must be governed as critical infrastructure. A remote-access service without multifactor authentication was not merely a local access weakness; it was an entry point into a platform whose failure disrupted claims, payments, pharmacy services, provider liquidity, and patient care at national scale.

The access-control failure is demonstrated, and the operational impact is documented at national scale. The incident should be treated as both an identity failure and a critical-supplier continuity failure. Critical severity reflects the credible consequence of losing a platform central to care and payment, not a legal conclusion about any party.

Relief Ordered

  • Immediate · IAM / security: Require MFA on every remote-access and administrative path; disable unsupported or unowned services until verified.
  • Immediate · Incident response / vendor management: Inventory supplier-linked credentials, VPNs, service accounts, APIs, certificates, support channels, and data flows; rotate or suspend as risk requires.
  • 72 hours · Revenue cycle / pharmacy / operations: Document minimum viable workflows for claims, payments, pharmacy, eligibility, and prior authorization without the primary clearinghouse.
  • 30 days · Business continuity / finance: Test provider-liquidity, manual-processing, alternate-clearinghouse, and patient-communication plans.
  • 90 days · Executive risk / procurement: Create concentration thresholds, minimum supplier controls, evidence rights, notification duties, and staged-reconnection requirements for critical healthcare vendors.

Leadership questions this should trigger

  • Which single supplier outage can stop payment, medication, eligibility, or authorization workflows?
  • Which acquired or legacy systems remain below the enterprise authentication baseline?
  • Can critical workflows continue for 72 hours, 30 days, and a full billing cycle?
  • What evidence must a supplier provide before reconnection?
  • Who can fund or prioritize emergency operations when normal payment rails fail?

Action Items / Meeting Close

  • Priority: Immediate. IAM: export every remote-access and privileged path for critical revenue-cycle systems and certify MFA coverage.
  • Priority: 72 hours. Operations: identify workflows that stop when the primary clearinghouse is unavailable and name an accountable fallback owner for each.
  • Priority: 30 days. Business Continuity: run a tabletop that includes pharmacies, claims, payments, communications, and provider cash flow.
  • Priority: 30 days. Vendor Management: amend critical-supplier requirements to include identity controls, incident notification, evidence sharing, and reconnection criteria.
  • Priority: Before next board risk review. Executive Leadership: approve a maximum concentration tolerance and a funded alternative-processing strategy.
Meeting: CLOSE Do not close the lesson with “MFA was missing.” Close it only when remote access is fully inventoried and tested, and the organization can continue critical healthcare operations when the supplier is disconnected.

Verification and Acceptance Criteria

  • Remote-access coverage · Every remote and privileged path uses approved MFA with no unmanaged legacy exception.: Path inventory, policy exports, successful and failed tests.
  • Fallback transaction test · Critical claims, payment, pharmacy, and eligibility workflows operate under the documented alternative mode.: Tabletop records, transaction samples, owner signoff.
  • Supplier trust test · Reconnection requires credential rotation, interface validation, evidence review, and approved sequence.: Reconnection checklist and approval record.
  • Concentration review · All critical dependencies have recovery targets and funded alternatives or accepted residual risk.: Dependency register and executive approval.
  • Durability review · Controls are revalidated after acquisitions, platform changes, and annually.: Audit report and remediation tracker.

Residual risk

Healthcare clearinghouses remain attractive targets and cannot be made interruption-proof. Residual risk should be reduced through strong authentication, segmented trust, independent transaction alternatives, financial contingency planning, and customer-level readiness to operate while the supplier is isolated.

Source Notes

  1. Change Healthcare Cybersecurity Incident Frequently Asked Questions — HHS Office for Civil Rights, Updated August 13, 2025. Federal breach and impact record.
  2. Healthcare Cybersecurity: HHS Continues to Have Challenges as Lead Agency — U.S. Government Accountability Office, November 13, 2024. Federal assessment of losses and sector impact.
  3. Hacking America's Health Care: Assessing the Change Healthcare Cyber Attack and What's Next — U.S. Senate Committee on Finance, May 1, 2024. Hearing record and CEO testimony.
  4. What We Learned: Change Healthcare Cyber Attack — U.S. House Committee on Energy and Commerce, May 2024. Hearing summary confirming the remote service lacked MFA.
  5. UnitedHealth Group Cyberattack Status Update — UnitedHealth Group, March 18, 2024. Affected-party restoration and financial-support update.
  6. Summary of the HIPAA Security Rule — HHS Office for Civil Rights, Current as accessed July 2026. Authoritative control expectations; no compliance conclusion is made.
  7. Cross-Sector Cybersecurity Performance Goals — CISA, Current as accessed July 2026. Voluntary high-impact cybersecurity practices.

Public-record and confidence note

The public record strongly supports the missing-MFA control failure, nationwide operational disruption, and large-scale data impact. The memorandum does not determine legal liability or reconstruct every stage of the intrusion.