The News: In early 2024, the “BlackCat” ransomware group executed the largest healthcare payment disruption in U.S. history by attacking Change Healthcare. The impact was so severe that UnitedHealth Group CEO Andrew Witty eventually authorized a $22 million ransom payment in Bitcoin to the hackers in a desperate attempt to protect patient data and restore services. Despite this massive payment, the recovery took months, and the total cost to the company eventually exceeded $2 billion in lost revenue and restoration costs.
The Expert Take: The most frustrating part of this $22 million disaster? It was entirely preventable. The CEO confirmed in Congressional testimony that the hackers didn’t use a high-tech “cyber weapon”—they simply used a stolen username and password to log into a remote-access server that did not have Multi-Factor Authentication (MFA) enabled.
From a NIST CSF 2.0 “Protect” (PR.AC) perspective, this is a warning about the “Identity Perimeter.” If you have a remote-access tool (like a VPN or Citrix) that only requires a password, you don’t have a security system—you have a suggestion. For an SMB, the lesson is clear: A hacker doesn’t need to be a genius to ruin your business; they just need to find the one door you forgot to double-lock with MFA.
3 Survival Lessons for Small Businesses:
- The Ransom is Just the Tip of the Iceberg: UnitedHealth paid $22 million, but they lost $2 billion. For a small business, the “downtime” and “reputation damage” are usually 10x more expensive than any ransom demand.
- Paying Doesn’t Guarantee Safety: Even after paying the $22 million, the hackers “double-crossed” each other, and a second group tried to extort the company again using the same stolen data. You cannot buy your way out of a breach.
- Audit Your “Legacy” Systems: The server that caused this was an older portal that had been “missed” during security updates. Do you have an old laptop or a “temporary” remote login that was never properly secured?
How to Secure Your Business Today:
- Enforce MFA Everywhere: If a service touches your bank account, your email, or your customer data, it must have MFA. If the software doesn’t support it, replace the software.
- Test Your “Manual” Plan B: If your primary payment processor or software provider went dark for 14 days, could you still invoice your clients? Could you still pay your staff?
- Assume the Breach: Shift your mindset. Instead of asking “Will I be hacked?”, ask “What happens when my vendor is hacked?” This shift in strategy is what separates a resilient business from one that closes its doors.
Original reporting via: The HIPAA Journal and US Senate Finance Committee Testimony.
