BREACH WATCH BRIEF High 🏥 Breach

Senate Passes Health Care Cybersecurity & Resiliency Act After Change Healthcare Ransomware Breach Exposes 190 Million Records

A ransomware attack on Change Healthcare compromised the health data of 190 million people. In response, the Senate enacted a new cybersecurity law that mandates minimum security standards and vendor oversight for all private health‑care entities. This underscores the need for continuous vendor risk monitoring and audit‑ready evidence.

SeverityHigh
Type🏥 Breach
ConfidenceHigh
ReportedOct 7, 2026
Healthcare & Life Sciences Health‑care providers Health‑IT vendors handling PHI Private entities that store or transmit health data Malware

What happened

Change Healthcare suffered a ransomware intrusion that encrypted claim‑processing systems and exfiltrated protected health information for roughly 190 million individuals. The Senate subsequently passed the Health Care Cybersecurity and Resiliency Act of 2026, requiring private health‑care entities to adopt baseline controls such as multifactor authentication and to extend those requirements to third‑party vendors handling PHI.

Why it matters for trust and compliance

  • The breach highlights the critical control objective of third‑party oversight; a continuous‑control‑assurance program would have required documented due‑diligence, real‑time monitoring of vendor security controls, and defensible audit evidence to satisfy emerging federal mandates.
  • Establish a vendor inventory and assess each provider against the new MFA and security‑baseline requirements.
  • Implement continuous monitoring and retain audit‑ready evidence to demonstrate compliance with federal health‑care cybersecurity standards.

Who is affected

Health‑care providers Health‑IT vendors handling PHI Private entities that store or transmit health data

Recommended actions

  1. Create or update a third‑party risk register that captures security controls, MFA adoption, and breach‑notification obligations.
  2. Deploy continuous monitoring tools to collect real‑time evidence of vendor compliance and generate audit‑ready reports.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.