What happened
Change Healthcare suffered a ransomware intrusion that encrypted claim‑processing systems and exfiltrated protected health information for roughly 190 million individuals. The Senate subsequently passed the Health Care Cybersecurity and Resiliency Act of 2026, requiring private health‑care entities to adopt baseline controls such as multifactor authentication and to extend those requirements to third‑party vendors handling PHI.
Why it matters for trust and compliance
- The breach highlights the critical control objective of third‑party oversight; a continuous‑control‑assurance program would have required documented due‑diligence, real‑time monitoring of vendor security controls, and defensible audit evidence to satisfy emerging federal mandates.
- Establish a vendor inventory and assess each provider against the new MFA and security‑baseline requirements.
- Implement continuous monitoring and retain audit‑ready evidence to demonstrate compliance with federal health‑care cybersecurity standards.
Who is affected
Health‑care providers Health‑IT vendors handling PHI Private entities that store or transmit health data
Recommended actions
- Create or update a third‑party risk register that captures security controls, MFA adoption, and breach‑notification obligations.
- Deploy continuous monitoring tools to collect real‑time evidence of vendor compliance and generate audit‑ready reports.