LIVE NEWS
  • Continuous Observability as the Decision Engine
  • How to Prevent Colon Cancer and Tell If Your Poop Is Normal: Doctor
  • Iran War Live Updates: U.S. Defense Officials Speak About War Effort
  • NZD/USD edges higher as softer US Dollar, firm RBNZ outlook lift pair
  • Holding out: Japan rearms impressively, but Taiwan can’t count on it
  • Week in wildlife: a tiny harvest mouse, bagel cats and a rhino out for a stroll
  • In Baltic skies, NATO and Russian pilots size each other up warily but without a tilt into war
  • Metaplanet raises $50M in zero-interest bonds to buy more Bitcoin
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»HHS burrows into identifying risks to health sector from third-party vendors
Cybersecurity

HHS burrows into identifying risks to health sector from third-party vendors

primereportsBy primereportsFebruary 22, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
HHS burrows into identifying risks to health sector from third-party vendors
Share
Facebook Twitter LinkedIn Pinterest Email


A Department of Health and Human Services official said Thursday that HHS is devoting a lot of attention to the security of third-party service providers after the 2024 Change Healthcare cyberattack.

That attack, which is widely regarded as the biggest ever in the sector — including by HHS’s Charlee Hess, who spoke Thursday at CyberTalks presented by CyberScoop — began with hackers exploiting the lack of multifactor authentication set up on a remote access portal at Change Healthcare.

“It wasn’t a hospital, it was a company most people have never heard of and had major impacts on our sector and threatened the liquidity of our entire health care system,” said Hess, director of the healthcare and public health sector cybersecurity at the Administration for Strategy Preparedness and Response division. “We recovered from that, but we realized there are third-party risks lurking in our health care system, and we don’t even know they’re there. Where are those entities or systems that will have an outsized impact on our sector?”

That realization arose from meetings between HHS and industry, she said. The focus on third-party service provider risk came next.

“We are going through and working through a methodology to identify that, and we’ve been working with industry on doing that, really finding where those places are,” Hess said.

The Change Healthcare breach, which exposed the data of 190 million people, has triggered other government responses, too, including on Capitol Hill.

It also prompted UnitedHealth Group, the parent company of Change Healthcare to “start over” on its use of computer systems. But industry has also bristled at the notion of mandatory cybersecurity requirements on hospitals — in part because, they note, the Change Healthcare attack wasn’t their fault.

HHS burrows into identifying risks to health sector from third-party vendors

Written by Tim Starks

Tim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he’s covered cybersecurity since 2003. Email Tim here: tim.starks@cyberscoop.com.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSam Altman: AI Will Be “quite Bad” For Some Software Companies
Next Article Who Is Not Funding This Antarctic Expedition?
primereports
  • Website

Related Posts

Cybersecurity

Continuous Observability as the Decision Engine

April 24, 2026
Cybersecurity

‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty – Krebs on Security

April 23, 2026
Cybersecurity

Cloudsmith Raises $72 Million in Series C Funding

April 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20258 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20265 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Continuous Observability as the Decision Engine
  • How to Prevent Colon Cancer and Tell If Your Poop Is Normal: Doctor
  • Iran War Live Updates: U.S. Defense Officials Speak About War Effort
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.