A single compromised login at one claims-processing subsidiary froze payment flows across a large share of the United States healthcare system. The interesting failure was not the ransomware. It was the concentration nobody had priced.
What became visible
In February 2024, a ransomware attack on Change Healthcare, a claims clearinghouse subsidiary of UnitedHealth Group, disrupted prescription and medical claims processing for a large share of pharmacies, hospitals, and providers across the United States for weeks. UnitedHealth Group has disclosed direct response and remediation costs in the billions of dollars in its own financial reporting since the incident, a figure that continues to be revised as recovery costs accumulate.
The technical entry point was unremarkable: compromised credentials on a system that lacked multi factor authentication. What made the incident systemic was not the entry point. It was how much of the industry routed claims through one processor.
Why the exposure existed
Concentration risk of this kind rarely shows up in a single organization risk register, because no single provider or pharmacy owned the concentration. Each of them saw a vendor relationship with one clearinghouse. None of them saw that the clearinghouse sat in the payment path for a large fraction of the entire sector at once. The exposure was aggregate and systemic, not something visible from inside any one counterparty relationship.
What assumptions failed
The working assumption in most vendor risk programs is that a critical vendor failure is a contained, single-relationship event: this vendor goes down, this customer is affected. Change Healthcare showed that when a vendor sits at a genuine chokepoint, a single compromise becomes correlated failure across every customer at once, which is a different loss shape than the one most third party risk scoring is built to catch.
What another organization should learn
The question worth asking is not whether this specific vendor is well controlled. It is whether any single vendor relationship in the organization dependency chain sits at a chokepoint shared with a large number of unrelated peers, and whether that concentration is visible anywhere in the organization own risk register, or only visible in hindsight, once the vendor fails for everyone at once.
The broader point
This is not really an article about one claims processor. It is about a category of exposure, vendor concentration at an industry chokepoint, that a standard vendor scorecard rarely surfaces, because the scorecard is built one relationship at a time and the risk only exists in aggregate.
