Join our Newsletter — 33% off our NHI Course

Change Healthcare breach: what it means for IAM and NHI governance

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Change Healthcare was breached through compromised credentials to a Citrix remote access portal without MFA, followed by lateral movement, data exfiltration, and a $22 million ransom payment, according to Oasis Security and UnitedHealth Group. The incident shows why MFA is necessary for human access but insufficient when identity governance does not extend to non-human identities and remote access pathways.

Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “The Future of Identity Security: Lessons from the Change Health Breach”.

By the numbers:

  • Non-human identities can outnumber human identities by 10x-50x in modern environments, according to Oasis Security.

Key questions

Q: What breaks when a remote access portal does not require MFA?

A: Password-only remote access turns stolen credentials into immediate session access, which means the attacker can enter through a normal user path and blend into routine activity.

Q: Why do compromised credentials often bypass MFA controls?

A: Because many attacks steal the artifact issued after MFA, not the password itself.

Q: How do security teams know whether remote admin access is too broad?

A: Look for accounts that can reach servers, stop services, or manage recovery tooling without task-specific approval or expiry.

Practitioner guidance

  • Harden remote access pathways Review every portal that allows remote entry into internal systems and require step-up controls where privileged or sensitive access is reachable after authentication.
  • Inventory non-human identities by reach Map service accounts, API keys, tokens and certificates that can reach the same systems as user logins, then separate them by ownership and business purpose.
  • Reduce lateral movement paths Limit what a successfully authenticated remote session can reach by tightening segmentation, privilege scope and session-based access boundaries.

Bottom line: The breach shows how MFA can fail to contain risk when compromised credentials can still reach a remote access portal and pivot inward.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

MFA-only thinking breaks at the boundary between authentication and governance: This breach worked because the security programme treated MFA as a sufficient endpoint rather than one layer in a larger identity model. Compromised credentials still opened a path into a remote access portal, and the surrounding access fabric allowed the attacker to keep going. The implication is that authentication strength and identity governance must be evaluated separately, not collapsed into one control story.

A few things that frame the scale:

  • Stolen credentials were involved in 22% of breaches overall and in 88% of basic web application attacks, according to Verizon's 2025 Data Breach Investigations Report.

A question worth separating out:

Q: How should teams govern non-human identities that support remote access and back-end workflows?

A: They should govern them as distinct identities with explicit ownership, scoped permissions, rotation, revocation and offboarding. Service accounts, tokens and API keys cannot rely on human MFA, so their lifecycle controls must be designed around reach and persistence. The goal is to prevent machine access from becoming the hidden path through the environment.

👉 Read our full editorial: Change Healthcare breach exposes the limits of MFA-only identity security


This post was modified 5 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.