Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • HHS burrows into identifying risks to health sector from third-party vendors  – CyberScoop
AttackFeed by Joe Wagner | HHS burrows into identifying risks to health sector from third-party vendors  - CyberScoop

HHS burrows into identifying risks to health sector from third-party vendors  – CyberScoop

Posted on February 19, 2026 By Tim Starks
Attack Feeds

A Department of Health and Human Services official said Thursday that HHS is devoting a lot of attention to the security of third-party service providers after the 2024 Change Healthcare cyberattack.

That attack, which is widely regarded as the biggest ever in the sector — including by HHS’s Charlee Hess, who spoke Thursday at CyberTalks presented by CyberScoop — began with hackers exploiting the lack of multifactor authentication set up on a remote access portal at Change Healthcare.

“It wasn’t a hospital, it was a company most people have never heard of and had major impacts on our sector and threatened the liquidity of our entire health care system,” said Hess, director of the healthcare and public health sector cybersecurity at the Administration for Strategy Preparedness and Response division. “We recovered from that, but we realized there are third-party risks lurking in our health care system, and we don’t even know they’re there. Where are those entities or systems that will have an outsized impact on our sector?”

That realization arose from meetings between HHS and industry, she said. The focus on third-party service provider risk came next.

“We are going through and working through a methodology to identify that, and we’ve been working with industry on doing that, really finding where those places are,” Hess said.

The Change Healthcare breach, which exposed the data of 190 million people, has triggered other government responses, too, including on Capitol Hill.

It also prompted UnitedHealth Group, the parent company of Change Healthcare to “start over” on its use of computer systems. But industry has also bristled at the notion of mandatory cybersecurity requirements on hospitals — in part because, they note, the Change Healthcare attack wasn’t their fault.

The post HHS burrows into identifying risks to health sector from third-party vendors appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post:  FBI: Threats from Salt Typhoon are ‘still very much ongoing’  – CyberScoop
Next Post: ONCD official says Trump administration aims to bolster AI use for defense without increasing risk  – CyberScoop ❯

You may also like

AttackFeed by Joe Wagner | Wave Browser Brings Gaming Tools and Ocean Cleanup into the Same Tab   - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Wave Browser Brings Gaming Tools and Ocean Cleanup into the Same Tab   – Hackread – Cybersecurity News, Data Breaches, AI and More
March 30, 2026
Attack Feeds
Defenders fall behind, as AI rewrites the rules of a data breach  – GRAHAM CLULEY
May 21, 2026
AttackFeed by Joe Wagner | Agent AI is Coming. Are You Ready?  - The Hacker News
Attack Feeds
Agent AI is Coming. Are You Ready?  – The Hacker News
May 20, 2026
AttackFeed by Joe Wagner | SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files  - The Hacker News
Attack Feeds
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files  – The Hacker News
April 20, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.