My main takeaway: test your backup routes before a vendor outage stops claims, prescriptions, or payments. Before the February 21, 2024, attack, Change Healthcare processed about 20%–25% of pharmacy claims - showing how much can depend on one supplier.

I’d focus on four steps:

  • Rank vendor dependencies: Identify which services affect patient care and cash flow, and how long switching would take.
  • Map hidden links: Check subcontractors, access controls, and recovery-test results - not just vendor questionnaires.
  • Test downtime plans: Run backup routes and manual workflows, with staffing and cash plans for a weeks-long outage.
  • Finish recovery: Reconnect safely, match claims to payments, and resolve patient-access problems.

<u>Restoring a connection is not the same as finishing recovery.</u> I’d turn these steps into a 30/60/90/120-day plan, with one owner, deadline, and pass-or-fail test for each task.

Healthcare Supply Chain Resilience: 120-Day Plan

Healthcare Supply Chain Resilience: 120-Day Plan

Reflecting on the Change Healthcare cyberattack, one year later

Reduce Dependence on Critical Healthcare Vendors

The Change Healthcare attack showed that security threats in healthcare’s third-party vendor relationships do not guarantee service continuity. One failed intermediary stalled claims, pharmacy, and payment flows. Assign clinical, IT, and revenue-cycle owners to a single service-impact register. Use it to decide which vendors need backups, manual workarounds, and executive sign-off.

Rank Vendors by Service Impact and Switching Time

Map services across hospitals, clinics, pharmacies, applications, and business units. For each service, record its owner, maximum tolerable outage, and barriers to switching: contracting, payer enrollment, configuration, testing, and staffing.

Classify switching time as immediate, less than 30 days, 31–90 days, or more than 90 days. Support each estimate with documented onboarding steps. Escalate any dependency that takes longer to replace than the organization can safely tolerate an outage.

Use these indicators to distinguish critical vendors from vendors that are simply expensive.

Indicator What to record What it reveals
Patient and financial impact Affected services, daily transactions, and payment value Consequences for care and reimbursement
Shared dependencies Fourth parties, payer gateways, hosting, networks, and processors Whether multiple vendors could fail together
Geographic concentration Facilities, regions, hosting locations, and recovery sites How broadly one failure could affect operations
Time to switch Contracting, enrollment, configuration, testing, and staffing time Whether a replacement can be used within the tolerable outage

Test Backup Routes and Manual Workflows

Check payer connectivity, onboarding time, tested transaction capacity, and shared underlying dependencies. Contracts should require outage notification, data export, transition assistance, and tested continuity arrangements. After Change Healthcare, rerouting required payer and contract coordination - not just technical changes.[1] A backup is ready only after it passes live transaction testing.

Test manual procedures with the staff who will use them. For eligibility checks, prior authorizations, claim capture, and payment posting, define approved tools, minimum data fields, secure storage, escalation contacts, and duplicate-submission controls.

Measure staff capacity instead of assuming manual work can handle normal demand. The American Medical Association reported that 85% of physician practices committed additional staff time and resources to revenue-cycle workarounds.[4]

Where diversification is not practical, create a formal risk record. Include a business owner, technical owner, estimated switching time, tested fallback, mitigation deadline, and remaining patient and financial impact. Document whether an outage would stop billing, dispensing, or cash flow. Require executive approval with a review date and conditions that trigger another review.

Treat “no replacement available” as a documented risk decision, not an assumption.

Map Vendor and Fourth-Party Dependencies

The Change Healthcare attack showed how hidden dependencies can delay containment and recovery. When teams lack visibility into subcontractors, they can’t reroute services quickly.

Build one record per critical service, not just per vendor. Connect each service to its applications, interfaces, data flows, departments, PHI exposure, hosting location, access paths, and recovery dependencies. Require vendors to name subcontractors that process, host, authenticate, support, or restore the service. Identify which ones can affect containment, restoration, or identity control. Procurement records alone won’t show these connections.

Once the service map is complete, check which controls protect the live connection.

Check Access Controls and Recovery Plans

Document remote-access methods, privileged and service accounts, API keys, certificates, file transfers, and credential owners. Ask for evidence that MFA covers administrative and remote access. For system-to-system connections, check authentication, key rotation, and logging. Confirm who can revoke access and whether vendor connections are segmented from clinical systems. A questionnaire answer is not proof of production control.

Request service-specific network diagrams, vulnerability reports, and restoration-test results. Compare tested recovery-time and recovery-point performance against contractual commitments. For clinical applications, check interface recovery order and safeguards for validating data.

Require clear incident-notification deadlines and notice of material fourth-party changes. Reassess after acquisitions, architecture migrations, new integrations, incidents, or failed recovery tests.

Keep Vendor Evidence and Remediation in One Place

After mapping services and checking controls, bring the evidence needed to close gaps into one place. Use a shared assessment record, such as Censinet RiskOps™, to connect integration details, fourth-party exposure, evidence, gaps, owners, and deadlines.

Security, clinical, procurement, and finance teams should work from one current record, with one owner list, remediation path, and proof trail.

Tie each finding to the affected service, evidence date, reviewer, and verification requirement. Mark missing subcontractor information as unknown, not low risk. Human review is still needed: automation cannot verify MFA, segmentation, backup performance, or recovery results.

Plan for Long Outages and Recovery Backlogs

When vendor links fail, recovery means more than restoring connections. Teams also need to manage the backlog.

Restored systems do not mean recovered operations. A single vendor outage can leave downstream claims rejected, duplicated, or awaiting payment. In a March 2024 American Hospital Association survey of nearly 1,000 hospitals, 60% reported needing two weeks to three months to resume normal operations after Change Healthcare’s full functionality was restored.[2][3]

Define who can disconnect, restart, and reconcile those services safely.

Define Disconnection, Reconnection, and Notification Rules

Use the dependency map to assign authority. Cybersecurity isolates integrations, while business owners run downtime workflows. Both teams approve phased reconnection using tested transactions and rollback steps. Include 24/7 escalation contacts and notification deadlines in the incident plan.

Preserve authentication logs, interface queues, transaction records, and vendor communications. Assign an evidence custodian to record timestamps, restrict access, and document transfers so the chain of custody remains intact. Privacy and legal teams should coordinate forensic review and notification decisions. An outage alone does not prove downstream compromise.

Test Downtime Workflows and Emergency Cash Flow

Test for a supply-chain outage that lasts weeks - not a brief system interruption. Run workflows at multiweek transaction volumes within staffing and cash limits. Tie recovery objectives to patient-safety urgency and acceptable data loss, and retain manual entries for reconciliation.

Finance should track cash daily and set escalation thresholds, such as 30, 14, and 7 days of projected liquidity, for contacting payers, lenders, suppliers, and relevant government programs. Smaller practices need to escalate earlier because their reserves run out faster.

Check Restored Services and Reconcile Transactions

As services resume in stages, use a transaction-control register to match services delivered against claims, payer acknowledgments, remittances, deposits, and patient accounts. Flag duplicates, denials, payment mismatches, and manual-entry errors. Pause automatic resubmission when a transaction’s status is unknown.

Keep separate queues for unresolved medication access, authorizations, and incorrect bills. Assign owners and deadlines to each case.

Measure decision time, fallback capacity, recovery duration, backlog size and age, and time to resolve patient-access cases - not just uptime. Track recovery through containment → continuity → restoration → reconciliation.

Stage Owners Trigger Proof
Containment Cybersecurity, privacy, legal Evidence of compromise or unsafe connectivity Approved isolation record; preserved evidence; documented notification decisions
Continuity Clinical operations, pharmacy, revenue cycle, finance Failed care transactions or liquidity threshold reached Downtime logs; measured fallback capacity; cash-flow actions
Restoration Cybersecurity and business owners Vendor readiness and local acceptance criteria met Tested transactions; phased reconnection approval
Reconciliation Revenue cycle, finance, clinical operations, pharmacy Normal routing resumes but exceptions remain Matched claim and payment totals; resolved patient cases; remaining exceptions assigned owners and deadlines

Use this structure to give each recovery task a clear owner rather than leaving teams to scramble.

Conclusion: Assign Owners and Deadlines for Supply Chain Resilience

After containment, continuity, restoration, and reconciliation, leadership must set firm deadlines. Turn the lessons learned into assigned actions for healthcare supply chain security challenges and resilience.

Build a 30/60/90/120-day action plan:

  • By day 30: Inventory critical services and rank them by patient impact, revenue exposure, and switching time.
  • By day 60: Map fourth parties and review service-specific security and recovery evidence.
  • By day 90: Test fallback routes for shared dependencies in claims, pharmacy, and payment flows.
  • By day 120: Run a prolonged-outage exercise for those flows and close remediation items.

Give each gap one owner, one due date, one acceptance criterion, and one escalation path. The CIO owns dependency mapping; the CISO owns security-control gaps; the CFO owns liquidity planning; and the COO owns continuity testing. Require executive approval for overdue high-risk items or accepted residual risk.

Report readiness to leadership through four metrics: tested fallbacks, incomplete fourth-party maps, switching time, and overdue remediation. Censinet RiskOps™ can centralize assessments, evidence, and remediation workflows.

Leadership remains accountable for governance, continuity testing, risk acceptance, and incident decisions.

FAQs

How can we spot concentration risk across different vendors?

Keep a dependency inventory up to date and map it to clinical and business workflows. Start with services whose loss would stop care or revenue within 72 hours. Then trace each service’s vendors, subcontractors, cloud hosts, and data centers.

Review API logs, outbound traffic, and authentication activity to find hidden fourth-party links and shared infrastructure. Look for common cloud regions or identity providers: a failure in either could take down multiple vendors at once.

How can small practices afford prolonged-outage preparedness?

Build resilience with low-cost steps, not expensive system overhauls. Map the services you rely on, including clearinghouses and EHR connections, to spot single points of failure.

Set up manual backup procedures for claims, prescriptions, and documentation - and practice them regularly. Use more than one provider for key clearinghouse and banking needs so a vendor failure doesn’t bring everything to a halt.

Censinet RiskOps™ can simplify risk assessments and vendor oversight, helping small teams decide where to focus limited time and budgets.

How do we verify vendor recovery claims?

Require dated, end-to-end test results for critical workflows, including claims submission, reversals, and reconciliation. Test backup vendors, too. Naming them in a contract isn’t enough.

Contracts should require documented recovery time objectives (RTO) and recovery point objectives (RPO), verified through routine disaster recovery tests or live drills. Track missed recovery commitments and keep remediation records in one place so recovery procedures stay aligned with current dependencies.

Related Blog Posts