When the clearinghouse went dark

The Change Healthcare cyberattack showed how one vendor outage can stop a practice's cash flow. This is the one-page contingency plan we think every practice should have.

Published
Reading time
2 minutes
Written by
FizzTech billing team
Sources
4 cited

The short version

  • 80% of practices in an AMA survey lost revenue from unpaid claims after the attack.
  • Claims, eligibility checks and remittances usually all run through one clearinghouse.
  • Payer portal and backup clearinghouse enrollments take time you will not have in an outage.
  • The plan belongs with whoever runs billing, not only with IT.

In February 2024, Change Healthcare, one of the largest claims clearinghouses in the United States, was hit by a ransomware attack and took its systems offline. For practices that sent their claims through it, the effect was simple: claims stopped going out, remittances stopped coming in and cash stopped arriving.

The American Medical Association surveyed physicians in the weeks that followed. Eighty percent of practices said they had lost revenue from unpaid claims, 85% had put extra staff time into revenue cycle work, and more than half had used personal funds to cover practice expenses. Most respondents were in practices of ten physicians or fewer.

80%
Practices in an AMA survey that lost revenue from unpaid claims after the Change Healthcare attack.Source: AMA

The single point of failure

Most practices connect to payers through one clearinghouse and rarely think about it. It sits between the practice management system and hundreds of payers, sending claims out and bringing remittances back. When it stops, eligibility checks, claim submission and electronic remittance advice stop with it. In the AMA's follow-up survey in late April 2024, 79% of practices still could not receive electronic remittance advice.

A contingency plan on one page

  1. Know how to switch. Find out now what it takes to connect a second clearinghouse, how long enrollment takes and whether your practice management system supports it.
  2. Enroll in your largest payers' portals. Most accept direct claim entry and show claim status, and enrollment takes days you will not have during an outage.
  3. Keep ERA and EFT records by payer, so you know who sends your remittances and how to redirect them.
  4. Know how many weeks of expenses you could cover if payments stopped, and decide in advance how you would bridge the gap.
  5. Read your vendor agreements. They should say how you will be told about an incident and what happens to your data.

Why this is a billing question

Cybersecurity usually lands with IT, but the consequences land with billing. Whoever runs your revenue cycle should know, before anything happens, which claims can go out another way and in what order.

Keep on file

  • Backup clearinghouse contact and enrollment steps
  • Portal logins for your top ten payers, held by more than one person
  • ERA and EFT enrollment details by payer
  • A ranked list of which claims to send first if you have to go manual

Sources

  1. American Medical AssociationChange Healthcare cyberattack
  2. American Medical AssociationChange Healthcare cyberattack impact: survey results
  3. American Medical AssociationChange Healthcare cyberattack impact: follow-up survey
  4. HFMACyberattack on Change Healthcare brings turmoil to healthcare operations nationwide

These articles are general information for practice owners and managers. They are not legal, coding or compliance advice. Payer rules change and vary by plan and state, so check the current source before you act on anything here.

Have a question these did not answer?

Tell us what is going wrong with your claims. A short call is usually enough to see where the problem starts.