After the CommonSpirit ransomware attack: Why healthcare M&A has become a 'huge' cybersecurity risk
CommonSpirit Health suffered a ransomware attack this month, drawing attention to cybersecurity risks during the integration period of healthcare industry mergers and acquisitions. Experts point out that system integration, weak supply chains, and distracted executive attention during M&A make healthcare organizations more vulnerable to attacks. The FBI has also warned that ransomware groups tend to launch attacks during major financial events.

Earlier this month, CommonSpirit Health, formed in 2019 by the merger of Dignity Health and Catholic Health Initiatives, was still dealing with the aftermath of a ransomware attack. Security experts noted that such mergers and integrations can make healthcare systems more vulnerable to security breaches.
Mergers and acquisitions in the healthcare industry "create enormous risk" and also provide "enormous opportunities" for ransomware, said Israel Barak, chief information security officer at Cybereason, a company that helps defend businesses against attacks.
Barak added that healthcare deals carry a higher risk of cyberattacks because the supply chains of the systems involved are often relatively weak.
Systems like CommonSpirit rely on a vast network of suppliers. Most of them are smaller organizations with "very low security maturity," but they need to share large amounts of data among themselves, Barak said.
"This leads to a situation where a threat that enters the network from one point can affect a very wide range of entities within that network," Barak said.
Security experts believe that companies in the process of merging or being acquired become targets because executives often focus their attention on other priorities and may not be vigilant enough.
"Whenever there is chaos or uncertainty, attackers will try to seize the opportunity to launch an attack," said Aneeka Gupta, chief product officer at data security company Rubrik, whose clients include some of the largest U.S. companies.
The FBI has warnedthat ransomware attackers tend to target companies undergoing significant financial events, including mergers and acquisitions.
Fitch Ratings analysts said last week that CommonSpirit is in the process of a sizable debt issuance.
For an entity of this scale, integrating IT platforms and systems onto the same technology stack is not something that can be done overnight.
"Often, IT teams may need years to merge or agree on a particular technology portfolio," said Allie Mellen, senior analyst for security and risk at research and consulting firm Forrester.
Although some of CommonSpirit's affiliated systems did not show the same signs of attack, that does not necessarily mean they employ different security practices, Mellen said.
"They may have made design decisions to keep those systems relatively separate from an IT perspective," as a potential defensive measure, Mellen said.
Adequate due diligence needed before signing merger agreements
Experts say risk assessment needs to begin before the two companies are integrated. Before signing a merger agreement, companies need to scrutinize the cybersecurity risks of the deal with the same critical perspective they apply to other factors.
"Cyber due diligence should be part of assessing, alongside financial analysis, whether merging with or acquiring a particular entity poses risks to the organization," said John Riggi, cybersecurity and risk advisor at the American Hospital Association. He declined to comment directly on the CommonSpirit Health incident.
Part of the work also involves ensuring that a company does not inherit an attack, which is difficult because companies are often reluctant to disclose too much information before a deal is completed, said Barak of Cybereason.
Still, failed due diligence should serve as a warning, and PayPal's acquisition in 2017 is an example of what not to do before an acquisition, Barak said.
The digital payments company acquired Canadian payment processing company TIO for $238 million in 2017. Just months after the deal closed, PayPal announced it was suspending TIO's operations after discovering a security vulnerability that exposed the personal information of 1.6 million customers. The company disclosed in its 2017 annual report thatit expected to write down $168 million by 2022, a significant portion of the original purchase price.
Hotel chain Marriott, when it acquired Starwood Hotels & Resorts in 2016,unknowingly inherited a massive data breach. Two years later, Marriott said it discovered that hackers had been able to access sensitive customer information over four years, affecting 500 million people. The hacking incident did not affect Marriott's own properties; hackers breached Starwood's reservation database. According toreports, for a period after the merger, Marriott and Starwood's reservation databases remained separate.
Rubrik's Gupta said the hardest obstacle is not necessarily technology, but establishing the right people and processes.
Who is responsible when something goes wrong? That is a key question companies need to clarify before an attack occurs, Gupta said.
For healthcare companies that weave together the operations and management of legacy systems across different regions and states across the country, this can pose a challenge.
"Many times, organizations are not prepared. Maybe they have the technology in place, but they haven't even pre-planned what actions to take," Gupta said.
A cyberattack is a high-pressure crisis situation and should not be an occasion for some leaders to interact for the first time, Gupta said.
If companies have not refined these processes, they may face greater pressure to pay the ransom demanded by attackers to regain access to information or systems.
"From a people, process, and technology perspective, a lot of preparation must be done for organizations to stop paying ransoms," Gupta said.
CommonSpirit was born from a mega-merger
CommonSpirit is only three years old.
The system wasformed in 2019 following the mega-merger of San Francisco-based Dignity Health and Colorado-based Catholic Health Initiatives。
The deal stitched together Dignity's operations in the West with CHI's system primarily in the Midwest and South.
The merger created one of the largest healthcare systems in the U.S., with 142 hospitals across 21 states and combined revenue of nearly $29 billion in 2019.
At the time, executives claimed CommonSpiritaimed to address pressing national health issues, requiring greater scale and size to have a national impact.
According to its latest annual report, CommonSpirit now has more than 25,000 physicians and clinicians, as well as more than 2,200 care sites. This does not include other providers that interact with the system and share information as independent providers.
Healthcare Dive found that affiliated health systems in seven states displayed banners on their websites warning of ongoing IT issues, which may provide clues about the scope of the incident. With one exception, these warnings appeared on CHI-affiliated websites.
List of website warnings:
- CHI Saint Joseph Health - Kentucky
- CHI Health - Nebraska
- CHI Health - Iowa
- CHI St. Alexius Health - North Dakota
- CHI St. Gabriel's Health - Minnesota
- CHI St. Luke's - Texas
- CHI Baylor St. Luke's - Texas
- Virginia Mason Franciscan Health - Washington
CommonSpirit appears to confirm that the other half of its network—Dignity Health—did not suffer the same disruption.
In a recent statement, the system said its Dignity Health-affiliated systems, as well as TriHealth and Centura Health facilities, were unaffected in terms of clinics or patient care.
Combined with this statement and the online warnings, the attack appears to have been more severe for CHI Health entities.
The attack comes at a difficult time for healthcare providers.
The effects of the pandemic are still weighing on hospital operators, CommonSpirit said in its 2022 financial results. Staffing shortages drove up spending on more expensive labor. The system lost $1.8 billion in 2022.
However, Fitch Ratings said it does not expect a rating adjustment for the system due to the cyberattack. Fitch reported that CommonSpirit has cyber insurance coverage.