Skip to main content

Hospitals were overpaid after Change cyberattack, Health Affairs says

CMS distributed $3.3B to providers experiencing revenue disruptions, including $2.2B to hospitals, report says.
By Susan Morse , Executive Editor
Clinicians talking at computer

Photo: Reza Estakhrian/Getty Images

The federal government overpaid hospitals and other providers in relief funding following the February 2024 cyberattack on Change Healthcare, according to a new Health Affairs report. 

The Centers for Medicare and Medicaid Services distributed $3.3 billion to providers experiencing revenue disruptions, including $2.2 billion to hospitals, the report said. 

“We found that the opt-in, one-size-fits-all nature of this relief funding simultaneously resulted in overpayments to many participating hospitals and underparticipation by many hospitals that had likely been disrupted by the cyberattack,” the report said.

Health Affairs released “Lessons from CMS Relief Funding After Cyberattack on Change Healthcare” this month.

The design of future provider relief payments could be improved for accuracy, Health Affairs recommended. For example, CMS might adjust amounts downward from 30-day average payments. CMS could also build in outlier payments for providers experiencing unusually severe disruptions, reflecting the finding that some recipients experienced a revenue disruption far exceeding their 30-day average payment amount.

WHY THIS MATTERS

Change Healthcare was hit by the ransomware attack in February 2024, about two years after UnitedHealth Group bought the company. The cyberattack affected Change’s claims processing business, which impacted hospital payments nationwide. 

CMS stepped in to help with reimbursement issues, establishing the Change Healthcare/Optum Payment Disruption accelerated and advance payment program, or CHOPD. The goal was to alleviate the financial strain from disruptions to Medicare reimbursement, the report said.

From March through July 2024, CHOPD paid $3.3 billion in program payments.

Of the 8,538 Medicare Parts A and B suppliers that received a total of $3.3 billion in advance payments through CMS’ CHOPD program, individual physicians or physician group practices represented 42.4% of the payments, followed by dialysis facilities at 31.2%. 

Despite representing only 7.7% of CHOPD program payment recipients, hospitals received 67.1% of total payments, with physicians coming in a distant second at 18.8%, Health Affairs said.

Hospitals experienced six weeks of reduced revenue at the time of the cyberattack compared with one year prior. 

Hospitals that received CHOPD program payments were more likely to be nonprofit, non-publicly owned and affiliated with a health system.

In addition to overpayment in the CHOPD program, Health Affairs also found evidence of underparticipation. Specifically, 312 hospitals experienced a Medicare revenue loss during the first six weeks of the cyberattack that was equal to or exceeding the revenue loss of the median CHOPD program recipient. This suggests that a large number of hospitals were disrupted by the cyberattack but did not apply for CHOPD program payments, Health Affairs said.

THE LARGER TREND

The study had limitations, authors said.

First, attributing changes in revenue from 2023 to 2024 could not be definitely determined to be caused by the Change cyberattack. 

“However, we know of no other nationwide events at that time that would have led to such a large decrease in hospital revenue from Medicare, and we estimated sharp changes in revenue that corresponded to the periods of greatest disruption as reported in the media (mid-February 2024),” the report said.

Secondly, Health Affairs was limited to observing revenue from fee-for-service Medicare, which represents only part of most hospitals’ incoming patient care revenue. 

Third, its analysis did not include any information on payments through UnitedHealth Group’s temporary funding assistance program.

Finally, the report said that its analysis could not speak to how hospitals allocated CHOPD program payments. 

Email the writer: SMorse@himss.org