← Case Files · The Breach Files

2024 · Healthcare payments

Change Healthcare, 2024: one login, and American healthcare stopped billing

Case file · 4 min read · Published 14 September 2026

People affected
about 190 million people
When it happened
February 2024
Made public
21 February 2024
How they got in
Stolen credentials used on a Citrix remote access portal that had no multi-factor authentication
Attributed to
The ALPHV/BlackCat ransomware group; a second extortion attempt followed from RansomHub
What it cost
A $22 million ransom paid, and roughly $3 billion in response costs reported by the parent company

What was exposed: Names · Addresses · Dates of birth · Social Security numbers · Health insurance details · Diagnoses and treatment information · Billing and claims data

On 21 February 2024, the company that processes a very large share of American medical claims went dark. For weeks afterwards, pharmacists could not tell patients whether their insurance covered a prescription, and doctors' practices could not bill for work they had already done. The way in was a remote access portal with no second factor on it.

What happened

Change Healthcare, part of UnitedHealth Group's Optum division, is infrastructure. It sits between providers, pharmacies and insurers, handling eligibility checks, claims and payments at enormous volume. Most patients have never heard of it, which is exactly the profile of the systems whose failure is most disruptive.

Attackers associated with the ALPHV/BlackCat ransomware operation obtained credentials for a Citrix remote access portal. That portal did not enforce multi-factor authentication, so the password was sufficient. They were inside for more than a week — moving laterally, staging data — before deploying ransomware on 21 February.

The company disconnected systems to contain it. That containment decision was correct and it was also what produced the national disruption: pulling the plug on the clearing house meant pulling the plug on the payment flow for a third of the country's medical transactions.

The finding, stated plainly. UnitedHealth's chief executive told Congress that the portal lacked multi-factor authentication. A company with revenues in the hundreds of billions, running systemically important infrastructure, was entered through a remote access server protected by a password alone. Every other detail of this case is downstream of that sentence.

What the outage actually did

The cyber-physical consequences are easy to underrate from a distance:

  1. Pharmacies could not check coverage. Patients were asked to pay cash prices for medication or go without, including for insulin and cardiac drugs.
  2. Providers could not bill. Small practices, community clinics and behavioural health providers operate on thin cash reserves; within weeks some were unable to make payroll.
  3. Emergency funding became necessary. UnitedHealth advanced billions of dollars to providers, and federal agencies relaxed rules to let claims flow through alternative channels.
  4. The backlog outlasted the outage. Restoring systems is not the same as clearing months of unprocessed claims, and the financial effects ran through the rest of 2024.

This is what "critical infrastructure" means in practice. Not power stations and water treatment alone — the payment rails that make ordinary services function.

The ransom, and why paying failed twice

Roughly $22 million in bitcoin moved to an address associated with ALPHV. The transaction was visible on the blockchain and widely analysed.

What followed is the clearest public illustration of why payment is an unreliable transaction. The affiliate who had actually carried out the intrusion complained publicly that ALPHV had taken the money and vanished, and ALPHV's infrastructure went offline shortly afterwards in what appeared to be an exit scam. Then, months later, a different group — RansomHub — attempted to extort the company again, claiming to hold the same data.

The victim paid, and the data was still in circulation and still being used as leverage. When people argue that paying buys nothing enforceable, this is the case they mean.

The timeline

  1. Early February 2024 — Stolen credentials are used on a Citrix portal without MFA; attackers establish access.
  2. 21 February 2024 — Ransomware is deployed; Change Healthcare disconnects systems.
  3. Late February – March — Pharmacy and claims disruption spreads nationally; emergency funding and workarounds are arranged.
  4. March 2024 — A $22 million payment to ALPHV is identified on the blockchain; the group's infrastructure goes offline.
  5. April 2024 — RansomHub attempts a second extortion using apparently the same data.
  6. May 2024 — UnitedHealth's chief executive testifies that the portal lacked multi-factor authentication.
  7. October 2024 — The affected population is reported as approximately 100 million.
  8. January 2025 — The figure is revised to approximately 190 million.

What it changed

Healthcare consolidation became a security argument. The disruption was severe precisely because so much of the payment system runs through one company. Regulators and legislators who had treated healthcare consolidation purely as a competition question started treating it as a concentration risk — single points of failure created by acquisition.

MFA on remote access stopped being negotiable. It was already standard advice. After a $3 billion incident traced to its absence on one portal, it became the first question in every healthcare security assessment and a condition in cyber insurance underwriting.

Third-party dependency mapping got funding. Thousands of organisations discovered they depended on Change Healthcare only when it stopped. The exercise of knowing which suppliers your operations cannot survive losing — and for how long — moved from a compliance artefact to a real programme.

If you are one of the 190 million

Most people in this file have never had any relationship with Change Healthcare. It processed claims on behalf of insurers and providers, which is how a company you have never heard of ends up holding your diagnoses.

  1. Freeze your credit files. Social Security numbers were in the data; this is the control that blocks new-account fraud.
  2. Read every explanation of benefits. Medical identity fraud surfaces there first, if it surfaces at all.
  3. Treat health-related calls and letters as unverified. Claims data makes an approach specific enough to be convincing — the checks that still work.
  4. Take the free monitoring if it was offered to you, but do not mistake it for protection. Monitoring reports fraud after it happens; a freeze prevents a category of it.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

How did the Change Healthcare attack happen?

Attackers used stolen credentials on a Citrix remote access portal that was not protected by multi-factor authentication. The company's parent, UnitedHealth Group, confirmed this in congressional testimony. Once inside, the group moved through the network for more than a week before deploying ransomware.

Why did it disrupt so much of US healthcare?

Change Healthcare sits in the middle of the American medical payment system, handling a very large share of claims, eligibility checks and pharmacy transactions. When it went offline, pharmacies could not verify coverage or process claims, and providers could not bill. Independent practices ran out of cash within weeks; UnitedHealth advanced billions of dollars in emergency funding.

Did they pay the ransom?

Yes — about $22 million in bitcoin, traced publicly on the blockchain. It did not resolve matters: the affiliate who carried out the intrusion accused ALPHV of taking the payment and disappearing, and a second group, RansomHub, later attempted to extort the company again using what appeared to be the same data.

How many people were affected?

The estimate was 100 million in October 2024 and was revised to roughly 190 million in January 2025, making it the largest breach of protected health information ever reported in the United States — more than half the country's population.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →