Public incident case study · Healthcare · United States

Change Healthcare Case Study

Initial access 12 February 2024 · ransomware and nationwide disruption 21 February

192.7Mpeople impacted by the breachChange Healthcare notified the U.S. Department of Health and Human Services in July 2025 that approximately 192.7 million individuals had been impacted, making the incident unprecedented in scale within the U.S. health sector.
US$3.87B+
disclosed response and business-disruption impact
>US$9B
interest-free funding advanced to care providers
9 days
from initial remote access to ransomware deployment
~US$22M
ransom reportedly paid
Executive summary

Incident sequence

  1. Compromised credentials bypassed control

    On 12 February 2024, the attackers used compromised credentials to remotely access a Change Healthcare Citrix portal used to provide access to desktops. UnitedHealth CEO Andrew Witty later testified that the portal did not have multi-factor authentication. The attackers then moved laterally through the environment and exfiltrated data.

  2. Ransomware triggered nationwide containment

    Nine days after the initial access, ransomware was deployed. UnitedHealth detected the activity on 21 February and disconnected affected Change Healthcare systems from connected environments. The resulting containment removed critical pharmacy, medical claims, payment, eligibility, and related services from normal operation across the U.S. health system.

  3. A technology outage became a health system liquidity crisis

    Hospitals, pharmacies, medical practices, and other providers experienced disrupted claims submission and reimbursement while Change Healthcare services were unavailable. UnitedHealth established temporary funding programs, introduced alternative claims-processing pathways, relaxed some care management requirements, and progressively restored pharmacy, payments, and medical-claims services while providers used manual and alternative workflows.

  4. The incident became a record-scale data breach

    UnitedHealth confirmed that a ransom was paid, with Congressional Research Service reporting the payment at approximately US$22 million in Bitcoin. Change Healthcare later confirmed that stolen information could include contact details, health insurance information, diagnoses and treatment information, billing and claims data, and, for some individuals, Social Security numbers or other identifiers. By July 2025, Change Healthcare had reported approximately 192.7 million affected individuals to HHS.

Full incident chronology

Incident timeline

Incident chronology.

  1. Initial access

    Compromised credentials reached a Citrix portal without MFA

    Attackers remotely accessed the portal with compromised credentials; UnitedHealth later confirmed that the affected access path did not use multi-factor authentication.

  2. 12–21 Feb 2024

    Attacker activity

    The attackers moved laterally and removed data

    During the period before ransomware deployment, the intruders traversed the environment and exfiltrated information later associated with the breach response.

  3. Ransomware

    Ransomware was deployed and detected

    UnitedHealth detected the attack nine days after initial access, triggering an enterprise incident response.

  4. Containment

    Change Healthcare systems were disconnected

    The containment decision removed pharmacy, claims, payments, eligibility, and related services from normal operation across the U.S. healthcare system.

  5. Late Feb–Mar 2024

    Healthcare continuity

    Providers shifted to funding support and alternative workflows

    UnitedHealth introduced temporary funding, alternative claims pathways, and relaxed requirements while hospitals, pharmacies, and practices managed delayed reimbursement.

  6. Mar–Apr 2024

    Service restoration

    Pharmacy, payment, and claims services returned progressively

    Restoration proceeded by service rather than as a single recovery event, leaving some providers on manual or alternate processes after core connections resumed.

  7. Ransom and breach disclosure

    UnitedHealth confirmed payment and extensive data exposure

    The company confirmed a ransom payment and described stolen information spanning insurance, treatment, billing, claims, contact, and identity data.

  8. Breach scale

    The reported affected population reached approximately 192.7 million

    HHS records reflected a record-scale affected population, while notification and longer-term response continued well beyond operational restoration.

Lykos analysis

What organisations should learn.

Why this matters to executives and boards

Change Healthcare demonstrates how a control weakness in one highly connected technology provider can become a sector-wide continuity event. The attackers didn't need to compromise thousands of hospitals or pharmacies individually. Disrupting a platform embedded in claims, payments, pharmacy transactions, and revenue-cycle processes was sufficient to create nationwide downstream impact. Cyber concentration risk therefore needs to be treated as an operational and financial resilience issue, not simply as third-party IT risk.

Readiness gaps and lessons visible in the public record

The clearest control deficiency in the public record is the absence of multi-factor authentication on the compromised externally accessible Citrix portal. UnitedHealth later described the server as legacy Change Healthcare technology that had not yet been brought to UnitedHealth standards following the acquisition. The case supports enforcing MFA across all remote access paths, continuously discovering legacy and acquired technology, rapidly disabling compromised identities, limiting lateral movement, understanding critical service dependencies, maintaining alternate transaction pathways, preparing liquidity support for downstream partners, and defining ransomware, notification, and regulatory decision-making before an incident occurs.

How Lykos helps

Turn the lesson into tested capability.

Operational resilience and business continuity

Build and re-test workable continuity, containment, and recovery arrangements before disruption.

Explore IR Readiness

Not sure where to begin? Start with Capability Validation.

Public record

Sources

Public record reviewed 22 Aug 2026.

  1. Testimony of Andrew Witty, Chief Executive Officer, UnitedHealth GroupU.S. House Committee on Energy and Commerce · 1 May 2024 · Executive congressional testimony
  2. Examining the Change Healthcare Cyber-attackU.S. House Committee on Energy and Commerce · 1 May 2024 · Congressional hearing
  3. Form 8-K/A — Change Healthcare Cybersecurity IncidentUnitedHealth Group / U.S. Securities and Exchange Commission · 8 Mar 2024 · Company regulatory filing
  4. Dear Colleague Letter: Cyber-attack on Change HealthcareU.S. Department of Health and Human Services, Office for Civil Rights · 13 Mar 2024 · Regulator statement
  5. UnitedHealth Group Update on Change Healthcare Cyber-attackUnitedHealth Group · 7 Mar 2024 · Company statement
  6. UnitedHealth Group Updates on Change Healthcare Cyber-attackUnitedHealth Group · 22 Apr 2024 · Company statement
  7. The Change Healthcare Cyber-attack and Response Considerations for PolicymakersCongressional Research Service · 24 Apr 2024 · Government analysis
  8. HIPAA Website Substitute NoticeChange Healthcare · 14 Jan 2025 · Company breach notice
  9. UnitedHealth Group Form 10-K for the year ended 31 December 2024UnitedHealth Group / U.S. Securities and Exchange Commission · 27 Feb 2025 · Company regulatory filing
  10. Change Healthcare Cybersecurity Incident Frequently Asked QuestionsU.S. Department of Health and Human Services, Office for Civil Rights · 31 Jul 2025 · Regulator update
  11. UnitedHealth Group Form 10-K for the year ended 31 December 2025UnitedHealth Group / U.S. Securities and Exchange Commission · 2 Mar 2026 · Company regulatory filing