Public incident case study · Healthcare · United States
Change Healthcare Case Study
Initial access 12 February 2024 · ransomware and nationwide disruption 21 February
- US$3.87B+
- disclosed response and business-disruption impact
- >US$9B
- interest-free funding advanced to care providers
- 9 days
- from initial remote access to ransomware deployment
- ~US$22M
- ransom reportedly paid
Executive summary
Incident sequence
Compromised credentials bypassed control
On 12 February 2024, the attackers used compromised credentials to remotely access a Change Healthcare Citrix portal used to provide access to desktops. UnitedHealth CEO Andrew Witty later testified that the portal did not have multi-factor authentication. The attackers then moved laterally through the environment and exfiltrated data.
Ransomware triggered nationwide containment
Nine days after the initial access, ransomware was deployed. UnitedHealth detected the activity on 21 February and disconnected affected Change Healthcare systems from connected environments. The resulting containment removed critical pharmacy, medical claims, payment, eligibility, and related services from normal operation across the U.S. health system.
A technology outage became a health system liquidity crisis
Hospitals, pharmacies, medical practices, and other providers experienced disrupted claims submission and reimbursement while Change Healthcare services were unavailable. UnitedHealth established temporary funding programs, introduced alternative claims-processing pathways, relaxed some care management requirements, and progressively restored pharmacy, payments, and medical-claims services while providers used manual and alternative workflows.
The incident became a record-scale data breach
UnitedHealth confirmed that a ransom was paid, with Congressional Research Service reporting the payment at approximately US$22 million in Bitcoin. Change Healthcare later confirmed that stolen information could include contact details, health insurance information, diagnoses and treatment information, billing and claims data, and, for some individuals, Social Security numbers or other identifiers. By July 2025, Change Healthcare had reported approximately 192.7 million affected individuals to HHS.
Full incident chronology
Incident timeline
Incident chronology.
Initial access
Compromised credentials reached a Citrix portal without MFA
Attackers remotely accessed the portal with compromised credentials; UnitedHealth later confirmed that the affected access path did not use multi-factor authentication.
- 12–21 Feb 2024
Attacker activity
The attackers moved laterally and removed data
During the period before ransomware deployment, the intruders traversed the environment and exfiltrated information later associated with the breach response.
Ransomware
Ransomware was deployed and detected
UnitedHealth detected the attack nine days after initial access, triggering an enterprise incident response.
Containment
Change Healthcare systems were disconnected
The containment decision removed pharmacy, claims, payments, eligibility, and related services from normal operation across the U.S. healthcare system.
- Late Feb–Mar 2024
Healthcare continuity
Providers shifted to funding support and alternative workflows
UnitedHealth introduced temporary funding, alternative claims pathways, and relaxed requirements while hospitals, pharmacies, and practices managed delayed reimbursement.
- Mar–Apr 2024
Service restoration
Pharmacy, payment, and claims services returned progressively
Restoration proceeded by service rather than as a single recovery event, leaving some providers on manual or alternate processes after core connections resumed.
Ransom and breach disclosure
UnitedHealth confirmed payment and extensive data exposure
The company confirmed a ransom payment and described stolen information spanning insurance, treatment, billing, claims, contact, and identity data.
Breach scale
The reported affected population reached approximately 192.7 million
HHS records reflected a record-scale affected population, while notification and longer-term response continued well beyond operational restoration.
Lykos analysis
What organisations should learn.
Why this matters to executives and boards
Change Healthcare demonstrates how a control weakness in one highly connected technology provider can become a sector-wide continuity event. The attackers didn't need to compromise thousands of hospitals or pharmacies individually. Disrupting a platform embedded in claims, payments, pharmacy transactions, and revenue-cycle processes was sufficient to create nationwide downstream impact. Cyber concentration risk therefore needs to be treated as an operational and financial resilience issue, not simply as third-party IT risk.
Readiness gaps and lessons visible in the public record
The clearest control deficiency in the public record is the absence of multi-factor authentication on the compromised externally accessible Citrix portal. UnitedHealth later described the server as legacy Change Healthcare technology that had not yet been brought to UnitedHealth standards following the acquisition. The case supports enforcing MFA across all remote access paths, continuously discovering legacy and acquired technology, rapidly disabling compromised identities, limiting lateral movement, understanding critical service dependencies, maintaining alternate transaction pathways, preparing liquidity support for downstream partners, and defining ransomware, notification, and regulatory decision-making before an incident occurs.
How Lykos helps
Turn the lesson into tested capability.
Identity and access
Validate privileged access, MFA, and account-control decisions across response-critical systems.
Explore Capability ValidationThird-party risk
Exercise provider failure, alternate workflows, notification, and safe reconnection decisions.
Explore Tabletop ExercisesOperational resilience and business continuity
Build and re-test workable continuity, containment, and recovery arrangements before disruption.
Explore IR ReadinessNot sure where to begin? Start with Capability Validation.
Public record
Sources
Public record reviewed 22 Aug 2026.
- Testimony of Andrew Witty, Chief Executive Officer, UnitedHealth GroupU.S. House Committee on Energy and Commerce · 1 May 2024 · Executive congressional testimony
- Examining the Change Healthcare Cyber-attackU.S. House Committee on Energy and Commerce · 1 May 2024 · Congressional hearing
- Form 8-K/A — Change Healthcare Cybersecurity IncidentUnitedHealth Group / U.S. Securities and Exchange Commission · 8 Mar 2024 · Company regulatory filing
- Dear Colleague Letter: Cyber-attack on Change HealthcareU.S. Department of Health and Human Services, Office for Civil Rights · 13 Mar 2024 · Regulator statement
- UnitedHealth Group Update on Change Healthcare Cyber-attackUnitedHealth Group · 7 Mar 2024 · Company statement
- UnitedHealth Group Updates on Change Healthcare Cyber-attackUnitedHealth Group · 22 Apr 2024 · Company statement
- The Change Healthcare Cyber-attack and Response Considerations for PolicymakersCongressional Research Service · 24 Apr 2024 · Government analysis
- HIPAA Website Substitute NoticeChange Healthcare · 14 Jan 2025 · Company breach notice
- UnitedHealth Group Form 10-K for the year ended 31 December 2024UnitedHealth Group / U.S. Securities and Exchange Commission · 27 Feb 2025 · Company regulatory filing
- Change Healthcare Cybersecurity Incident Frequently Asked QuestionsU.S. Department of Health and Human Services, Office for Civil Rights · 31 Jul 2025 · Regulator update
- UnitedHealth Group Form 10-K for the year ended 31 December 2025UnitedHealth Group / U.S. Securities and Exchange Commission · 2 Mar 2026 · Company regulatory filing