Skip to main content
Breach Signal

Breach report

Healthcare

Change Healthcare (UnitedHealth Group)

UnitedHealth confirms 190 million Americans affected by Change Healthcare data breach

A ransomware attack on UnitedHealth's claims-processing unit paralyzed pharmacies and billing nationwide and exposed medical and personal data on roughly 190 million Americans, the largest health data breach in U.S. history.

Reported by TechCrunch

Records exposed

190M

About 190 million people (later reported to HHS as roughly 192.7 million)

Scale vs. largest on file

When
2024
How they got in
Ransomware via stolen credentials on a remote-access portal without multi-factor authentication
Sector
Healthcare

In February 2024, criminals linked to the ALPHV/BlackCat ransomware operation broke into Change Healthcare, the UnitedHealth Group subsidiary that routes a huge share of American medical claims, prescriptions and payments. The intrusion began around February 12 and was detected on February 21, when the company began pulling systems offline. The shutdown rippled across the U.S. health system for weeks: pharmacies could not process insurance, hospitals and small practices lost cash flow, and some providers borrowed money to make payroll. Because Change handles billions of healthcare transactions a year, providers had few ready alternatives.

The entry point was strikingly basic. UnitedHealth chief executive Andrew Witty told Congress in May 2024 that attackers used a stolen username and password to log into a Citrix remote-access portal that was not protected by multi-factor authentication. Once inside, they moved through the network for days, stole large volumes of data and then deployed ransomware.

UnitedHealth paid a $22 million ransom in March 2024, but the ALPHV gang appears to have pocketed the money and vanished, leaving the affiliate who carried out the attack unpaid and still holding the data. A new group, RansomHub, then attempted a second extortion and posted samples of patient records. UnitedHealth has said it paid more than one ransom to try to contain publication.

The scale of the exposure grew steadily. The company first warned that a substantial proportion of Americans could be affected, confirmed at least 100 million people in October 2024, and in January 2025 put the total at about 190 million, later filed with federal regulators as roughly 192.7 million. Stolen information varied by person but included Social Security numbers, government ID numbers, diagnoses, medications, test results, insurance details and banking data drawn from claims.

The fallout has been enormous. UnitedHealth has reported billions of dollars in response costs, including emergency loans to providers. Nebraska's attorney general sued the company, dozens of class actions were consolidated, and lawmakers used the case to push for mandatory cybersecurity standards in health care. The breach showed how concentrated the U.S. medical payment system has become: a single compromised password at one intermediary exposed the records of more than half the country, most of whom had never heard of Change Healthcare.

More from the wire

More in Healthcare.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.