The Change Healthcare Breach: The Largest Healthcare Hack in US History
A ransomware attack on a single billing company froze prescriptions and payments across the entire US healthcare system for weeks. Here's what happened and who was affected.
In February 2024, a ransomware attack on Change Healthcare — a company most patients have never heard of — disrupted prescriptions, insurance claims, and payments at pharmacies and hospitals nationwide, in what regulators later confirmed was the largest healthcare data breach in US history.
Why a company you’ve never heard of could break the whole system
Change Healthcare isn’t a hospital or insurer — it’s a billing and claims-processing middleman that sits behind the scenes of a huge share of US healthcare transactions, owned by UnitedHealth Group’s Optum division. When its systems went down, pharmacies couldn’t process insurance claims, hospitals couldn’t submit bills, and some patients couldn’t get prescriptions filled or had to pay full price out of pocket, all without ever being a “customer” of Change Healthcare directly.
What was actually exposed
The attackers, a ransomware group, stole a massive volume of data before encrypting systems — later estimates put the number of affected individuals at over 100 million, covering health records, insurance information, and personal identifying details. UnitedHealth confirmed it paid a ransom to the attackers, and disruption to claims processing lasted for weeks.
Why this incident matters more than a typical breach
Most breaches expose your data. This one also broke the plumbing that gets people their medication and gets providers paid — a reminder that healthcare cybersecurity isn’t just a privacy issue, it’s a patient-safety and access issue.
What to actually do about it
- If you received a notification letter from Change Healthcare, UnitedHealth, or your provider, it will specify what data of yours was involved — read it rather than assume the worst or dismiss it.
- Watch your insurance explanation-of-benefits statements for claims you don’t recognize, which can indicate medical identity theft.
- Freeze your credit if Social Security numbers were part of what was exposed for you specifically.
- Understand this happened upstream of your own choices — there was nothing an individual patient could have done differently to prevent this, since the exposure happened at a vendor most people never directly interact with.
Worried this affects you?
Check whether your email address has shown up in this breach — or any other — in seconds.
Run a free breach check →Related coverage
HCA Healthcare: 11 Million Patient Records, One Exposed Storage Location
One of the largest hospital operators in the country lost patient data not through a sophisticated hack, but through a misconfigured external storage location. Here's what that means.
The MOVEit Breach Explained: What Actually Happened
A 2023 flaw in a file-transfer tool used by thousands of companies led to one of the largest data breaches in recent memory. Here's what it means if you got a notification letter.