RealCyberNews
Back to latest
criticalFebruary 21, 2024 · 5 min read

The Change Healthcare Breach: The Largest Healthcare Hack in US History

A ransomware attack on a single billing company froze prescriptions and payments across the entire US healthcare system for weeks. Here's what happened and who was affected.

By RealCyberNews Editorial Team

Share

In February 2024, a ransomware attack on Change Healthcare — a company most patients have never heard of — disrupted prescriptions, insurance claims, and payments at pharmacies and hospitals nationwide, in what regulators later confirmed was the largest healthcare data breach in US history.

Why a company you’ve never heard of could break the whole system

Change Healthcare isn’t a hospital or insurer — it’s a billing and claims-processing middleman that sits behind the scenes of a huge share of US healthcare transactions, owned by UnitedHealth Group’s Optum division. When its systems went down, pharmacies couldn’t process insurance claims, hospitals couldn’t submit bills, and some patients couldn’t get prescriptions filled or had to pay full price out of pocket, all without ever being a “customer” of Change Healthcare directly.

What was actually exposed

The attackers, a ransomware group, stole a massive volume of data before encrypting systems — later estimates put the number of affected individuals at over 100 million, covering health records, insurance information, and personal identifying details. UnitedHealth confirmed it paid a ransom to the attackers, and disruption to claims processing lasted for weeks.

Why this incident matters more than a typical breach

Most breaches expose your data. This one also broke the plumbing that gets people their medication and gets providers paid — a reminder that healthcare cybersecurity isn’t just a privacy issue, it’s a patient-safety and access issue.

What to actually do about it

  • If you received a notification letter from Change Healthcare, UnitedHealth, or your provider, it will specify what data of yours was involved — read it rather than assume the worst or dismiss it.
  • Watch your insurance explanation-of-benefits statements for claims you don’t recognize, which can indicate medical identity theft.
  • Freeze your credit if Social Security numbers were part of what was exposed for you specifically.
  • Understand this happened upstream of your own choices — there was nothing an individual patient could have done differently to prevent this, since the exposure happened at a vendor most people never directly interact with.

Worried this affects you?

Check whether your email address has shown up in this breach — or any other — in seconds.

Run a free breach check →