In late February 2024, pharmacists across America started handing back prescriptions they could not fill. Their software would not confirm insurance. Claims bounced. In hospitals, billing froze, and in small clinics the money simply stopped arriving, leaving some owners to quietly count how many weeks of payroll they had left before the doors would have to close. None of these people had been hacked. Their patients had not been hacked either. They were all just downstream of one company most of them had never heard of, and that company had left a single door unlocked. Behind it sat the medical records of roughly a third of the country.

Key Takeaways

  • The February 2024 Change Healthcare attack is the largest healthcare data breach in US history, exposing the personal and medical data of an estimated 190 million people or more.
  • The way in was a single server with no multi-factor authentication. Attackers used stolen credentials on a Citrix remote-access portal that any second factor would have protected.
  • UnitedHealth paid about $22 million in ransom, and it did not work. The gang exit-scammed its own affiliate, who kept the stolen data and demanded a second payment.
  • The disruption was national. Prescription and claims systems were down for weeks, and UnitedHealth advanced billions of dollars to providers who suddenly could not get paid.
  • The total cost cleared $2.8 billion, and lawsuits and regulatory questions are still open more than a year later.

What Was the Change Healthcare Hack?

In plain terms, the Change Healthcare hack was a ransomware attack that knocked out a chunk of America’s medical payments system for weeks. Change Healthcare is not a household name. That is exactly why it mattered. Owned by UnitedHealth Group through its Optum division, the company is a clearinghouse: the invisible switchboard that quietly connects doctors, pharmacies, hospitals and insurers so that claims get verified, prescriptions get approved, and money moves through the whole system without anyone ever noticing the wiring underneath. It touches an estimated one in three US patient records. Billions of transactions run through it every year.

Concentrate that much of a country’s healthcare plumbing into one company and you create a single point of failure. On February 21, 2024, that point failed. Change took its systems offline to contain a ransomware infection, and because so much of the industry ran through it, taking Change offline meant taking a large piece of American healthcare offline with it. Pharmacies switched to paper and phone calls. Providers went unpaid. Some services stayed dark for weeks, and a handful took months to come fully back online.

How Did Hackers Get Into Change Healthcare?

They used a stolen password on a server that asked for nothing else. An affiliate of the ALPHV/BlackCat ransomware group logged into a Change Healthcare Citrix remote-access portal on February 12, 2024, using compromised credentials. That portal, a gateway straight into the internal network, was not protected by multi-factor authentication. No code from an app, no tap on a phone, no second check of any kind stood behind it. One stolen login was the entire lock, and the attackers walked in holding the key.

Once inside, they did what modern ransomware crews do: they moved slowly. For roughly nine days they explored the network, spread their access, and quietly copied data out, an estimated 6 terabytes of it, including health records, before anyone noticed. Only on February 21 did they trigger the ransomware itself and encrypt Change’s systems. By then the theft was already complete. For more than a week, the lock on the front door had simply been missing.

Date (2024)What happened
February 12Attackers log into a Citrix portal with stolen credentials; no MFA stops them
February 12 to 20Nine days of lateral movement; about 6TB of data quietly stolen
February 21Ransomware is triggered; Change takes systems offline and the national outage begins
March 3UnitedHealth pays roughly $22 million in Bitcoin to ALPHV/BlackCat
Early MarchALPHV exit-scams its affiliate, who keeps the data and later re-extorts Change
May 1CEO Andrew Witty tells Congress the breached portal had no multi-factor authentication

Did Change Healthcare Pay the Ransom?

Yes, and it is a case study in why paying often solves nothing. On March 3, 2024, UnitedHealth sent about $22 million in Bitcoin to the ALPHV/BlackCat group, hoping to keep the stolen patient data from being leaked. What happened next reads like a heist that turned on itself. ALPHV took the full payment and then vanished, stiffing the affiliate who had actually done the hacking and staging a fake law-enforcement takedown of its own website to cover the exit.

Their own affiliate, unpaid and furious, still had a copy of everything. So the data moved to a second gang, RansomHub, which promptly demanded a fresh ransom of its own. UnitedHealth had paid $22 million and received, in return, a second extortion threat and not one shred of proof that the data was ever deleted. Twice burned. This is the quiet truth about ransoms that the hacks archive keeps running into: a receipt from a criminal is worthless, and the only people who reliably profit from a payment are the ones planning the next attack.

The Critical Choice

The decision that made this disaster inevitable was almost insultingly small: leaving that one remote-access server without multi-factor authentication. MFA is not exotic. It is the same second step your bank app nags you about, it costs almost nothing, and UnitedHealth required it in plenty of other places. On this particular gateway, the one that happened to open into the network holding a third of America’s health data, it simply was not turned on. Andrew Witty, UnitedHealth’s own chief executive, admitted as much under oath to Congress. One missing checkbox, on one server, was the entire difference between a blocked login and the largest medical breach in history.

The reason that small gap became a national emergency is the bigger, slower choice sitting behind it. UnitedHealth spent years buying up the connective tissue of American healthcare and routing it through Change, building exactly the kind of single point of failure that regulators warned about when they tried and failed to block the deal. When you make one company indispensable to a whole industry, you also make its worst day everyone’s worst day. The missing MFA lit the match. The decision to concentrate that much of the system in one place is what turned a break-in into a country-wide blackout, the same money-and-power logic that runs through the quiet monopolies we investigate.

Where Things Stand Now

More than a year later, the numbers have only grown. UnitedHealth confirmed in January 2025 that around 190 million people were affected, a figure later revised to roughly 192.7 million, close to two-thirds of everyone in the country. Counting the ransom, the recovery and the billions advanced to providers who could not bill during the outage, the financial hit to UnitedHealth cleared $2.8 billion. Class-action lawsuits and state investigations are still working through the courts, and no global settlement has been reached.

Our take: the enduring scandal here is not that a sophisticated gang got in, because they were not sophisticated. They logged in. No, the real scandal is that a company entrusted with the medical histories of most of the nation guarded its door with less security than a personal email account, and that so much of the system had been funneled through that single door in the first place. Those attackers exposed a vulnerability. They did not create it. That was a choice, made long before February 2024, to build something too big to fail and then protect it as if it could not. For the human side of medical-system security, watch the strange story of a cybersecurity CEO caught hacking a hospital, and see how the same unlocked-door pattern played out when one phone call shut down MGM’s casinos. This page will be updated as the litigation and the final breach count are resolved.