For roughly ten days in late February 2024, a single compromised login screen brought a meaningful slice of the American healthcare payment system to a standstill. Pharmacies couldn’t verify insurance. Hospitals couldn’t submit claims. Some providers went weeks without being able to bill for care they had already delivered. The cause was not a sophisticated zero-day exploit or a nation-state operation — by most public accounts, it was a remote-access portal without multi-factor authentication.

The Change Healthcare cyberattack has become the reference case for what happens when a single vendor sits at a chokepoint in a critical industry’s infrastructure. This article walks through what is publicly known about the incident as of mid-2024, why its ripple effects were so disproportionate to the initial point of entry, and the resilience lessons healthcare organizations and their boards are drawing from it.

What happened: a timeline of the attack

Change Healthcare, a subsidiary of Optum and ultimately UnitedHealth Group (UHG), operates one of the largest clearinghouses for medical claims, eligibility checks, and pharmacy transactions in the United States. According to testimony UHG CEO Andrew Witty gave to Congress in May 2024, the intrusion unfolded roughly as follows:

  • February 12, 2024 — Attackers used compromised credentials to log into a Citrix remote-access portal that, according to Witty’s testimony, was not protected by multi-factor authentication.
  • February 12–21, 2024 — The threat actor moved through internal systems, reportedly exfiltrating data before deploying ransomware.
  • February 21, 2024 — Ransomware executed across Change Healthcare’s IT environment, encrypting systems and forcing the company to disconnect and shut down thousands of applications to contain the spread.
  • February 22–23, 2024 — UnitedHealth Group publicly disclosed the cyberattack, confirming widespread outages across its claims and payment platforms.
  • Early March 2024 — Blockchain researchers identified a transaction of roughly 350 bitcoin (reported at the time to be worth approximately $22 million) sent to a wallet associated with the ALPHV/BlackCat group. UHG later confirmed to Congress that it made a ransom payment.
  • March 7 and after — UnitedHealth began restoring pharmacy and payment functions in stages, with the company describing a “multi-week” timeline for fuller claims-processing recovery.

By the time Witty testified before the Senate Finance Committee and a House Energy and Commerce subcommittee in May 2024, the company estimated the breach could affect a substantial share of Americans — though the final scope of affected individuals continued to be revised upward well after the initial disclosure, underscoring how difficult these numbers are to pin down in the early months of a breach of this size. Organizations tracking their own exposure should watch for updated notices rather than relying on any single early estimate.

The threat actor: ALPHV/BlackCat

Responsibility for the attack was claimed by ALPHV, also known as BlackCat, a ransomware-as-a-service operation that the FBI and CISA had already flagged as one of the most prolific ransomware families targeting critical infrastructure sectors, including healthcare. Ransomware-as-a-service groups license their malware and infrastructure to affiliates, who carry out the intrusions and split any ransom proceeds with the operators.

That affiliate structure produced an unusual coda to this incident. Shortly after the reported $22 million payment, an affiliate publicly claimed that ALPHV’s core operators had taken the entire payment for themselves in an apparent exit scam, staging a fake FBI takedown notice on their own leak site rather than actually shutting down. If accurate, this means Change Healthcare may have paid a ransom without receiving the guarantees typically implied by such payments, and that stolen data may have remained exposed regardless. That tension — paying to prevent disclosure with no enforceable guarantee the data is deleted — is one reason law enforcement agencies including the FBI have long discouraged ransom payments, even as they acknowledge the decision ultimately rests with the victim organization.

Nationwide disruption: claims, pharmacy, and payments

What set this incident apart from other healthcare breaches was not the sophistication of the intrusion but the sheer footprint of the system taken offline. Change Healthcare’s platforms reportedly touch a very large share of U.S. medical claims and pharmacy transactions, functioning as connective tissue between providers, pharmacies, and payers rather than being visible to patients directly.

When those systems went dark, the effects cascaded in several directions at once:

  • Pharmacy operations. E-prescribing and pharmacy claims-adjudication services were disrupted, and reports from pharmacists and patients described delays filling prescriptions, with some patients paying cash or going without medication while systems were down.
  • Hospital and provider claims. Surveys conducted by the American Hospital Association (AHA) in the weeks following the attack found that the substantial majority of responding hospitals reported direct financial impact, with many unable to submit claims, verify patient eligibility, or receive claim payments through their normal channels.
  • Cash flow strain. Because claims and reimbursements stalled, many providers — particularly smaller practices and rural hospitals with thinner cash reserves — faced acute liquidity problems even though the care they delivered was unaffected. UnitedHealth and other payers subsequently offered advance-payment and loan programs to bridge providers through the outage.
  • Downstream administrative backlog. Even after core systems were restored in stages through March 2024, providers described a lingering backlog of unprocessed claims that took additional time to clear.

The Department of Health and Human Services (HHS) responded by issuing guidance allowing affected covered entities to delegate HIPAA breach-notification obligations to Change Healthcare, and by opening an Office for Civil Rights (OCR) investigation into whether the breach involved a violation of the HIPAA Security Rule. That OCR inquiry, along with a wave of state attorney general and congressional scrutiny, remained active as of mid-2024.

Why concentration risk mattered

The most widely discussed lesson from this incident is not really about ransomware at all — it is about market structure. Change Healthcare’s role as a dominant clearinghouse meant that a single company’s security failure had the practical effect of disabling infrastructure that thousands of unrelated hospitals, pharmacies, and physician practices had no direct relationship with and no visibility into.

This is the definition of concentration risk: when a critical function is consolidated in one vendor (or a small handful of vendors), that vendor’s failure stops being a contained, single-organization event and becomes a systemic one. Healthcare has consolidated significant claims, payment, and data-exchange infrastructure into a small number of large intermediaries over the past decade, often for legitimate efficiency reasons. The Change Healthcare incident showed the other side of that trade-off: efficiency gains concentrated in fewer hands also concentrate risk.

Members of Congress questioned UHG executives directly about whether the company’s scale — as both a major insurer and the owner of a dominant claims clearinghouse — had made the healthcare system more fragile rather than less. Regardless of how that policy debate resolves, the operational reality for any hospital, health system, or practice is the same: a critical vendor’s outage can become your outage, on a timeline and to a degree you don’t control.

The ransom payment controversy

UnitedHealth’s decision to pay a reported $22 million ransom drew scrutiny from multiple directions. Witty told Congress “the decision to pay a ransom was mine,” describing it as one of the hardest decisions of his career, made in an effort to protect patient data and speed recovery.

Critics raised several concerns that are relevant to any organization thinking through its own ransomware response planning:

  • No guarantee of deletion. Law enforcement agencies, including the FBI, have consistently cautioned that paying a ransom does not guarantee stolen data will be deleted or that decryption will fully succeed — a caution borne out here given the affiliate’s claim that data remained in its possession after payment.
  • Funding future attacks. Ransom payments, in aggregate, help finance the ransomware-as-a-service economy, potentially funding tooling and operations used against future victims.
  • Incentive effects. Some policy analysts argue that large, publicized payments by well-resourced organizations signal to ransomware operators that critical-infrastructure targets are lucrative, potentially inviting more attacks on similar organizations.

At the same time, defenders of the decision point out that Witty was weighing an active, ongoing national disruption to patient care against an uncertain outcome from refusing to pay — a genuinely difficult tradeoff without a clean answer, and one that boards and executives across other sectors have faced in their own incidents.

Resilience and third-party risk lessons

Whatever conclusions eventually emerge from the various congressional, regulatory, and legal reviews, several practical lessons were already being widely discussed across the health IT and security community by mid-2024:

Multi-factor authentication is not optional on remote access. The reported absence of MFA on the compromised Citrix portal became a focal point of the congressional hearings specifically because it is one of the most basic, well-established controls in enterprise security. CISA and other federal guidance have for years listed MFA on remote-access services as a baseline expectation, not an advanced practice.

Map your critical vendor dependencies before an incident, not during one. Many affected hospitals and practices reportedly did not have a clear, tested picture of how much of their claims and payment workflow ran through Change Healthcare specifically, as opposed to a diversified set of clearinghouses. Third-party risk management in healthcare has traditionally focused heavily on data-sharing agreements and HIPAA business associate contracts; this incident argues for extending that mapping to operational and financial dependency, not just data flows.

Build manual and alternate-vendor fallback processes. Organizations that were able to shift claims submission to alternate clearinghouses, or that had manual eligibility-verification workarounds ready, generally recovered faster than those with no fallback. Business continuity planning for healthcare providers increasingly needs to assume that a core administrative vendor — not just an EHR or clinical system — can become unavailable for weeks.

Cash reserves and payer relationships matter during vendor outages. The AHA’s advocacy for advance payments and flexible timelines reflected a real vulnerability: many providers operate with limited days of cash on hand, and a multi-week interruption to claims and reimbursement can create solvency pressure even when the provider itself was never breached.

Incident response plans should anticipate multi-week, not multi-day, outages. Several organizations’ continuity plans reportedly assumed shorter outage windows than what actually occurred. Given the complexity of rebuilding trust in an environment after a ransomware deployment — validating that systems are clean before reconnecting them — recovery timelines for infrastructure at this scale can extend well beyond initial estimates.

None of the above should be read as a compliance checklist or a certification that any particular organization’s HIPAA Security Rule program is adequate; it reflects lessons publicly discussed in the aftermath of this specific incident, not formal regulatory guidance in itself. Organizations evaluating their own HIPAA Security Rule compliance and incident-response readiness should consult their compliance and legal counsel and refer directly to HHS and CISA resources.

A watershed moment, still unfolding

As of mid-2024, the Change Healthcare cyberattack stood as, by many accounts, the most disruptive cybersecurity incident the U.S. healthcare sector had experienced. The financial toll, the number of affected individuals, and the regulatory and legal fallout were all still being tallied months after systems were restored, and the final scope of the breach-notification process was expected to keep evolving as Change Healthcare and UHG completed their review of exposed data.

What was already clear by mid-2024 is that the incident reframed how healthcare organizations, regulators, and lawmakers think about cyber risk in the sector: not solely as a question of whether an individual hospital’s own systems are secure, but whether the small number of vendors that the entire system depends on are secure, transparent about incidents, and resilient enough that their failure doesn’t become everyone’s failure at once.

Frequently Asked Questions

What company was behind the Change Healthcare cyberattack?

Responsibility was claimed by ALPHV, also known as BlackCat, a ransomware-as-a-service group. According to congressional testimony from UnitedHealth Group’s CEO, attackers used compromised credentials to access a Citrix remote-access portal that reportedly lacked multi-factor authentication, beginning February 12, 2024.

When did the Change Healthcare ransomware attack happen?

Attackers gained initial access on February 12, 2024, and deployed ransomware on February 21, 2024. UnitedHealth Group publicly disclosed the cyberattack on February 22–23, 2024, and restoration of core claims and payment functions occurred in stages over the following weeks.

Did UnitedHealth Group pay the ransom?

UHG CEO Andrew Witty told Congress in May 2024 that the company paid a ransom, widely reported at roughly $22 million in bitcoin, calling it his own decision and one of the hardest he has had to make. An affiliate of the ransomware group later claimed the operators kept the payment without deleting stolen data.

Why did the Change Healthcare cyberattack affect so many unrelated organizations?

Change Healthcare operates as a major clearinghouse for medical claims, eligibility checks, and pharmacy transactions across the U.S. healthcare system. Because so many hospitals, pharmacies, and practices routed transactions through its infrastructure, one company’s outage disrupted payment and prescription processes nationwide — a textbook case of vendor concentration risk.