Skip to content
Longterm Wiki

Change Healthcare (2024)

On February 21, 2024, Change Healthcare — a UnitedHealth subsidiary processing roughly one-third of US healthcare payment claims — was attacked by BlackCat/ALPHV ransomware. The shutdown crippled pharmacy fulfillment, claims processing, and revenue cycle management nationwide for weeks. UnitedHealth disclosed the breach affected approximately 190M Americans, making it the largest US healthcare breach on record. UnitedHealth has reported $2.87B in direct costs as of FY2024 reports; sector-wide downstream costs (pharmacy cash-flow disruption, hospital revenue gaps, delayed care) are not consolidated. The incident demonstrates the systemic-risk profile of healthcare clearinghouses.

Details

Date

February 21, 2024

Attribution

BlackCat / ALPHV ransomware (with Notchy / RansomHub follow-on extortion)

AI involvement

none documented

Initial vector

Compromised Citrix portal credential without MFA

Ransom paid

$22M to BlackCat (early 2024); additional ransom alleged paid to follow-on group

People affected

~190 million Americans (largest US healthcare breach on record)

Estimated total damages

~$2.87B UnitedHealth direct costs; sector-wide cascade much larger (medium confidence)

Related Wiki Pages

Top Related Pages

Historical

CDK Global (2024)NotPetya (2017)

Policy

Indiana AI Healthcare Disclosure

Tags

cyber-incidentransomwarehealthcareclearinghouseblackcat-alphvcritical-infrastructure