Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Change Healthcare

Change Healthcare Vendor Cyber Rating & Cyber Score

changehealthcare.com

Change Healthcare is now a part of Optum. To stay up-to-date with news please connect with us at Optum.com. At both Optum and Change Healthcare, our teams strive to help people live healthier lives and help the health system work better for everyone.


Change Healthcare A.I CyberSecurity Scoring

Change Healthcare
Company Information
Website:http://www.changehealthcare.com
Employees number:4,617
Number of followers:147,311
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:changehealthcare.com
Change Healthcare Risk Score (AI oriented)
Between 0 and 549
logo
Change HealthcareIT Services and IT Consulting
Updated:
20/07/2026
100/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Change Healthcare Global Score (TPRM)
xxxx
logo
Change HealthcareIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Change Healthcare
Change HealthcareCritical
Current Score
100C (CRITICAL)
01000
27 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
100Before Incident
JUNE 2026
100Before Incident
MAY 2026
100Before Incident
Ransomware
07 May 2026Change Healthcare
UnitedHealth Group and Change Healthcare: MSN

Ransomware Attack on Change Healthcare Disrupts U.S. Healthcare System

100After Incident
CRITICAL0
UNICHA1778149488
Cyberattack Disrupts Major U.S. Healthcare Provider, Exposing Patient Data A ransomware attack on Change Healthcare, a key subsidiary of UnitedHealth Group (UHG), has caused widespread disruptions across the U.S. healthcare system, delaying payments, prescriptions, and critical medical services. The incident, first detected on February 21, 2024, forced the company to take its systems offline, severing connections with pharmacies, hospitals, and insurers nationwide. The attack has been attributed to the BlackCat (ALPHV) ransomware group, which claimed responsibility and allegedly stole 6 terabytes of sensitive data, including patient records, insurance details, and billing information. While UHG has not confirmed whether a ransom was paid, reports suggest the group received a $22 million payment one of the largest known ransomware payouts to date. The fallout has been severe: pharmacies reported delays in processing prescriptions, healthcare providers faced interruptions in claims processing, and some patients experienced denied or delayed care due to system outages. The U.S. Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA) are investigating the breach, which has raised concerns about the vulnerability of healthcare infrastructure to cyber threats. Change Healthcare processes 15 billion healthcare transactions annually, making this one of the most significant cyber incidents to hit the U.S. medical sector. Recovery efforts are ongoing, but the full extent of the data exposure and long-term operational impact remains unclear. The attack underscores the growing risk of ransomware targeting critical healthcare systems, where disruptions can directly endanger patient safety.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: 6 terabytes of sensitive dataSystems Affected: Pharmacy processing, claims processing, medical servicesOperational Impact: Delays in prescriptions, claims processing, and patient care; system outagesBrand Reputation Impact: SevereIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Patient recordsInsurance detailsBilling informationSensitivity Of Data: HighData Exfiltration: YesData Encryption: Yes (ransomware encryption)Personally Identifiable Information: Yes
APRIL 2026
100Before Incident
Ransomware
14 Apr 2026Change Healthcare
UnitedHealth Group and Change Healthcare: WUSA9

Cyberattack Disrupts Major U.S. Healthcare Network, Exposing Patient Data

100After Incident
CRITICAL0
CHAUNI1776205836
Cyberattack Disrupts Major U.S. Healthcare Network, Exposing Patient Data A ransomware attack on Change Healthcare, a key subsidiary of UnitedHealth Group (UHG), has caused widespread disruption across the U.S. healthcare system, impacting pharmacies, hospitals, and patients nationwide. The incident, first detected on February 21, 2024, forced the company to take its systems offline, halting critical services such as prescription processing, insurance claims, and payment systems. The attack has been attributed to the BlackCat/ALPHV ransomware group, which claimed responsibility and later allegedly received a $22 million ransom payment one of the largest known in healthcare. Despite the payment, the group reportedly withheld decryption keys, leaving Change Healthcare to rebuild affected systems independently. The breach exposed sensitive patient data, including medical records, billing information, and personal identifiers, though the full extent of the compromise remains under investigation. The fallout has been severe: pharmacies faced delays in filling prescriptions, healthcare providers struggled with billing disruptions, and patients encountered difficulties accessing medications. The American Hospital Association (AHA) warned of "catastrophic" financial strain on hospitals, some of which reported cash-flow crises due to unprocessed claims. The U.S. Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA) are coordinating with law enforcement to assess the breach’s scope and mitigate further risks. Change Healthcare has since restored many services, but the incident underscores the growing threat of ransomware to critical infrastructure, particularly in healthcare, where operational disruptions can have life-threatening consequences. The attack also raises concerns about the BlackCat group’s tactics, including double-extortion schemes and targeting high-value victims for maximum leverage. Investigations into the breach’s origins and potential regulatory penalties are ongoing.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: Sensitive patient data, including medical records, billing information, and personal identifiersSystems Affected: Prescription processing, insurance claims, payment systemsOperational Impact: Widespread disruption across U.S. healthcare system; pharmacies faced delays in filling prescriptions; healthcare providers struggled with billing disruptions; patients encountered difficulties accessing medicationsBrand Reputation Impact: SevereIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Medical recordsBilling informationPersonal identifiersSensitivity Of Data: HighData Encryption: YesPersonally Identifiable Information: Yes
Ransomware
14 Apr 2026Change Healthcare
UnitedHealth Group and Change Healthcare: KARE 11

Ransomware Attack on Change Healthcare Disrupts U.S. Healthcare Network

100After Incident
CRITICAL0
UNICHA1776140687
Cyberattack Disrupts Major U.S. Healthcare Network, Exposing Patient Data A ransomware attack on Change Healthcare, a key subsidiary of UnitedHealth Group (UHG), has caused widespread disruptions across the U.S. healthcare system, impacting pharmacies, hospitals, and patients nationwide. The incident, first detected on February 21, 2024, forced the company to take its systems offline, halting critical services such as prescription processing, insurance claims, and payment systems. The attack has been attributed to the BlackCat/ALPHV ransomware group, which reportedly exploited vulnerabilities in Change Healthcare’s IT infrastructure. While UHG has not confirmed whether a ransom was paid, the group claimed responsibility and later removed its dark web post, a tactic often associated with negotiations or payment. The breach exposed sensitive patient data, though the full extent of the compromise remains under investigation. The fallout has been severe, with pharmacies reporting delays in filling prescriptions, healthcare providers struggling to process claims, and patients facing difficulties accessing medications. Some hospitals have resorted to manual workarounds, while others have temporarily diverted services to alternative systems. The American Hospital Association (AHA) has urged federal agencies to provide emergency funding and support to mitigate the crisis. As of March 2024, Change Healthcare has begun restoring services, but full recovery is expected to take weeks. The incident underscores the growing threat of ransomware to critical infrastructure, particularly in the healthcare sector, where operational disruptions can have life-threatening consequences. Regulatory bodies, including the HHS Office for Civil Rights (OCR), are monitoring the situation for potential HIPAA violations.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Data Compromised: Sensitive patient dataPrescription processingInsurance claimsPayment systemsDowntime: Weeks (ongoing as of March 2024)Operational Impact: Widespread disruptions in pharmacies, hospitals, and patient services; manual workarounds required; service diversions
DATA BREACH
Type Of Data Compromised: Patient dataSensitivity Of Data: High (sensitive patient data)Personally Identifiable Information: Likely (patient data)
APRIL 2026
100Before Incident
Ransomware
09 Apr 2026Change Healthcare
Change Healthcare: MSN

Cyberattack Disrupts Major U.S. Healthcare Network, Exposing Patient Data

100After Incident
CRITICAL0
CHA1775773596
Cyberattack Disrupts Major U.S. Healthcare Network, Exposing Patient Data A significant cyberattack targeted Change Healthcare, a key subsidiary of UnitedHealth Group, in late February 2024, causing widespread disruptions across the U.S. healthcare system. The attack, attributed to the BlackCat/ALPHV ransomware group, encrypted critical systems, halting claims processing, prescription fulfillment, and payment operations for pharmacies, hospitals, and clinics nationwide. The incident forced healthcare providers to revert to manual processes, delaying patient care and financial transactions. While UnitedHealth Group confirmed the attack on February 21, the full extent of the breach remains under investigation. Early reports suggest sensitive patient data, including medical records and personal information, may have been exfiltrated, raising concerns about potential identity theft and fraud. Change Healthcare, which processes nearly 15 billion healthcare transactions annually, plays a central role in the U.S. medical billing ecosystem. The attack underscores vulnerabilities in third-party healthcare IT infrastructure and the growing threat of ransomware targeting critical services. As of early March, recovery efforts were ongoing, with UnitedHealth Group working to restore systems and mitigate further risks. The incident has prompted discussions among policymakers and cybersecurity experts about strengthening defenses in the healthcare sector.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Data Compromised: Sensitive patient data, including medical records and personal informationSystems Affected: Claims processing, prescription fulfillment, payment operationsOperational Impact: Widespread disruptions, manual processes required, delayed patient care and financial transactionsIdentity Theft Risk: Potential identity theft and fraud
DATA BREACH
Type Of Data Compromised: Medical records, personal informationSensitivity Of Data: HighData Exfiltration: PossibleData Encryption: Yes (ransomware encryption)Personally Identifiable Information: Yes
MARCH 2026
100Before Incident
FEBRUARY 2026
100Before Incident
Ransomware
03 Feb 2026Change Healthcare
UnitedHealth Group and Change Healthcare: NEWS CENTER Maine

Cyberattack Disrupts Major U.S. Healthcare Network, Exposing Patient Data

100After Incident
CRITICAL0
CHAUNI1770195897
Cyberattack Disrupts Major U.S. Healthcare Network, Exposing Patient Data A ransomware attack on Change Healthcare, a key subsidiary of UnitedHealth Group (UHG), has caused widespread disruptions across the U.S. healthcare system, impacting pharmacies, hospitals, and insurance providers. The incident, first detected on February 21, 2024, forced the company to take its systems offline, halting critical services such as prescription processing, claims submissions, and payment transactions. The attack has been attributed to the BlackCat/ALPHV ransomware group, which claimed responsibility and later listed the stolen data on its dark web leak site. While UHG has not confirmed whether a ransom was paid, reports suggest the hackers may have received a $22 million payment one of the largest known ransomware payouts to date. The breach exposed sensitive patient information, including medical records, billing details, and personal identifiers, though the full extent of the data compromise remains under investigation. The outage has had cascading effects, with pharmacies reporting delays in filling prescriptions, healthcare providers struggling to verify insurance coverage, and patients facing challenges accessing medications. Some hospitals have resorted to manual workarounds, while others have temporarily diverted patients to alternative facilities. The American Hospital Association (AHA) and the U.S. Department of Health and Human Services (HHS) have issued alerts, urging organizations to monitor for potential fraud and reinforce cybersecurity measures. Change Healthcare has since begun restoring services, with partial functionality returning in early March, but full recovery is expected to take weeks. The incident underscores the growing threat of ransomware to critical infrastructure, particularly in the healthcare sector, where operational disruptions can directly endanger patient care. Regulatory scrutiny is likely to follow, as lawmakers and industry groups assess the attack’s implications for data security and resilience in the healthcare ecosystem.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: Sensitive patient information, including medical records, billing details, and personal identifiersSystems Affected: Prescription processing, claims submissions, payment transactionsDowntime: Weeks (partial recovery in early March 2024)Operational Impact: Widespread disruptions across pharmacies, hospitals, and insurance providers; manual workarounds and patient diversionsBrand Reputation Impact: SignificantLegal Liabilities: LikelyIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Medical recordsBilling detailsPersonal identifiersSensitivity Of Data: HighData Exfiltration: Yes (listed on dark web leak site)Data Encryption: Yes (ransomware encryption)Personally Identifiable Information: Yes
JANUARY 2026
100Before Incident
Ransomware
01 Jan 2026Change Healthcare
Change Healthcare and Federal Reserve: Claimed Twice: Five Reasons the Same Ransomware Victim Shows Up Under Two Flags

Ransomware’s Double Trouble: Duplicate Victim Claims in 2026

100After Incident
CRITICAL0
CHAFED1781757064
Ransomware’s Double Trouble: Why Victims Are Being Claimed Twice in 2026 In 2026, a troubling trend has emerged in the ransomware landscape: the same victim organizations are appearing on leak sites under two different ransomware group names. Bitdefender’s analysis of five months of data tracking 98 claims across 49 distinct victims reveals that this phenomenon is not a fluke but a systemic issue with multiple underlying causes. ### The Mechanics Behind Duplicate Claims The median gap between the first and second claim is 12 days, with a mean of 23 days and some cases stretching up to 96 days. Only five cases were posted simultaneously, suggesting that most duplicates stem from staggered rather than coordinated attacks. The patterns vary, but four primary explanations account for the trend: 1. One Attack, Two Brands Some groups operate under multiple names within the same criminal network. For example, the DragonForce cartel absorbed affiliates from defunct operations like RansomHub, leading to the same victim appearing under both Qilin and DragonForce. Similarly, Hunters International rebranded as World Leaks, yet victims were listed under both names. In these cases, the breach is singular, but the leak site postings double-count the incident. 2. Recycled Data, Second Extortion When affiliates don’t receive their cut of a ransom payment, they may relist the stolen data under a new group. The Change Healthcare breach, initially claimed by ALPHV/BlackCat, later resurfaced under RansomHub after an affiliate dispute. This creates two distinct extortion attempts from the same dataset, with the second group operating independently of the first. 3. Two Real Breaches, Same Victim Some organizations are breached twice sometimes through the same vulnerability, other times through a different but equally unpatched weakness. In 16 of the 49 cases analyzed, the gap between claims exceeded 31 days, suggesting separate intrusions. Often, the root cause isn’t a single missed patch but systemic security failures: unchanged credentials, unenforced multi-factor authentication, or undetected network access. Access brokers exacerbate this by reselling stolen credentials to multiple threat actors. 4. No Breach at All Some claims are outright fabrications. Groups like 0APT and Dispossessor have been caught reposting victim lists from other leak sites or inventing attacks entirely. After Operation Cronos disrupted LockBit, the group falsely claimed the Federal Reserve as a victim, later revealed to be data from Evolve Bank. These fake claims waste resources, as organizations may respond to a non-existent breach. ### The Impact on Statistics and Response The prevalence of duplicate and fabricated claims distorts ransomware statistics. For instance, Q1 2026’s raw leak site data showed a 15% increase in victims year-over-year. However, removing 0APT’s 549 fake claims reversed the trend, revealing a 6% decline. This noise complicates threat assessments and incident response. For victims, distinguishing between these scenarios is critical: - Same breach, two groups? Treat it as one negotiation. - Recycled data? Paying the second group doesn’t silence the first. - Two real breaches? The issue isn’t just the breach it’s the security posture that allowed it. - No breach at all? Verification is key before taking action. The rise of duplicate claims underscores the need for defenders to look beyond surface-level leak site postings. Context timing, group relationships, and data authenticity determines the appropriate response. Without it, organizations risk misallocating resources, overpaying ransoms, or failing to address the real vulnerabilities that led to repeat victimization.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainExtortionData resaleAffiliate disputes
DATA BREACH
Stolen credentialsSensitive dataPersonally identifiable informationSensitivity Of Data: High
DECEMBER 2025
100Before Incident
NOVEMBER 2025
100Before Incident
OCTOBER 2025
100Before Incident
SEPTEMBER 2025
100Before Incident
AUGUST 2025
100Before Incident
JUNE 2025
100Before Incident
Ransomware
16 Jun 2025Change Healthcare
Change Healthcare

Midyear 2025 Cyber Risk Landscape Analysis: Ransomware, Vendor Disruptions, and AI-Powered Attacks

100After Incident
CRITICAL0
CHA2962029091225
Change Healthcare, a critical vendor in the U.S. healthcare system, suffered a devastating ransomware attack in early 2025, disrupting operations across pharmacies, hospitals, and insurance providers nationwide. The attack, attributed to ALPHV/BlackCat, encrypted systems and exfiltrated sensitive patient data, including medical records, billing information, and personally identifiable information (PII). The outage lasted weeks, crippling prescription processing, claims submissions, and revenue cycles for thousands of healthcare providers. While Change Healthcare reportedly paid a $22 million ransom to restore operations, the financial fallout extended far beyond the payment—providers faced cash flow crises, delayed patient care, and long-term reputational damage. The incident also triggered regulatory scrutiny and class-action lawsuits, with estimates suggesting total losses (including indirect costs) could exceed $1 billion. The attack exposed vulnerabilities in third-party supply chains, demonstrating how a single breach in a vendor can paralyze an entire sector.
INCIDENT DETAILS -
TYPE
RansomwareVendor/Third-Party DisruptionAI-Powered Social EngineeringBusiness Interruption
MOTIVATION
Financial gain (ransomware, extortion)Data theft for resale/exploitationDisruption of operations (supply chain impact)
IMPACT
Average Ransomware Claim: $1.18M (H1 2025, +17% YoY)Vendor Related Losses: 15% of total claims (H1 2025, down from 22% in 2024)Social Engineering Losses: 60% of total losses (H1 2025)Overall Claims Reduction: 53% drop in ransomware claims (H1 2025 vs. H1 2024)Industry-wide disruptions (e.g., CDK Global, Change Healthcare)Supply chain ripple effectsIT helpdesk compromises via social engineeringErosion of trust in vendor securityPerceived vulnerability to AI-powered attacks
DATA BREACH
Data Exfiltration: Reported in double extortion ransomware casesData Encryption: Ransomware encryption (systems locked)
MARCH 2025
100Before Incident
Ransomware
01 Mar 2025Change Healthcare
Change Healthcare

Massive Cyberattack on Change Healthcare

100After Incident
CRITICAL0
CHA123030725
Change Healthcare, a subsidiary of UnitedHealth, faced a massive cyberattack which disrupted billions of medical claims processing and cost the company $3.1 billion. Dubbed the most significant attack in U.S. healthcare history, it led to extensive disruptions in the healthcare sector. The attack's magnitude and repercussions across interconnected systems underscore its potential to ripple through and impact an entire industry.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
Financial Loss: $3.1 billionSystems Affected: Medical claims processing systemsOperational Impact: Extensive disruptions in the healthcare sector
FEBRUARY 2025
100Before Incident
Ransomware
01 Feb 2025Change Healthcare
Change Healthcare

Change Healthcare Ransomware Attack

100After Incident
CRITICAL0
CHA003032225
Change Healthcare experienced a ransomware attack in February that resulted in significant cash flow disruptions for Medicare providers and suppliers, including hospitals, pharmacies, and physicians. The Centers for Medicare and Medicaid Services (CMS) responded by launching the Change Healthcare/Optum Payment Disruption (CHOPD) program to provide accelerated and advance payments to affected parties. More than $3.26 billion was disbursed to ensure continued patient care. CMS has recovered the majority of these payments as providers resumed normal Medicare billing. This incident highlights the potential financial and operational impacts of ransomware on the healthcare sector.
INCIDENT DETAILS -
TYPE
Ransomware Attack
MOTIVATION
Financial Disruption
IMPACT
Operational Impact: Cash Flow Disruptions
NOVEMBER 2024
100Before Incident
Breach
01 Nov 2024Change Healthcare
TriZetto, OCHIN and Change Healthcare: TriZetto confirms data breach affecting 3.4 million patients tied to 2024 cyberattack

TriZetto Confirms 2024 Cyberattack Exposing 3.4 Million Patients’ Data

100After Incident
CRITICAL0
TRICHAOCH1772815208
TriZetto Confirms 2024 Cyberattack Exposing 3.4 Million Patients’ Data TriZetto, a major U.S. health technology provider under Cognizant, disclosed a 2024 cyberattack that compromised the personal and medical data of over 3.4 million individuals. The breach, detected on October 2, 2025, went unnoticed for nearly a year, with unauthorized access dating back to November 2024. The stolen data included sensitive information such as names, dates of birth, home addresses, Social Security numbers, health status details, provider names, and insurance records. TriZetto, which processes insurance eligibility for roughly 200 million patients through 875,000 healthcare providers, confirmed that patient eligibility reports were extracted from its servers. Multiple organizations, including OCHIN a nonprofit serving 300 U.S. providers and several California-based medical providers, verified that their patients’ data was exposed. However, TriZetto stated that not all clients were affected. The incident follows a 2024 ransomware attack on Change Healthcare, which resulted in the theft of 192 million patient files and caused widespread disruptions in medical services nationwide. TriZetto has not provided details on why the breach remained undetected for nearly a year, and Cognizant has not responded to requests for comment.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Personal and medical data of over 3.4 million individualsSystems Affected: TriZetto serversIdentity Theft Risk: High
DATA BREACH
NamesDates of birthHome addressesSocial Security numbersHealth status detailsProvider namesInsurance recordsNumber Of Records Exposed: 3.4 millionSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
SEPTEMBER 2024
100Before Incident
Ransomware
10 Sep 2024Change Healthcare
Change Healthcare

Ransomware Attack on Change Healthcare

100After Incident
CRITICAL0
CHA001032225
Change Healthcare, a subsidiary of Optum Inc and part of UnitedHealth Group, faced a substantial ransomware attack that disabled many of its electronic systems. This disruption halted the ability of thousands of healthcare providers to submit claims and receive payments, causing an estimated $100 million in daily deferred patient care revenue over a period exceeding three weeks. The attack affected various operations, including insurance verification, prior authorization processes, clinical information exchange, and e-prescription services. The aftermath of the attack persisted, with reported continuing challenges and disruptions despite a hefty ransom payment allegedly made.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial
IMPACT
Financial Loss: $100 million in daily deferred patient care revenueelectronic systemsinsurance verificationprior authorization processesclinical information exchangee-prescription servicesDowntime: over three weeksOperational Impact: halted the ability of thousands of healthcare providers to submit claims and receive paymentsRevenue Loss: $100 million in daily deferred patient care revenue
JULY 2024
100Before Incident
Ransomware
29 Jul 2024Change Healthcare
Change Healthcare

Change Healthcare Cyberattack

100After Incident
CRITICAL0
CHA002032225
Change Healthcare experienced a cyberattack leading to widespread disruption of medical billing and pre-authorization services, affecting hundreds of health systems across the United States. The incident resulted in delays in medical procedures, restricted access to prescription medications, financial strains on health systems, and some reportedly facing receivership. The consolidation in healthcare has resulted in fewer alternatives for such services, emphasizing the failures and risks associated with creating single points of failure within critical healthcare infrastructure.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
Delays in medical proceduresRestricted access to prescription medicationsFinancial strains on health systemsSome health systems facing receivershipMedical billing servicesPre-authorization servicesOperational Impact: Widespread disruption of medical billing and pre-authorization services
JUNE 2024
100Before Incident
Ransomware
16 Jun 2024Change Healthcare
Change Healthcare

Active Directory Compromise and Ransomware Attack on Change Healthcare (2024)

100After Incident
CRITICAL0
CHA1032510111225
In the 2024 Change Healthcare breach, attackers exploited a server lacking multifactor authentication (MFA) to infiltrate the company’s Active Directory (AD), the central authentication backbone for over 90% of Fortune 1000 firms. Once inside, they escalated privileges, executed lateral movement, and deployed a ransomware attack that crippled operations. The incident forced a complete halt to patient care services, exposed sensitive health records, and resulted in the company paying millions in ransom to restore systems. The attack disrupted billing, claims processing, and pharmacy operations nationwide, causing prolonged financial and reputational damage. The breach highlighted critical vulnerabilities in AD security, including weak credential management, unpatched systems, and excessive privileged access, which allowed attackers to maintain persistence and evade detection by mimicking legitimate AD operations. Recovery efforts took weeks, with lingering impacts on healthcare providers and patients reliant on Change Healthcare’s infrastructure.
INCIDENT DETAILS -
TYPE
Data BreachRansomwarePrivilege EscalationLateral Movement
MOTIVATION
Financial Gain (Ransom Payment)Data Theft (Health Records)Disruption (Patient Care Halt)
IMPACT
Financial Loss: Millions (Ransom Paid + Operational Costs)Health RecordsPatient DataActive DirectoryDomain ControllersHybrid Cloud Infrastructure (Azure AD)Patient Care SystemsDowntime: Extended (Patient Care Disruption)Operational Impact: Severe (Halt in Patient Services, Administrative Paralysis)Customer Complaints: High (Patients and Healthcare Providers)Brand Reputation Impact: Significant (Loss of Trust in Healthcare Data Security)Identity Theft Risk: High (Exposed Health Records)
DATA BREACH
Health RecordsPatient DataPotentially Administrative CredentialsSensitivity Of Data: High (Protected Health Information - PHI)Data Exfiltration: Confirmed (Health Records)Data Encryption: Likely (Ransomware Encryption)Personally Identifiable Information: Yes (Patient Identities)
MAY 2024
100Before Incident
Ransomware
20 May 2024Change Healthcare
Change Healthcare

Ransomware Attack on Change Healthcare

100After Incident
CRITICAL0
CHA002032325
The ransomware attack on Change Healthcare reported on February 21st has caused substantial disruption across the healthcare sector, with the breach costs estimated by UnitedHealth, Change's parent company, to potentially reach $1.6 billion. The breach has drastically affected providers relying on Change Healthcare's services, leading to financial distress, with a clear recovery path not yet in sight. The repercussions of the breach have been amplified by the lack of definitive information and guidance on reporting responsibilities, causing unease among affected healthcare providers.
INCIDENT DETAILS -
TYPE
Ransomware Attack
IMPACT
Financial Loss: $1.6 billionOperational Impact: Substantial disruption across the healthcare sector
APRIL 2024
100Before Incident
Ransomware
01 Apr 2024Change Healthcare
UnitedHealth Group, Optum, Inc., and Change Healthcare

Ransomware Attack on Change Healthcare

100After Incident
CRITICAL0
CHA004101724
Following a ransomware attack on February 21, the extent of the impact on Change Healthcare, providers, and patients is being evaluated. Class action lawsuits filed against UnitedHealth Group, Optum, Inc., and Change Healthcare are converging in Nashville's federal court, as proposed by Change Healthcare to streamline proceedings. Healthcare providers faced difficulties in checking insurance eligibility and processing prior authorization requests, disrupting patient care. Restoration efforts for Change Healthcare's products and services were still ongoing as of March 31.
INCIDENT DETAILS -
TYPE
Ransomware Attack
IMPACT
Insurance eligibility checksPrior authorization requestsDisruption in patient careClass action lawsuits
MARCH 2024
100Before Incident
Cyber Attack
01 Mar 2024Change Healthcare
Change Healthcare

Change Healthcare Cyberattack

100After Incident
CRITICAL0
CHA1012070724
The Change Healthcare cyberattack has led to a significant disruption in the claims processing system affecting over 1,850 hospitals and 250,000 physicians. The direct impact has been a staggering $6.3 billion cash flow deficit since the breach, as reported through March 9. The inability to process claims digitally has caused a decline in cash and potential long-term consequences such as medical necessity denials and prior authorization denials due to delayed claims. Healthcare providers are struggling to cope with the manpower required for paper claims and the unsustainable financial pressure during the interim of restoring the compromised system. The lack of adequate action from payers exacerbates the situation, making it critical to reassess cybersecurity measures in the healthcare industry.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
Financial Loss: $6.3 billionSystems Affected: Claims processing systemInability to process claims digitallyDecline in cashMedical necessity denialsPrior authorization denialsDelayed claims
Ransomware
01 Mar 2024Change Healthcare
UnitedHealth Group

UnitedHealth Group Ransomware Attack

100After Incident
CRITICAL0
UNI1012070724
UnitedHealth Group experienced a ransomware attack on February 21, which disrupted their services including medical claim handling and revenue cycle services. This resulted in severe delays in processing claims, pushing healthcare providers towards financial distress, with some nearly facing bankruptcy. The attack by the group BlackCat forced UnitedHealth to rebuild services and affected providers have started filing lawsuits due to not maintaining adequate cybersecurity measures, with allegations of sensitive information leaks. UnitedHealth has paid over $2 billion to affected providers and the data compromised in the attack remains undisclosed.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial Gain
IMPACT
Financial Loss: $2 billionMedical claim handlingRevenue cycle servicesDowntime: Severe delays in processing claimsOperational Impact: Rebuild servicesLegal Liabilities: Lawsuits filed by affected providers
FEBRUARY 2024
100Before Incident
Cyber Attack
21 Feb 2024Change Healthcare
UnitedHealth Group and Change Healthcare: WNEP

Ransomware Attack on Change Healthcare Disrupts U.S. Healthcare Network

100After Incident
CRITICAL0
UNICHA1768835481
Cyberattack Disrupts Major U.S. Healthcare Network, Exposing Patient Data A ransomware attack targeted Change Healthcare, a key subsidiary of UnitedHealth Group (UHG), on February 21, 2024, crippling critical payment and claims processing systems across the U.S. healthcare sector. The incident, attributed to the BlackCat/ALPHV ransomware group, forced widespread disruptions in pharmacies, hospitals, and clinics, delaying prescriptions, billing, and insurance reimbursements. The attack exploited vulnerabilities in Change Healthcare’s IT infrastructure, encrypting systems and exfiltrating sensitive data, including patient records and financial information. While UHG has not confirmed the full extent of the breach, reports suggest millions of individuals may be affected, with some data already surfacing on dark web forums. In response, UHG isolated affected systems, engaged cybersecurity firms, and worked with law enforcement, including the FBI and CISA. The outage lasted over a week, with partial restoration beginning in early March, though lingering disruptions continued to strain healthcare providers. The incident underscores the growing threat of ransomware to critical infrastructure, particularly in sectors reliant on interconnected digital systems. The fallout has prompted scrutiny of healthcare cybersecurity practices, with industry experts warning of potential long-term financial and operational consequences for providers already grappling with the attack’s aftermath.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Data Compromised: Patient records and financial informationSystems Affected: Payment and claims processing systemsDowntime: Over a weekOperational Impact: Delayed prescriptions, billing, and insurance reimbursementsIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Patient recordsFinancial informationNumber Of Records Exposed: MillionsSensitivity Of Data: HighData Exfiltration: YesData Encryption: YesPersonally Identifiable Information: Yes
Ransomware
21 Feb 2024Change Healthcare
UnitedHealth Group and Change Healthcare: JavaScript is disabled

Cyberattack Disrupts Major U.S. Healthcare Network, Exposing Patient Data

100After Incident
CRITICAL0
UNICHA1769160792
Cyberattack Disrupts Major U.S. Healthcare Network, Exposing Patient Data A ransomware attack on Change Healthcare, a critical payment and claims processing platform owned by UnitedHealth Group (UHG), has caused widespread disruptions across the U.S. healthcare system. The incident, first detected on February 21, 2024, forced the company to take its systems offline, halting prescription processing, insurance claims, and billing operations for pharmacies, hospitals, and clinics nationwide. The attack has been attributed to the BlackCat/ALPHV ransomware group, which claimed responsibility and allegedly exfiltrated 6 terabytes of sensitive data, including patient records, payment details, and personal information. While UHG has not confirmed whether a ransom was paid, reports suggest the group received a $22 million payment one of the largest known ransomware payouts to date. The fallout has been severe: pharmacies reported delays in filling prescriptions, healthcare providers faced cash flow shortages due to unprocessed claims, and some patients were forced to pay out-of-pocket for medications. The U.S. Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA) are investigating the breach, which has raised concerns about the vulnerability of third-party healthcare vendors. Change Healthcare has since restored some services, but full recovery remains ongoing. The incident underscores the growing threat of ransomware to critical infrastructure, particularly in sectors reliant on interconnected digital systems.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: 6 terabytes of sensitive dataSystems Affected: Payment and claims processing systems, prescription processing, insurance claims, billing operationsOperational Impact: Halted prescription processing, insurance claims, and billing operations; cash flow shortages for healthcare providers; patients forced to pay out-of-pocket for medicationsIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Patient records, payment details, personal informationSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
Cyber Attack
21 Feb 2024Change Healthcare
Pittsburgh Regional Transit, Oahu Transit Services, Kansas City Transportation Authority and Change Healthcare: How Cyberattacks on Essential Services Hit Women Harder

Cyberattacks on Critical Infrastructure Disproportionately Impact Women, Yet Policy Remains Gender-Blind

100After Incident
CRITICAL0
CHAOAHARKUNV1775594838
Cyberattacks on Critical Infrastructure Disproportionately Impact Women, Yet Policy Remains Gender-Blind Cyberattacks on essential services healthcare, education, and transportation are increasing in frequency and severity, with consequences that extend far beyond technical disruptions. While these incidents are often framed as neutral operational failures, their impacts are deeply gendered, disproportionately burdening women due to their structural roles in both the formal workforce and unpaid care labor. Despite this, U.S. cybersecurity policy continues to treat these effects as evenly distributed, undermining resilience and risk assessment. ### Healthcare: Frontline Workers Bear the Brunt Women make up 80% of the U.S. healthcare workforce, particularly in nursing and frontline care roles. When ransomware attacks such as the 2024 Change Healthcare breach, the largest in U.S. history disrupt digital systems, women absorb the immediate operational strain. Nurses must manually transcribe records, manage patient care without electronic alerts, and navigate heightened safety risks from delayed diagnostics. These disruptions also worsen maternal health outcomes, with outages increasing risks like delayed obstetric care and elevated maternal mortality, yet these consequences remain unmeasured in incident reports. Beyond clinical settings, cyber-induced healthcare failures shift caregiving responsibilities back to households, where women perform the majority of unpaid labor. The lack of gender-disaggregated data obscures these compounding burdens, leaving policymakers with an incomplete understanding of systemic harm. ### Education: Teachers and Caregivers Face Cascading Disruptions The education sector has become a prime target for ransomware, with over 80% of U.S. K-12 schools experiencing cyber incidents between mid-2023 and late 2024. Women comprise 77% of K-12 educators and nearly 90% of elementary school teachers, meaning they bear the brunt of operational fallout managing disrupted curricula, reconstructing lost data, and addressing student anxiety during outages. School closures further exacerbate gendered disparities, as women disproportionately absorb childcare responsibilities, leading to lost work time, reduced income, and increased stress. Despite these patterns, cybersecurity incident reports rarely document gendered workforce impacts or caregiving burdens, and the education sector remains undervalued in federal critical infrastructure definitions, reflecting a broader blind spot in resilience planning. ### Transportation: Mobility Disruptions Hit Women Hardest Cyberattacks on transit systems such as those affecting Pittsburgh Regional Transit, Kansas City Transportation Authority, and Oahu Transit Services disrupt payment systems and service availability. Women, who constitute the majority of public transit users, rely on these systems for caregiving, household management, and service-sector employment. Outages limit access to medical care, workplaces, and essential services, yet transportation cyber incident analyses rarely include gender-based assessments, leaving compounded burdens unaddressed. ### Interconnected Systems: The Invisible Labor of Recovery Critical infrastructure sectors are deeply interdependent, and disruptions in one area such as healthcare cascade into others, intensifying caregiving demands at home. When schools close, childcare responsibilities shift to families; when transit fails, access to essential services diminishes. Each of these burdens falls disproportionately on women, yet cybersecurity policy frameworks focus on technical interdependencies rather than social ones, failing to account for the gendered distribution of labor that underpins recovery. ### Why Gender-Blind Cybersecurity Undermines National Security The assumption that cyberattacks affect all demographics equally is not just inaccurate it weakens resilience. Women’s paid and unpaid labor acts as a buffer during crises, yet this labor remains invisible in incident reporting and unaccounted for in policy. Without gender-disaggregated data, risk assessments are incomplete, response efforts underestimate consequences, and recovery strategies fail to address the populations most affected. ### The Path Forward: Secure-by-Design and Gender-Intentional Policy Many cyber incidents stem from preventable software vulnerabilities, yet manufacturers face little accountability for insecure products. Addressing these root causes through secure-by-design standards, regulatory reforms, and liability frameworks would reduce harm, particularly for women, who disproportionately rely on public services. A gender-intentional cybersecurity framework would: 1. Center real users in threat modeling, accounting for how women engage with technology in work, caregiving, and transit. 2. Measure gender-disaggregated impacts to improve risk assessment and resilience planning. 3. Adopt human-centered security, designing policies that reflect actual user behavior rather than idealized assumptions. Efforts like Critical Cyber and the Foundation Layer initiative are mapping real-world consequences of cyberattacks, emphasizing that digital resilience depends on the stability of the communities interacting with these systems. Without integrating gender analysis, cybersecurity strategies will continue to fail in practice leaving the most vulnerable populations to bear the costs of systemic failure.
INCIDENT DETAILS -
TYPE
ransomwarecyberattack
IMPACT
healthcareeducationtransportationmanual transcription of records in healthcaredisrupted curricula in educationtransit payment system outages
Ransomware
21 Feb 2024Change Healthcare
UnitedHealth Group and Change Healthcare: U.S. Investors Accuse South Korea of Discrimination Over Coupang Data Leak

Ransomware Attack on Change Healthcare Disrupts U.S. Healthcare Network

100After Incident
CRITICAL0
UNICHA1769088935
Cyberattack Disrupts Major U.S. Healthcare Network, Exposing Patient Data A ransomware attack on Change Healthcare, a key subsidiary of UnitedHealth Group, has caused widespread disruption across the U.S. healthcare system, impacting pharmacies, hospitals, and insurance providers. The incident, first detected on February 21, 2024, forced the company to disconnect critical systems to contain the breach, leading to delays in prescription processing, billing, and claims submissions nationwide. The attack has been attributed to the BlackCat/ALPHV ransomware group, which claimed responsibility and allegedly exfiltrated 6 terabytes of sensitive data, including patient records, insurance details, and financial information. While UnitedHealth Group has not confirmed whether a ransom was paid, the group’s dark web leak site previously listed Change Healthcare as a victim before the listing was removed suggesting possible negotiations. The fallout has been severe, with some healthcare providers reporting cash flow disruptions due to halted payments, while patients faced difficulties accessing medications. The American Hospital Association (AHA) and U.S. Department of Health and Human Services (HHS) have issued alerts, urging providers to implement contingency plans. Investigations by cybersecurity firms and federal agencies, including the FBI and CISA, are ongoing to assess the full scope of the breach and its implications for healthcare cybersecurity. This incident underscores the growing threat of ransomware to critical infrastructure, particularly in sectors reliant on interconnected digital systems. The attack’s ripple effects continue to strain an already overburdened healthcare system, raising concerns about long-term vulnerabilities in patient data protection.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: 6 terabytes of sensitive data, including patient records, insurance details, and financial informationSystems Affected: Pharmacies, hospitals, insurance providers, prescription processing, billing, and claims submissions systemsOperational Impact: Delays in prescription processing, billing, and claims submissions; cash flow disruptions for healthcare providersBrand Reputation Impact: SevereIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Patient records, insurance details, financial informationSensitivity Of Data: HighData Exfiltration: YesData Encryption: Yes (ransomware encryption)Personally Identifiable Information: Yes
FEBRUARY 2024
532Before Incident
Ransomware
01 Feb 2024Change Healthcare
UnitedHealth Group (Change Healthcare)

Cyberattack on Indian Council of Medical Research (ICMR) Leads to Data Breach of 81.5 Crore Citizens

100After Incident
CRITICAL-432
UNI1362813111425
UnitedHealth Group’s subsidiary Change Healthcare suffered a massive cyberattack in February 2024, attributed to the Blackcat (ALPHV) ransomware group. The attack crippled critical systems, disrupting billing, claims processing, and prescription services across the U.S. healthcare sector. Hospitals, pharmacies, and providers faced payment processing outages, delaying patient care and financial transactions. The breach also exposed sensitive patient data, including medical records and personally identifiable information (PII), though the full scope of data theft remains under investigation. UnitedHealth was forced to isolate affected systems, leading to prolonged operational disruptions. The incident triggered federal investigations, with the U.S. Department of Health and Human Services (HHS) and the FBI involved. The financial and reputational damage was severe, with stock drops and lawsuits from affected parties. The attack underscored vulnerabilities in healthcare IT infrastructure, raising concerns about future ransomware threats to critical services.
INCIDENT DETAILS -
TYPE
data breachcyberattack
MOTIVATION
financial gaindata theft
IMPACT
Aadhaar detailspassport detailsnamesphone numbersaddressesmedical recordsBrand Reputation Impact: high (potential loss of public trust in ICMR's data security)Identity Theft Risk: high
DATA BREACH
personal identifiable information (PII)medical recordsgovernment-issued IDs (Aadhaar, passport)Number Of Records Exposed: 81.5 crore (815 million)Sensitivity Of Data: high (includes Aadhaar, passport, and medical data)
Ransomware
01 Feb 2024Change Healthcare
Change Healthcare (UnitedHealth Group)

Ransomware Attacks Overview (2011–2025)

100After Incident
CRITICAL-432
CHA455090325
In February 2024, Change Healthcare, a critical division of UnitedHealth Group, fell victim to a devastating BlackCat/ALPHV ransomware attack. The assault crippled its systems, disrupting prescription processing, medical claims, and payment operations across the U.S. healthcare sector. Over 100 million individuals were impacted due to service outages, with hospitals, pharmacies, and insurers facing delays in billing, reimbursements, and patient care. The company paid a $22 million ransom, but total financial losses ballooned to an estimated $2 billion, factoring in operational downtime, recovery costs, and reputational damage. The attack exposed vulnerabilities in third-party supply chains, as the breach originated from compromised credentials in a connected vendor system. Regulatory scrutiny intensified, with federal investigations probing compliance failures under HIPAA and cybersecurity negligence. The incident underscored the escalating threat of RaaS (Ransomware-as-a-Service) models, where affiliate hackers leverage sophisticated tools to target high-value sectors like healthcare, exploiting systemic interdependencies for maximum disruption.
INCIDENT DETAILS -
TYPE
ransomwaredata breachsupply chain attackphishingtriple extortion
MOTIVATION
financial gain (ransom payments, data extortion)disruption of critical infrastructure (e.g., healthcare, supply chains)data theft for dark web sales (e.g., PII, medical records)espionage (e.g., state-linked DanaBot attacks)reputation damage (e.g., leaking sensitive data)
IMPACT
$4B (WannaCry, 2017)$18M (Baltimore, 2019)$50M–$70M (Cognizant, 2020)$4.4M (Colonial Pipeline) + $11M (JBS, 2021)$1.1B (MOVEit breaches, 2023)$22M ransom + $2B losses (Change Healthcare, 2024)$25M (CDK Global, 2024)$160M (CommonSpirit Health, 2022)$300M (Marks & Spencer, 2024–2025)$4B (Sensata Technologies, 2025)Average ransom payment: $2.73M (2024, up from $1.5M in 2023)Average cost per attack: $5.13M (2025, +574% since 2019)93.3M individuals (MOVEit, 2023)9.7M medical records (Medibank, 2022)5.6M patient records (Healthcorps, 2024)726K customers (Patelco Credit Union, 2024)254K users (Kadokawa/Niconico, 2024)500GB (Spanish Tax Agency, 2024)1TB (Nvidia, 2022)190GB (Samsung, 2022)65GB (British Library, University of Hawaii, 2023)PII, payment info, medical records, corporate secrets (e.g., Apple blueprints via Quanta, 2021)300K+ computers (WannaCry, 150+ countries, 2017)650 servers + 150 apps (Sky Lakes Medical Center, 2021)800 servers (Costa Rica government, 2022)10TB data (Canon, 2020)740GB (Toshiba, 2021)1.4M patient records (Lubbock County, 2019)Port of Nagoya (10% of Japan’s trade disrupted, 2023)thousands of dealerships (CDK Global, 2024)US fuel supply (Colonial Pipeline, 2021)US meat supply (JBS, 2021)1 month (Baltimore, 2019)7 months (Sky Lakes Medical Center, 2021)prolonged disruptions (Change Healthcare, CDK Global, 2024)manual processes (University Hospital Center Zagreb, 2024)fuel shortages (Colonial Pipeline, 2021)meat supply disruption (JBS, 2021)healthcare service outages (CommonSpirit, Change Healthcare)auto sales halted (CDK Global, 2024)container operations destroyed (Port of Nagoya, 2023)online retail disruptions (Marks & Spencer, 2024–2025)government crises (Costa Rica, 2022)$2B (Change Healthcare, 2024)$300M (Marks & Spencer, 2024–2025)$160M (CommonSpirit Health, 2022)stock price drops (e.g., Carnival Corp, 2020)market cap drop of £1B (Marks & Spencer, 2025)leaked sensitive data (e.g., Washington DC Police, British Library)loss of trust in healthcare (e.g., Medibank, Healthcorps)publicized breaches (e.g., Christie’s, 2025)fines for regulatory violations (e.g., GDPR, HIPAA)lawsuits from affected customers (e.g., patients, credit union members)SEC disclosures (e.g., Sensata Technologies, 2025)9.7M medical records (Medibank, 2022)5.6M patient records (Healthcorps, 2024)726K customers (Patelco Credit Union, 2024)500K clients (Christie’s, 2025)credit card data (e.g., Patelco Credit Union, 2024)financial records (e.g., Spanish Tax Agency, 2024)cryptocurrency theft (e.g., CoinDash, 2017)
DATA BREACH
PII (e.g., Medibank, Patelco Credit Union)medical records (e.g., CommonSpirit, Healthcorps)payment information (e.g., Spanish Tax Agency)corporate secrets (e.g., Apple blueprints via Quanta)government data (e.g., Washington DC Police, Costa Rica)student/employee data (e.g., Munster Technological University)customer data (e.g., Christie’s, Marks & Spencer)93.3M (MOVEit, 2023)9.7M (Medibank, 2022)5.6M (Healthcorps, 2024)726K (Patelco Credit Union, 2024)254K (Kadokawa/Niconico, 2024)500K (Christie’s, 2025)1.4M (Lubbock County, 2019)70K (Nvidia, 2022)high (PII, medical, financial, corporate secrets)MOVEit (Clop gang, 2023)BlackCat/ALPHV (Change Healthcare, 2024)REvil (JBS, Kaseya, 2021)Lapsus$ (Nvidia, Samsung, 2022)Babuk (Washington DC Police, 2021)Rhysida (British Library, 2023)WannaCry (2017, 300K+ computers)Colonial Pipeline (2021)CDK Global (2024)Change Healthcare (2024)Port of Nagoya (2023)databases (e.g., patient records, customer data)documents (e.g., corporate secrets, legal files)emails (e.g., phishing lures, credentials)source code (e.g., Samsung, Nvidia)financial records (e.g., Spanish Tax Agency)names, addresses, SSNs (e.g., Patelco Credit Union)medical histories (e.g., Medibank, Healthcorps)payment card data (e.g., retail breaches)biometric data (e.g., healthcare breaches)
JUNE 2023
611Before Incident
Ransomware
01 Jun 2023Change Healthcare
Change Healthcare

Change Healthcare Ransomware Attack

478After Incident
CRITICAL-133
CHA424070124
In February, Change Healthcare suffered a ransomware attack that disrupted its services, impacting cash flow for Medicare providers, including hospitals and pharmacies. The CMS initiated the CHOPD program to alleviate the financial strain on affected parties by distributing over $2.55 billion to Part A providers and more than $717.18 million to Part B suppliers. The swift mitigation efforts by CMS ensured the continued delivery of essential patient care amidst one of the largest cyberattacks targeting the U.S. healthcare sector. Notably, CMS has recouped most of the advance payments, and normal billing processes are now reinstated for providers.
INCIDENT DETAILS -
TYPE
Ransomware Attack
IMPACT
Operational Impact: Disruption of services, impacting cash flow for Medicare providers
FEBRUARY 2023
617Before Incident
Cyber Attack
01 Feb 2023Change Healthcare
Change Healthcare

Change Healthcare Cyber-Attack

598After Incident
CRITICAL-19
CHA412050824
Change Healthcare, part of Optum and a subsidiary of UnitedHealth Group, experienced a significant cyber-attack that led to disruptions in prescription issuance. The attack began to surface on February 21, when certain applications became unavailable due to what was later identified as a network interruption caused by a cybersecurity issue. The company took measures to mitigate the impact by disconnecting its systems upon recognizing an external threat. The disruptions have affected the healthcare transactions of approximately one-third of US patients, given the company's substantial role in handling 15 billion transactions annually. This situation underscores the vulnerability of healthcare providers to cyber threats and the potential for such attacks to significantly delay medical treatments and prescriptions, affecting both the company's operations and patient care.
INCIDENT DETAILS -
TYPE
Cyber-Attack
IMPACT
Systems Affected: Prescription issuance applicationsOperational Impact: Disruptions in prescription issuance
JANUARY 2020
768Before Incident
Ransomware
01 Jan 2020Change Healthcare
Change Healthcare

Change Healthcare Ransomware Attack (2024)

456After Incident
CRITICAL-312
CHA734082825
In February 2024, Change Healthcare suffered a massive ransomware attack after hackers exploited a server lacking multi-factor authentication. The breach compromised personal health information of over 100 million individuals, making it one of the largest healthcare data breaches in U.S. history. Operations were severely disrupted, leading to financial losses estimated between $2.3 billion and $2.45 billion. The incident triggered investigations by the U.S. Department of Health and Human Services (HHS), intensifying regulatory scrutiny on healthcare cybersecurity. The attack highlighted systemic vulnerabilities in third-party vendors handling sensitive patient data, prompting broader industry-wide concerns about ransomware resilience and proactive threat detection. The fallout included operational chaos, reputational damage, and long-term financial repercussions, reinforcing the need for stricter access controls and advanced threat-monitoring systems.
INCIDENT DETAILS -
TYPE
ransomwaredata breach
MOTIVATION
financial gaindata exfiltration
IMPACT
Financial Loss: $2.3 billion to $2.45 billion (estimated response cost)Data Compromised: Personal health information (PHI) of over 100 million individualsnetwork serversoperational systemsOperational Impact: Significant disruption to healthcare operations and payment processingBrand Reputation Impact: Severe damage due to scale of breach and regulatory scrutinyLegal Liabilities: Investigations by U.S. Department of Health and Human Services (HHS)Identity Theft Risk: High (due to exposure of PHI for 100M+ individuals)
DATA BREACH
personal health information (PHI)patient recordsNumber Of Records Exposed: 100 million+Sensitivity Of Data: High (includes protected health information)
JANUARY 1999
768Before Incident
Breach
01 Jan 1999Change Healthcare
Yahoo, SolarWinds, Colonial Pipeline and Change Healthcare: The 25 Biggest Cyber Attacks In History

Yahoo Data Breach

618After Incident
CRITICAL-150
COLSOLYAHCHA1784557988
The 25 Most Impactful Cyberattacks in History: A Breakdown of Scale and Consequences Global cybercrime costs are projected to surge from $10.5 trillion in 2025 to $12.2 trillion by 2031, driven by data theft, financial fraud, operational disruptions, and recovery expenses. Cybersecurity Ventures has compiled a list of the 25 most significant cyberattacks in history, ranked by data compromised, financial impact, geopolitical fallout, and attack sophistication demonstrating that scale isn’t measured by a single metric. A nation-crippling fuel shortage and a breach of three billion records can both qualify as "biggest," depending on the damage inflicted. Key Incidents Highlighted: - Yahoo Data Breach (2013–2014): Compromised 3 billion user accounts, one of the largest breaches by volume. - Stuxnet (2010): A state-sponsored cyberweapon targeting Iran’s nuclear facilities, marking a turning point in cyber warfare. - WannaCry (2017): Ransomware that infected 200,000+ systems across 150 countries, disrupting hospitals, businesses, and government agencies. - NotPetya (2017): Initially disguised as ransomware, it caused $10 billion in global damages, crippling shipping, logistics, and pharmaceutical firms. - SolarWinds (2020): A supply chain attack attributed to Russian hackers, infiltrating U.S. government agencies and Fortune 500 companies via compromised software updates. - Colonial Pipeline (2021): A ransomware attack forced the shutdown of a major U.S. fuel pipeline, triggering fuel shortages and panic buying. - OPM Data Breach (2015): Exposed sensitive records of 21.5 million U.S. federal employees, including background check data. - MOVEit Transfer (2023): A zero-day exploit in file-transfer software led to widespread data theft, affecting government agencies, corporations, and universities. - Change Healthcare (2024): A ransomware attack disrupted U.S. healthcare payments, delaying prescriptions and insurance processing nationwide. Emerging Threats: Attackers are increasingly leveraging AI to refine phishing campaigns, generate polymorphic malware, and automate reconnaissance. Meanwhile, quantum computing looms as a future threat, with the potential to break widely used encryption standards. As cyber threats evolve, so too do their methods from early viruses like Melissa (1999) and Code Red (2001) to modern supply chain attacks and AI-driven exploits. The list underscores the persistent and escalating nature of cyber risks across industries and governments.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Theft
IMPACT
Data Compromised: 3 billion user accountsBrand Reputation Impact: SevereIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: User account dataNumber Of Records Exposed: 3 billionSensitivity Of Data: HighPersonally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Change Healthcare ?
?
What was Change Healthcare's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Change Healthcare's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Change Healthcare's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Change Healthcare's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Change Healthcare's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Change Healthcare's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Change Healthcare's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Change Healthcare's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Change Healthcare's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Change Healthcare's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Change Healthcare's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on Change Healthcare's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Change Healthcare ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Change Healthcare's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?