How the Change Healthcare breach happened: one password, no second factor
The biggest theft of American medical records started with one username and password typed into a remote-access portal that never asked for a second proof of identity.[1][5] This case file covers how the Change Healthcare attack unfolded, what the $22 million ransom did and did not buy, and the one control that would have closed the door.
What happened
Change Healthcare, owned by UnitedHealth Group, sits in the middle of American medicine. It says it handles 15 billion health care transactions a year and touches about 1 in 3 patient records, moving claims, payments and prescription approvals between doctors, pharmacies and insurers.[3]
On February 12, 2024, criminals logged in to a Change Healthcare Citrix portal, a remote-access gateway, using stolen credentials. The portal did not have multi-factor authentication turned on.[1][2] For 9 days they moved through the network and copied data. On February 21 they set off ransomware, and the company shut its systems down to contain it.[1][5]
The effect spread fast. Pharmacies could not process insurance claims the normal way, and more than 90% of the over 70,000 pharmacies that relied on Change had to switch to other processors.[3] UnitedHealth named the ALPHV, or BlackCat, ransomware group as responsible on February 29.[5] Around March 1 the company paid a ransom of $22 million, about 350 bitcoin.[1][4] Key pharmacy and payment systems began coming back from March 7, but the claims platform was offline for more than a month.[4][8]
How they got in
No clever exploit was needed. The portal was built to let people work on the network from outside, and it trusted anyone who had the right username and password. UnitedHealth's chief executive, Andrew Witty, told Congress that the attackers used compromised credentials on a portal that lacked multi-factor authentication, the step that asks for a code or a phone prompt on top of a password.[1] Later reporting described the account as belonging to a low-level support employee.[5]
Once inside, the attackers had days to explore before anyone noticed. Witty said they moved sideways through systems and took data before launching the ransomware.[2] Some of Change's technology was decades old, which made cleanup harder.[9]
What it cost
Witty told lawmakers the decision to pay was his.[1] The payment did not end the story. Days later, the ransomware group's leaders appear to have vanished with the money, and an affiliate who said they had done the actual break-in complained publicly that they had been cut out. In April that affiliate's new group demanded a second ransom and posted a portion of the stolen files as proof.[5]
The data haul kept growing. In October 2024 UnitedHealth put the number of affected people above 100 million. In January 2025 it raised the figure to about 190 million, more than half the U.S. population, making it the largest known breach of American health data.[5][7] The exposed information could include contact details, insurance information, health records and billing data.[7]
To keep doctors' offices afloat while claims were frozen, UnitedHealth advanced more than $6.5 billion in accelerated payments and loans to providers.[6] By the end of 2024 it said the attack had cost about $3.1 billion in response costs.[7] No one had been charged over the attack in the sources reviewed.
The missing control
The missing control: multi-factor authentication on every remote-access portal, with no exceptions.
A stolen password is common and cheap. What turns it into a disaster is a door that accepts the password alone. With a second factor on that portal, the attackers would have held a password that did nothing without the employee's phone or security key. After the attack, Witty said every external-facing system across the company now has multi-factor authentication enabled.[9] The lesson is that one overlooked gateway undoes the protection on all the others. Faster detection would also have helped: 9 days is a long time for intruders to wander unseen.
What to do in your business
- List every way in from outside. Write down every remote desktop, VPN, cloud admin page, email login and vendor portal. Old or test systems count too.
- Turn on multi-factor for all of them. Start with email, remote access and banking. Prefer an authenticator app or security key over text messages where you can.
- Close what you do not use. Shut down remote-access tools nobody needs, and remove accounts for people who have left.
- Watch for odd logins. Turn on alerts for sign-ins from new countries, new devices or odd hours, and have someone read them.
- Plan for the outage. Know how you would bill, pay staff and serve customers if a key vendor or system went dark for a month.
The Change Healthcare attack, start to finish: one password, no second lock, 192.7 million people: the long read behind the CL15 episode, chapter by chapter.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- The Register: UnitedHealth CEO says the ransom decision was his, Citrix portal lacked MFA
- TechTarget: Change Healthcare breached via Citrix portal with no MFA
- NBC News: Ransomware attack on U.S. health care payment processor
- TechTarget: The Change Healthcare attack, explaining how it happened
- TechCrunch: How the ransomware attack at Change Healthcare went down, a timeline
- Medical Economics: Reps grill Change Healthcare CEO over cyberattack effects on smaller practices
- Healthcare Dive: Change Healthcare cyberattack affects 190 million people
- Healthcare Dive: Change Healthcare hackers used compromised credentials, no MFA
- Cybersecurity Dive: Tech takeaways from the UnitedHealth hearings