Case file · CHANGE HEALTHCARE 2024

How the Change Healthcare breach happened: one password, no second factor

Published 2026-09-29 · 5 min read · Missing control: MFA on every remote portal

The biggest theft of American medical records started with one username and password typed into a remote-access portal that never asked for a second proof of identity.[1][5] This case file covers how the Change Healthcare attack unfolded, what the $22 million ransom did and did not buy, and the one control that would have closed the door.

What happened

Change Healthcare, owned by UnitedHealth Group, sits in the middle of American medicine. It says it handles 15 billion health care transactions a year and touches about 1 in 3 patient records, moving claims, payments and prescription approvals between doctors, pharmacies and insurers.[3]

On February 12, 2024, criminals logged in to a Change Healthcare Citrix portal, a remote-access gateway, using stolen credentials. The portal did not have multi-factor authentication turned on.[1][2] For 9 days they moved through the network and copied data. On February 21 they set off ransomware, and the company shut its systems down to contain it.[1][5]

The effect spread fast. Pharmacies could not process insurance claims the normal way, and more than 90% of the over 70,000 pharmacies that relied on Change had to switch to other processors.[3] UnitedHealth named the ALPHV, or BlackCat, ransomware group as responsible on February 29.[5] Around March 1 the company paid a ransom of $22 million, about 350 bitcoin.[1][4] Key pharmacy and payment systems began coming back from March 7, but the claims platform was offline for more than a month.[4][8]

How they got in

No clever exploit was needed. The portal was built to let people work on the network from outside, and it trusted anyone who had the right username and password. UnitedHealth's chief executive, Andrew Witty, told Congress that the attackers used compromised credentials on a portal that lacked multi-factor authentication, the step that asks for a code or a phone prompt on top of a password.[1] Later reporting described the account as belonging to a low-level support employee.[5]

Once inside, the attackers had days to explore before anyone noticed. Witty said they moved sideways through systems and took data before launching the ransomware.[2] Some of Change's technology was decades old, which made cleanup harder.[9]

What it cost

Witty told lawmakers the decision to pay was his.[1] The payment did not end the story. Days later, the ransomware group's leaders appear to have vanished with the money, and an affiliate who said they had done the actual break-in complained publicly that they had been cut out. In April that affiliate's new group demanded a second ransom and posted a portion of the stolen files as proof.[5]

The data haul kept growing. In October 2024 UnitedHealth put the number of affected people above 100 million. In January 2025 it raised the figure to about 190 million, more than half the U.S. population, making it the largest known breach of American health data.[5][7] The exposed information could include contact details, insurance information, health records and billing data.[7]

To keep doctors' offices afloat while claims were frozen, UnitedHealth advanced more than $6.5 billion in accelerated payments and loans to providers.[6] By the end of 2024 it said the attack had cost about $3.1 billion in response costs.[7] No one had been charged over the attack in the sources reviewed.

The missing control

The missing control: multi-factor authentication on every remote-access portal, with no exceptions.

A stolen password is common and cheap. What turns it into a disaster is a door that accepts the password alone. With a second factor on that portal, the attackers would have held a password that did nothing without the employee's phone or security key. After the attack, Witty said every external-facing system across the company now has multi-factor authentication enabled.[9] The lesson is that one overlooked gateway undoes the protection on all the others. Faster detection would also have helped: 9 days is a long time for intruders to wander unseen.

What to do in your business

Full episode

The Change Healthcare attack, start to finish: one password, no second lock, 192.7 million people: the long read behind the CL15 episode, chapter by chapter.

Watch the case
Change Healthcare: One Login Without MFA, $22M RansomDrops 2026-10-17
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. The Register: UnitedHealth CEO says the ransom decision was his, Citrix portal lacked MFA
  2. TechTarget: Change Healthcare breached via Citrix portal with no MFA
  3. NBC News: Ransomware attack on U.S. health care payment processor
  4. TechTarget: The Change Healthcare attack, explaining how it happened
  5. TechCrunch: How the ransomware attack at Change Healthcare went down, a timeline
  6. Medical Economics: Reps grill Change Healthcare CEO over cyberattack effects on smaller practices
  7. Healthcare Dive: Change Healthcare cyberattack affects 190 million people
  8. Healthcare Dive: Change Healthcare hackers used compromised credentials, no MFA
  9. Cybersecurity Dive: Tech takeaways from the UnitedHealth hearings