Episode · CHANGE HEALTHCARE 2024

The Change Healthcare attack, start to finish: one password, no second lock, 192.7 million people

Published 2026-09-29 · 8 min read · Episode 15 of the Cyber Heists long-form series
Change Healthcare 2024: one login, no second factor, 192.7M peoplePremieres 2026-11-22

The attack that left pharmacies across America unable to process prescriptions in February 2024 started 9 days earlier, with a stolen password on a remote login page that had no second sign-in step.[1] This long read follows the Change Healthcare heist in order: the outage, the unlocked door, the $22 million ransom that bought nothing, the count that reached 192.7 million people, the fallout, and the one control that would have stopped it.

The outage that stopped America's prescriptions

Change Healthcare sits in the plumbing of American medicine. When a pharmacy checks a patient's coverage or a clinic sends a bill to an insurer, the request often travels through its network. By one estimate, it handles around half of all health transactions in the United States.[2] UnitedHealth Group owns it through its Optum division.

On February 21, 2024, Change reported a cyber security issue, and outages spread across the country.[2] The ransomware, software that locks computer systems until a ransom is paid, had been launched inside its network that day. UnitedHealth's response was drastic: it cut every connection to Change's systems at once to keep the infection from spreading to hospitals, pharmacies and other customers.[1]

That quarantine stopped the attack from spreading, and it also stopped the money. Pharmacies struggled to confirm coverage, and clinics could not submit claims, which meant insurers could not pay them. For smaller practices living claim to claim, the outage became a cash crisis within days.[1][2]

On February 29, UnitedHealth named the attackers: a ransomware group known as ALPHV, or BlackCat.[2] Groups like it run as a kind of franchise. A core team maintains the ransomware and the payment site, and affiliates, independent criminals who break into victims, do the intrusions in exchange for a cut of each ransom.

The login with no second lock

The explanation came from UnitedHealth's chief executive, Andrew Witty, in written testimony to the Senate Finance Committee on May 1, 2024. On February 12, he said, criminals used compromised credentials to get into a Change Healthcare Citrix portal, a remote access system that let people reach company desktops from outside the office. That portal did not have multifactor authentication, the second sign-in step that asks for a code or a device on top of a password.[1]

Later reporting said the credentials belonged to a low-level customer support account.[2] Whoever it belonged to, a password alone was enough to open the door. The intruders then had 9 days inside before the ransomware went off on February 21, time to move around the network and copy data out.[1][3] Change later confirmed, on March 7, that data had been taken.[3]

This is the uncomfortable part of the case. The attack did not depend on a new or clever technique. Stolen passwords are bought and sold constantly, and remote access pages are among the first places criminals try them. A second sign-in step on that one portal would have turned the stolen password into a useless string of characters.

The $22 million ransom and the double cross

Witty told senators that the decision to pay the ransom was his, and that it was one of the hardest decisions he had ever made.[1] In early March 2024, UnitedHealth paid $22 million, with the stated aim of protecting patients' data and getting it deleted.[2][3]

It did not work out that way. Shortly after the payment, ALPHV's leadership disappeared. The affiliate who had carried out the break-in said the group's operators had kept the entire payment in what is known as an exit scam, cheating their own partner.[2] The affiliate still had the stolen data. On April 15, 2024, a new group called RansomHub posted samples of the stolen files and demanded a second ransom.[2]

Paying had not bought the data back or guaranteed its deletion. It had only shown the criminals that the victim would pay. On April 22, UnitedHealth confirmed publicly that the stolen files could cover a substantial proportion of people in America.[1][2]

Rebuilding Change and counting 192.7 million people

While the ransom drama played out, UnitedHealth rebuilt. Witty told the Senate that experts from Google, Microsoft, Cisco, Amazon, Mandiant and Palo Alto Networks helped reconstruct the systems from the ground up. Thousands of laptops were replaced, credentials were rotated across the company and the data center network was rebuilt.[1] By March 7, 99% of the pharmacies that had used Change before the attack were processing claims again. By late April, payment processing was back to about 86% of its earlier level.[1]

To keep providers afloat, UnitedHealth said it had advanced more than $6.5 billion in accelerated payments and no-interest loans by April 26, about a third of it going to hospitals that serve low-income communities.[1] In his testimony Witty also offered a direct apology to everyone affected.[1]

The count of affected people grew for more than a year. Formal notifications began on June 20, 2024, with letters mailed from July 29.[2] In October 2024, Change confirmed more than 100 million people. In January 2025 it raised the figure to 190 million, more than half the U.S. population.[2] As of July 31, 2025, it told federal regulators the total was 192.7 million, making it the largest health care data breach on record. The exposed files included health information, Social Security numbers, driver's license and passport numbers, and financial and payment card details.[3]

Regulators, lawsuits and a state's complaint

The questions moved from Congress to regulators and courts. In March 2024, the Department of Health and Human Services' Office for Civil Rights, which enforces federal health privacy law, announced an investigation unusually early in the life of a breach. As of November 2025, it had not announced any findings or enforcement action.[3]

Lawsuits from patients and health care providers were gathered into a single multidistrict case in federal court in Minnesota, where they were still moving through pretrial proceedings in late 2025.[3] On December 16, 2024, the state of Nebraska filed its own lawsuit laying out what it described as a series of security failures.[2]

None of that litigation changes the basic account Witty gave under oath: one remote access portal, one stolen password, and no second factor.[1]

How one password became 192.7 million records

Trace it backward. The pharmacies stopped because the network was encrypted and then cut off. The network was encrypted because intruders had 9 days inside. The intruders were inside because a remote login page trusted a password on its own.[1]

Every later cost flowed from that first step: the ransom, the rebuild, the loans to providers, the notifications to 192.7 million people and the lawsuits.[1][3] Large organizations often have one forgotten system that missed a security upgrade, especially after an acquisition, when the buyer inherits a network it did not design. Attackers do not need to find every weakness. They need the one that nobody has listed.

Timeline

DateWhat happened
Feb 12, 2024Intruders log in to a remote access portal with stolen credentials and no second factor.[1]
Feb 21, 2024Ransomware launched; UnitedHealth cuts connections to Change.[1]
Feb 29, 2024UnitedHealth attributes the attack to ALPHV/BlackCat.[2]
Early Mar 2024$22 million ransom paid; the gang vanishes with it.[2]
Mar 7, 202499% of pharmacies processing claims again; data theft confirmed.[1][3]
Apr 15, 2024A second group posts stolen samples and demands another ransom.[2]
May 1, 2024CEO testifies that the portal lacked multifactor authentication.[1]
Jun 20, 2024Formal breach notifications begin.[2]
Oct 2024Count confirmed at more than 100 million people.[2]
Dec 16, 2024Nebraska sues over security failures.[2]
Jan 2025Count raised to 190 million.[2]
Jul 31, 2025Final reported count of 192.7 million people.[3]

The missing control

The missing control: multifactor authentication on every remote access portal, with no exceptions for older systems, and an inventory that proves none are left without it. On February 12, that would have made the stolen password worthless.[1]

  1. List every way into your network from outside. Remote desktop, VPN, web email, cloud admin pages, vendor support tools: write them all down, including ones inherited from an old IT provider or a business you bought.
  2. Turn on two-factor sign-in for each one. Use an authenticator app, passkey or security key rather than text messages where possible, and make it mandatory for every account, not optional.
  3. Close what you do not use. If a remote access page exists only for convenience or history, shut it off instead of securing it.
  4. Check again after every change. When you add a system, switch providers or merge with another business, repeat the inventory and confirm the second factor is on before the new door opens.
  5. Plan for the outage, not just the breach. Keep offline backups, a paper fallback for critical work, and enough cash cushion to survive weeks without a key partner's system.

What it means now

Change Healthcare is the clearest modern proof that one missing checkbox can outweigh billions in security spending. The company had world-class help after the attack. What it lacked beforehand was a second sign-in step on a single page.

For a small business, the math is even starker. You probably have a handful of remote logins, not thousands. Turning on two-factor sign-in for all of them takes an afternoon, and it closes the door this heist walked through.

The short version

How the Change Healthcare breach happened: one password, no second factor: the case file and the Shorts from this case.

Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

Related case files

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. U.S. Senate Committee on Finance: Written testimony of Andrew Witty, CEO, UnitedHealth Group (May 1, 2024)
  2. TechCrunch: How the ransomware attack at Change Healthcare went down, a timeline
  3. Nixon Peabody: Change Healthcare cybersecurity breach, impact on healthcare providers