Change Healthcare, a unit of UnitedHealth Group that processes a large share of US medical claims, was hit by a ransomware attack later attributed to the ALPHV/BlackCat group, causing weeks of disruption to pharmacies, hospitals, and doctors’ practices.
What happened
- Outages became public on 21 February 2024, and UnitedHealth disclosed the attack in a regulatory filing the next day and took affected systems offline.
- Chief executive Andrew Witty told the US Senate Finance Committee on 1 May 2024 that attackers had used stolen credentials on a portal without multi-factor authentication, and confirmed a US$22m ransom had been paid.
- Many providers faced cash-flow problems while claims processing was down, prompting emergency funding support.
- UnitedHealth put the number of people affected at 190 million in January 2025, later revised to about 192.7 million, making it the largest known US healthcare data breach.
Why it mattered
The attack showed how a single, highly concentrated supplier can become a point of failure for an entire national sector, with patient and financial harm far beyond the company itself.
Lessons for organisations
Enforce MFA on every remote access route, with no exceptions for legacy systems. Map critical suppliers, understand concentration risk, and plan how you would operate if a key provider went offline for weeks.
Sources: TechCrunch, The Record
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.