The Change Healthcare Cyberattack: How One Missing MFA Setting Caused the Largest Healthcare Breach in US History
Most breach case studies involve a chain of failures. This one did not need a chain. A single remote access portal without multi-factor authentication was enough to trigger the largest healthcare data breach in US history, one that has now cost UnitedHealth Group more than $3.6 billion and affected roughly two out of every three Americans.
Here is exactly what happened, what it has cost so far, and the one lesson every business should take from it.
What Happened: A Timeline
- February 21, 2024: Attackers used stolen credentials to remotely access a Citrix portal belonging to Change Healthcare, a UnitedHealth Group subsidiary that processes a large share of US healthcare claims and payments. In testimony before Congress, CEO Andrew Witty confirmed the portal did not have multi-factor authentication enabled.
- Nine days later: After moving laterally through internal systems and exfiltrating data, the attackers, identified as the ALPHV/BlackCat ransomware group, deployed ransomware, forcing Change Healthcare to shut down its network to contain the damage.
- The ransom: UnitedHealth confirmed paying $22 million to the attackers. The group then exit-scammed its own affiliate, who took a copy of the stolen data to a second extortion group, RansomHub, which posted portions of it on the dark web demanding an additional payment.
- The scope grew for over a year: Initial disclosures cited roughly 500 affected individuals. That estimate rose to 100 million by October 2024, then to approximately 190 million by January 2025, and to 192.7 million by July 2025, nearly two-thirds of the US population and the largest healthcare breach ever recorded.
The Root Cause: One Missing Control
The technical details of this breach are almost beside the point. Attackers did not need a sophisticated exploit or a zero-day vulnerability. They needed one working set of stolen credentials and one remote access point that only checked a password. Every other security control Change Healthcare had in place, and a company of its size had many, became irrelevant the moment that single portal let a password stand in for identity verification.
This is precisely the scenario covered in our breakdown of what cyberattacks MFA actually stops: credential-based attacks work exactly once, at exactly the point where a second factor should have been required and wasn’t. It is worth being specific about why this particular gap was so damaging. Change Healthcare processes roughly one in three US patient records, meaning a single compromised portal did not just expose one organization’s data, it created a single point of failure for a meaningful share of the entire country’s healthcare claims infrastructure.
The Ripple Effect on Healthcare Providers
The damage did not stop at UnitedHealth Group’s own balance sheet. The American Medical Association surveyed more than 1,400 physician practices in the weeks after the attack and found the disruption threatened the financial survival of many of them. Eighty percent of practices reported lost revenue from unpaid claims, 85% had to dedicate additional staff time just to manage revenue cycle tasks manually, and 36% saw claim payments suspended outright. Nearly half of practices were forced into new, often costlier arrangements with alternative clearinghouses just to keep processing claims. A separate American Hospital Association survey found 94% of hospitals reported a financial impact, with almost 60% losing $1 million or more in revenue per day at the height of the disruption. One physician told the AMA the incident was “leading me to bankruptcy.” This is the part of a breach that rarely makes the initial headlines: the direct victim’s costs are only part of the story when that victim sits at the center of an entire industry’s payment infrastructure.
The Cost, By the Numbers
Impact | Figure |
Direct response and business disruption costs, 2024 | $2.87 billion |
Additional cyberattack costs recorded in 2025 | $799 million |
Combined direct costs, 2024 to 2025 | More than $3.6 billion |
Ransom paid to attackers | $22 million |
Interest-free loans and advance funding to care providers | Over $9 billion |
Individuals affected | Approximately 192.7 million |
Those figures come directly from UnitedHealth Group’s SEC filings, not third-party estimates, and they do not include the cost of ongoing litigation, which has not yet been resolved.
The Aftermath: Regulatory and Legal Fallout Is Still Unfolding
The consequences extend well beyond the initial response costs. The Department of Health and Human Services’ Office for Civil Rights opened a HIPAA compliance investigation into Change Healthcare and UnitedHealth Group, notably before Change had even formally reported the breach, an unusually proactive move that signals how seriously regulators are treating the incident. A multidistrict litigation is currently active in the US District Court for the District of Minnesota, with a pretrial scheduling conference held in early 2026 and settlement discussions between plaintiffs’ and defense counsel ongoing. Nebraska’s Attorney General separately sued Change Healthcare, UnitedHealth Group, and Optum, alleging violations of the state’s consumer protection and data privacy laws, a lawsuit that survived a motion to dismiss and is proceeding toward further hearings. As of early 2026, no global settlement has been reached. For comparison, the 2015 Anthem breach, which affected 78.8 million people, roughly a third of this incident’s scale, settled for $115 million in 2017. Legal experts widely expect any eventual Change Healthcare settlement to be considerably larger, given the difference in scale and the ongoing regulatory scrutiny.
The Lesson for Every Business
The takeaway is not “healthcare companies need better security.” UnitedHealth Group operates a large, well-resourced security program, and the vast majority of its systems were presumably protected far better than this one portal. The takeaway is narrower and more uncomfortable: partial MFA coverage is not real MFA coverage. A remote access portal, a legacy system, a third-party integration, or a vendor-facing login that gets overlooked during rollout is exactly the kind of gap attackers look for, and one gap is all a credential-based attack needs. Attackers do not need to find a weakness in your strongest system. They only need to find your weakest one. Our guide on the pros and cons of enabling MFA covers how to think through coverage systematically rather than account by account, and our post on how hackers bypass 2FA covers the specific techniques worth defending against once basic coverage is in place.
How OmniDefend Closes This Exact Gap
The failure point in this breach was a remote access portal, exactly the kind of system organizations sometimes treat as lower priority than customer-facing applications, precisely because it is used internally rather than by the public. That assumption is backwards: internal and remote access systems are often the ones attackers target first, since they frequently carry broad permissions and receive less scrutiny than anything customer-facing. OmniDefend’s MFA platform is built to close that specific blind spot, applying consistent multi-factor enforcement across remote access, internal systems, and cloud applications alike, rather than leaving coverage decisions to be made system by system or team by team. For healthcare organizations specifically, OmniDefend also supports HIPAA-aligned identity and access management built for the exact compliance requirements this scenario triggered.
Don’t Let One Overlooked System Become Your Breach Story
A single portal without MFA cost one company over $3.6 billion and counting. Closing that kind of gap does not require a multi-year overhaul. Start your 30-day free trial of OmniDefend and see how quickly full-coverage MFA can be in place across every access point in your organization, no credit card required.
Frequently Asked Questions
1. What caused the Change Healthcare breach?
Attackers used stolen credentials to log into a Citrix remote access portal that did not have multi-factor authentication enabled, then moved laterally through internal systems before deploying ransomware.
2. How many people were affected?
UnitedHealth Group’s most recent disclosure, as of July 2025, put the number at approximately 192.7 million individuals, making it the largest healthcare data breach recorded in the United States.
3. Did UnitedHealth pay the ransom?
Yes, the company confirmed paying $22 million to the attackers. A second group later claimed to also possess the stolen data and attempted to extort an additional payment.
4. Has the Change Healthcare breach been settled?
As of early 2026, no global settlement has been reached. Litigation is ongoing in a multidistrict case in Minnesota, along with separate state-level lawsuits, and a HIPAA investigation from HHS remains open.
5. How can businesses avoid a similar breach?
Apply multi-factor authentication consistently across every system that can be reached remotely, not just the ones considered highest priority. Attackers specifically look for the system that was left out of the rollout.
6. Why did this breach affect so many providers beyond UnitedHealth itself?
Change Healthcare processes roughly one in three US patient records and sits at the center of claims processing for a large share of the healthcare industry. When it went offline, the disruption cascaded to physician practices and hospitals nationwide that depended on it to get paid, independent of whether their own systems were ever compromised.
Sources
- UnitedHealth Group 10-K, Fiscal Year 2024 (SEC filing)
- UnitedHealth Group 8-K, Fiscal Year 2025 Q4 Results (SEC filing)
- Nixon Peabody: Change Healthcare Cybersecurity Breach Impact on Healthcare Providers
- Security.org: Change Healthcare Data Breach, What Happened and What to Do
- American Medical Association: Physicians Struggle to Keep Practices Afloat After Change Cyberattack

Ayush Bhansali is a seasoned writer with a passion for unraveling the intricacies of cyber security, workforce protection, and the cutting-edge realm of SAML 2.0, FIDO, OpenID Connect and FIDO 2.0. With three years of dedicated experience, Ayush has honed his expertise in dissecting the ever-evolving landscape of technology and its impact on our digital lives. His insightful articles not only demystify complex concepts but also provide practical insights for individuals and organizations looking to fortify their digital defenses. Ayush’s writing style is characterized by its clarity and accessibility, making even the most intricate topics comprehensible to a wide audience. Through his work, Ayush strives to empower readers with the knowledge they need to navigate the rapidly advancing world of technology securely.





