UnitedHealth Group has revised the impact of the 2024 Change Healthcare ransomware attack to approximately 190 million individuals, nearly doubling its previous estimate of 100 million. The updated figure, confirmed by UnitedHealth to Recorded Future News, makes this the largest healthcare data breach in US history by a wide margin. The attack was carried out by the ALPHV/BlackCat ransomware group, which received a $22 million ransom before the stolen data leaked anyway.
What Happened
In February 2024, the ALPHV/BlackCat ransomware group compromised Change Healthcare, a UnitedHealth Group subsidiary that processes a substantial share of US medical claims and pharmacy transactions. UnitedHealth paid a $22 million ransom in an attempt to prevent publication of the stolen data. That payment did not resolve the situation: a dispute among the attackers led to the data being reposted on a separate ransomware group's leak site, exposing the records anyway.
UnitedHealth has now completed more than 90% of its data review and raised the confirmed victim count from 100 million to roughly 190 million individuals. The company told Recorded Future News that the final tally will be confirmed and submitted to the Department of Health and Human Services Office for Civil Rights at a later date. HHS ordered Change Healthcare to file breach notifications on behalf of the thousands of hospitals, pharmacies, and doctor's offices that rely on its clearinghouse services.
What Was Taken
Investigators found no evidence that full medical records or doctors' charts were exfiltrated. However, the attackers likely accessed a wide range of sensitive information, including:
- Health insurance information
- Medical record numbers
- Test results
- Billing and claims data
- Personal identifiers including Social Security numbers
At an estimated 190 million individuals, the exposure touches well over half the US population. The combination of insurance details, medical record numbers, and Social Security numbers is highly valuable for identity theft, insurance fraud, and targeted phishing.
Why It Matters
Change Healthcare sits at a critical chokepoint in the US healthcare economy, brokering claims and payments for thousands of downstream providers. A single compromise at that layer cascaded into the largest healthcare breach the country has recorded. The incident demonstrates how a third-party clearinghouse can concentrate risk for organizations that never directly interacted with the attacker.
The case also illustrates the futility of ransom payment as a data-protection strategy. UnitedHealth paid $22 million, yet the records surfaced anyway when the criminal ecosystem turned on itself. The breach has already triggered multiple class action lawsuits and federal investigations, and the notification burden is being pushed downstream onto thousands of affected providers.
The Attack Technique
Public reporting attributes the intrusion to ALPHV/BlackCat, a ransomware-as-a-service operation known for double-extortion tactics that pair encryption with data theft and leak-site pressure. While the full initial-access vector for the Change Healthcare compromise has been widely discussed as a lack of multi-factor authentication on a remote-access system, the source reporting here focuses on the exfiltration and extortion phases. What is confirmed is that the group both accessed and stole large volumes of data, then attempted to monetize it through ransom payment. The subsequent internal dispute among the threat actors, and the reposting of data to a rival leak site, is characteristic of the unstable affiliate model that underpins ransomware-as-a-service.
What Organizations Should Do
- Enforce phishing-resistant multi-factor authentication on all remote-access and administrative systems, with no exceptions for legacy accounts.
- Map and continuously assess third-party and clearinghouse dependencies, treating concentrated vendors like Change Healthcare as critical single points of failure.
- Segment networks so a compromise of a claims or payment intermediary cannot expose full patient data stores.
- Maintain and test offline, immutable backups so recovery does not depend on paying a ransom, which offers no guarantee against data exposure.
- Prepare breach-notification and legal-response playbooks in advance, since providers may inherit notification duties from a compromised third party.
- Monitor for downstream fraud and phishing that abuse leaked insurance identifiers, medical record numbers, and Social Security numbers.
Sources: Change Healthcare data breach victims surge to 190 million – MedRisk
TWEET: Change Healthcare breached by ALPHV/BlackCat ransomware. UnitedHealth doubled the toll to ~190M people, now the largest US healthcare breach on record. Full breakdown: https://wasteland.me/intel/change-healthcare-breach-190-million #CyberSecurity #ThreatIntel