onlinesyscfg.research
utc
syscfg://research
home/research/change-healthcare-alphv-ransomware
PublishedThreat History

Change Healthcare: How One Ransomware Attack Broke the US Healthcare Payment System

2026-08-09-18 min read
#ransomware#alphv#blackcat#healthcare#change-healthcare#unitedhealth#raas

On February 21, 2024, Change Healthcare - a subsidiary of UnitedHealth Group and the largest healthcare payment processor in the United States - went offline. The disruption lasted weeks. Pharmacies couldn't process prescriptions. Hospitals couldn't verify insurance coverage. Clinics couldn't bill for services rendered. Patients at independent pharmacies were turned away or asked to pay cash. The company processes roughly 15 billion transactions per year, touching one in every three patient records in the US.

The cause was a ransomware attack by ALPHV/BlackCat, a ransomware-as-a-service group that had been operating since late 2021. They had been inside Change Healthcare's network for nine days before deploying the ransomware. UnitedHealth Group paid a $22 million ransom. Then ALPHV disappeared with the money, scamming their own affiliate.

Change Healthcare and Why It Mattered

Change Healthcare is invisible infrastructure. Most Americans have never heard of it, but it processes their insurance claims, routes their electronic prescriptions, handles prior authorizations, and manages the financial plumbing between healthcare providers and payers. The company was acquired by UnitedHealth Group's Optum subsidiary in 2022 after a proposed merger with Cigna was blocked by the Department of Justice on antitrust grounds.

That concentration - one company processing a third of all US healthcare transactions - created a single point of failure that no one in the healthcare industry had adequately planned for. When Change Healthcare went down, the cascade effects were immediate and widespread. The American Hospital Association estimated that hospitals were losing over $100 million per day during the outage. Independent pharmacies with thin margins and no alternative processing relationships were particularly exposed.

[WARNING]
The entry vector was a compromised Citrix remote access portal that lacked multi-factor authentication. This is the same class of vulnerability that has enabled attacks on dozens of healthcare organizations over the past several years. ALPHV/BlackCat had exploited Citrix vulnerabilities in multiple prior attacks.

ALPHV/BlackCat

ALPHV, also known as BlackCat, launched its ransomware-as-a-service operation in November 2021. It was notable for being written in Rust rather than C/C++ - an unusual choice that made cross-platform compilation easier and provided some evasion benefits against legacy antivirus tools that weren't parsing Rust binaries. The group operated a sophisticated affiliate model: developers and infrastructure providers took a cut of each ransom while independent affiliates conducted the actual intrusions.

ALPHV operated a data leak site called "ALPHV Collections" on the dark web, where they would publish stolen data from victims who refused to pay. This double extortion model - both encrypting data and threatening to publish it - had become standard by 2024, but ALPHV executed it with notable aggression. They were among the first groups to also extort patients directly, contacting individuals whose medical records they had stolen and demanding payment to keep the records private.

The group had prior law enforcement attention. In December 2023, the FBI and international partners seized ALPHV infrastructure and released a decryption tool. ALPHV responded within days by un-seizing their own site - accessing it through a backup domain they controlled - and announcing "unseized" status. They then claimed to be removing previous restrictions on affiliate attacks against hospitals and critical infrastructure. This taunting response illustrated how difficult it is to permanently disrupt ransomware infrastructure when operators remain at large.

The Attack

The ALPHV affiliate responsible for the Change Healthcare attack gained access through stolen credentials for a Citrix remote access portal. The portal did not require multi-factor authentication. From there, the attacker moved laterally through Change Healthcare's network over nine days, identifying high-value systems and exfiltrating data before deploying the ransomware payload.

The exfiltrated data was substantial. ALPHV and their affiliate claimed to have stolen 6 terabytes of data, including patient records, insurance information, payment data, and personally identifiable information for what may have been a majority of Americans. The scope of the data theft was initially unclear and has remained somewhat uncertain as UnitedHealth has provided limited specific details about what was taken.

[IOC]
Ransomware deployment: February 21, 2024. The encrypted systems were primarily Windows-based healthcare payment processing infrastructure. ALPHV used their Rust-based ransomware payload. Systems affected included pharmacy dispensing, insurance verification, electronic prescribing, and revenue cycle management platforms.

The Ransom Payment

UnitedHealth Group paid a $22 million ransom in Bitcoin on March 6, 2024. The transaction was visible on the blockchain and first reported by Wired. This was one of the largest publicly confirmed ransomware payments in history.

What happened next illustrated a hazard of the ransomware-as-a-service model. The ALPHV operators - the group that developed and maintained the ransomware platform - took the $22 million and then performed what is known in criminal forums as an "exit scam." They shut down their infrastructure, deleted their servers, and disappeared. The affiliate who had actually conducted the Change Healthcare attack received nothing.

The affiliate, identifying as a group called "RansomHub" on dark web forums, had retained copies of the stolen data. Having received no payment from ALPHV, they began extorting Change Healthcare independently. They published a portion of the stolen data on their own leak site and demanded additional payment. This created a situation where Change Healthcare had paid $22 million and still faced ongoing extortion from a different actor holding the same data.

The Congressional Response

UnitedHealth Group CEO Andrew Witty testified before Congress in May 2024. The hearings were notable for the level of bipartisan frustration directed at the company. Senators from both parties questioned how the largest health insurer in the country - one that had paid its CEO over $23 million the prior year - could be running a system that processed a third of all US healthcare transactions through a portal without multi-factor authentication.

Witty acknowledged the failure. He confirmed the $22 million ransom payment. He confirmed that MFA had not been enabled on the Citrix portal. He could not give senators a precise count of how many Americans' data had been stolen, saying estimates were still being compiled.

The hearings produced commitments to improve security posture but no specific legislative outcome addressing healthcare sector cybersecurity requirements. HIPAA's security rule had not been substantially updated to address current threat environments, and proposed updates had been stalled for years.

Impact on the Healthcare System

The full financial impact of the Change Healthcare attack is difficult to precisely quantify because the effects cascaded across the entire US healthcare system. UnitedHealth Group eventually disclosed estimated losses of $872 million in direct costs from the attack, with total financial impact estimated at $1.6 billion including lost revenues and remediation costs.

For individual healthcare providers, particularly independent practices and rural hospitals operating on thin margins, the weeks without payment processing were existential. The American Hospital Association surveyed members and found that 74% reported financial impacts including inability to pay staff and vendors. Some small practices reported taking out emergency loans or dipping into personal accounts to make payroll during the outage.

The concentration risk revealed by the attack became a policy discussion point. Healthcare experts noted that the trend toward consolidated health IT infrastructure - driven by cost efficiency and interoperability requirements - had created systemic vulnerabilities that individual providers could not mitigate on their own. A single vendor failure could now affect the entire healthcare delivery system.

[INFO]
Patient notification: UnitedHealth began notifying affected individuals in late 2024 and into 2025. The notifications cover a potentially unprecedented number of Americans. Exact figures have not been publicly confirmed but estimates from security researchers and the company's own disclosures suggest the breach may be the largest healthcare data breach in US history by record count.

ALPHV's End

After the exit scam following the Change Healthcare payment, ALPHV did not publicly reconstitute. The affiliate ecosystem that had operated under the ALPHV brand dispersed to other ransomware-as-a-service platforms, primarily RansomHub, which grew rapidly through 2024 in part by absorbing former ALPHV affiliates. By the end of 2024, RansomHub had become one of the most prolific ransomware groups operating, with a particular focus on healthcare and critical infrastructure - a continuation of the targeting patterns established by ALPHV.

The exit scam demonstrated both the internal criminal dynamics of ransomware-as-a-service and a potential leverage point for disruption. When affiliates can't trust that their ransom shares will be paid, the economics of the model break down. Law enforcement operations that seize infrastructure and cast doubt on whether operators will pay affiliates - even if they don't achieve arrests - can fracture the trust that makes ransomware-as-a-service work.

What Changed

UnitedHealth Group spent over $1 billion on cybersecurity remediation following the attack. This included mandatory MFA deployment across Optum and Change Healthcare systems, network segmentation improvements, and enhanced monitoring. The scale of the investment reflects both the severity of the incident and the reputational pressure on the company after congressional testimony and media coverage.

For the broader healthcare sector, the Change Healthcare attack accelerated discussions about minimum cybersecurity requirements for organizations that handle patient data at scale. HHS proposed updated HIPAA Security Rule requirements in January 2025, including mandatory MFA for certain systems, technology asset inventories, and network segmentation requirements. Whether those requirements will survive the regulatory process and be effectively enforced remains an open question.

The most durable lesson may be about concentration risk rather than any specific technical control. Healthcare's push toward interoperability and consolidated infrastructure creates efficiency but also creates targets. A single company processing 15 billion healthcare transactions per year is both a remarkable efficiency achievement and a remarkably attractive target. The two things cannot be fully separated.