On February 21, 2024, Change Healthcare - a subsidiary of UnitedHealth Group and the largest healthcare payment processing company in the United States - was taken offline by a ransomware attack. The outage lasted 22 days and affected every corner of the US healthcare system. Pharmacies could not process prescriptions. Hospitals could not verify insurance coverage or submit claims. Doctors' offices could not bill. Small independent pharmacies ran out of cash to pay for drug inventory. Cancer patients were unable to get chemotherapy approved. The attack caused what AHA President Rick Pollack called "an existential threat to hospitals."
The attacker was ALPHV (BlackCat), the same ransomware group behind the MGM attack five months earlier. The initial access vector was compromised credentials for Citrix remote access that lacked multi-factor authentication. UnitedHealth Group CEO Andrew Witty confirmed in May 2024 Congressional testimony that the attackers had used stolen credentials to access a Change Healthcare Citrix portal that did not have MFA enabled. UnitedHealth paid a $22 million ransom - the largest known ransomware payment in history at the time.
The Scale of Healthcare Dependency
Change Healthcare's position in the US healthcare system was not widely understood until it disappeared. The company processed approximately 15 billion healthcare transactions annually - roughly one-third of all healthcare claims in the United States. It was the connectivity layer between healthcare providers (hospitals, pharmacies, physician practices) and health insurance companies. When it went down, the electronic claims system that had replaced paper billing effectively ceased to function across a third of the healthcare sector.
The scope of services affected included: pharmacy point-of-sale systems, eligibility verification (determining whether a patient's insurance would cover a procedure), prior authorization (getting insurance approval before treatment), claims submission and payment processing, and clinical documentation. Many healthcare organizations had no manual backup processes because electronic processing had been the standard for over a decade.
The financial impact on healthcare providers was immediate and severe. Hospitals lost hundreds of millions in claims they could not submit. The American Hospital Association estimated hospitals and health systems were losing $1 billion per week during the outage. Small providers with limited cash reserves faced closure. The federal government eventually established emergency funding mechanisms and allowed Medicare advance payments to stabilize providers that were running out of operating cash.
The Ransom Payment and the ALPHV Exit Scam
UnitedHealth Group paid ALPHV $22 million in Bitcoin in early March 2024. The payment was intended to obtain a decryption key and a promise that stolen data would not be published. What happened next illustrated the unreliability of ransomware payment.
ALPHV took the $22 million and exit-scammed their own affiliate. The affiliate - a group called RansomHub that had been the actual operator conducting the Change Healthcare attack - claimed they had never received their share of the ransom from ALPHV. ALPHV's infrastructure had been seized by law enforcement in December 2023 (Operation Magnus), and ALPHV apparently used the Change Healthcare payment to perform a final cash-out before fully shutting down. RansomHub then began threatening to publish the stolen data themselves unless they were paid separately.
This scenario - paying one ransomware group only to be extorted by their affiliate - was a foreseeable consequence of the ransomware-as-a-service ecosystem structure. The payment to ALPHV did not bind RansomHub, who had conducted the actual operation. The stolen data included protected health information on approximately 190 million Americans - the largest healthcare data breach in US history - and its eventual disclosure or use remained uncertain.
Congressional Response and Andrew Witty's Testimony
UnitedHealth Group CEO Andrew Witty testified before both Senate and House committees in May 2024. His testimony was notable for several admissions: that the initial access was through a Citrix portal without MFA; that the company had paid $22 million in ransom; that data on "potentially a substantial proportion of people in America" had been stolen; and that Change Healthcare had been acquired by UnitedHealth in 2022 despite known security deficiencies.
Witty acknowledged under questioning that MFA had not been enabled on the breached Citrix portal, that the company had been working to improve Change Healthcare's security posture following the acquisition, and that the security improvements had not been completed before the breach. The testimony generated bipartisan outrage in both chambers.
Legislative proposals following the attack included: mandatory minimum cybersecurity standards for healthcare entities receiving Medicare and Medicaid payments, hospital-specific cybersecurity requirements under the Cybersecurity and Infrastructure Security Agency Act, and increased HHS enforcement authority for HIPAA security rule violations. The hospital lobby objected to unfunded mandates; UnitedHealth and other large vendors objected to prescriptive technical standards. As of mid-2026, no major new legislation had passed.