Change Healthcare Breach 2024: Identity Controls and Industry-Wide Risk
One legacy portal without multi-factor authentication. Nine quiet days. Then a third of American healthcare stopped being able to pay for itself, 190 million people's medical data left, and a $22 million ransom was stolen by the ransomware gang from its own affiliate, who extorted again anyway.
Case type: Ransomware / critical infrastructure disruption
Identified: Feb 21, 2024 Disclosed: Feb 21, 2024
Attribution: ALPHV/BlackCat affiliate; second extortion via RansomHub
In late February 2024, pharmacists across America started telling patients the same thing: the system is down, and nobody knows when it's coming back. Prescriptions went cash-pay or went unfilled. Hospitals stopped being able to bill for care they were still providing. The cause wasn't at any of those pharmacies or hospitals. It was one company most patients had never heard of, and one login screen that never asked for a second factor.
The Change Healthcare breach is the largest healthcare data breach in history, roughly 190 million people, nearly six in ten Americans, and the most disruptive cyberattack ever to hit US critical infrastructure. It is also this series' finale for a reason: nearly every failure the series has cataloged converges here. The single missing basic from the Snowflake campaign. The quiet dwell time that priced M&S. The catastrophic concentration of MOVEit and CDK. The manual weeks of MGM. And the definitive last word on paying, because the $22 million ransom was stolen by the ransomware brand from its own affiliate, who still had the data, and extorted again.
UnitedHealth Group acquired Change Healthcare in October 2022, adding the clearinghouse that processes roughly 15 billion transactions a year, claims, eligibility checks, prescriptions, payments, to its Optum division. Sixteen months later, a Citrix remote access portal in the Change environment still hadn't been brought under the parent's security standards. It faced the internet, it accepted a username and password, and it did not require multi-factor authentication. In congressional testimony, CEO Andrew Witty acknowledged both facts, and that the security integration of the acquired company had lagged.
On February 12, 2024, someone logged into that portal with a Change support employee's compromised credentials. How the credentials were obtained has never been determined, phishing and infostealer malware are the usual suspects, and the distinction barely matters: with no second factor, the password was the whole perimeter. For the next nine days the intruders moved laterally through Change's network, escalating access and exfiltrating roughly four terabytes of data, the records that would eventually be counted at 190 million people, without triggering detection. On the morning of February 21, they ended the quiet phase themselves: ALPHV/BlackCat ransomware began encrypting Change's systems.
Change responded by disconnecting its own data centers, and that containment decision worked as designed: the encryption never spread beyond Change's network into the rest of UnitedHealth. But Change's network was the point. The clearinghouse stopped, and with it, a staggering share of the machinery that moves money and prescriptions through American healthcare. A March survey by the American Hospital Association found 74 percent of hospitals reporting direct patient care impacts and 94 percent reporting financial harm, with a third saying more than half their revenue was disrupted. Practices ran toward payroll failure while claims sat frozen. UnitedHealth began emergency advances to providers that passed $6 billion within months. And patients, the least consulted parties in the whole system, paid cash for insulin or walked away from pharmacy counters empty-handed.
The smallest control, the largest consequence
Strip the incident to its causal chain and it is almost insultingly short: a stolen password, a login page that asked for nothing else, and nine days of silence. Every dollar of the multi-billion cost, every frozen claim, every patient at a pharmacy counter traces back through that chain. The security industry spends enormous energy on sophisticated threats, and the most disruptive attack on American critical infrastructure to date required none: it required a basic control to be absent in exactly one place that mattered.
One login without MFA stood between the internet and a third of American healthcare.
The place it was absent is the sharper lesson. The portal wasn't overlooked in some forgotten corner; it was inherited, part of an acquired company whose security integration was still incomplete sixteen months after closing. Mergers buy attack surface along with revenue, and the acquired environment, older, less documented, built to different standards, stays exactly as secure as it was on closing day until someone makes it otherwise. Due diligence that prices the revenue but not the remediation timeline is how a Fortune 5 company ends up with a password-only door into its most systemically important subsidiary.
$22 million bought a lesson, not a deletion
This series has now covered every posture toward extortion: Caesars paid quietly, MGM and Co-op refused publicly, M&S went silent, CDK's payment was traced but never confirmed. Change Healthcare's payment is the one with a verdict, because everything about it failed observably. The $22 million went to ALPHV's leadership, who promptly staged an exit scam and vanished, stiffing the affiliate who had actually done the intrusion. The affiliate, unpaid and still holding all four terabytes, took the data to a successor operation and extorted again, and patient data reached leak sites anyway. The transaction exposed what a ransom actually purchases: a promise, from a criminal marketplace with no enforcement mechanism, whose participants defraud each other as readily as their victims. Witty called authorizing it one of the hardest decisions of his career, and it may well have been the right call on the information he had. The record it created is the strongest argument any future victim will have for why it isn't.
Not one decision. A set of conditions.
The conditions here read like this series' index, gathered into one incident:
Cyber risk, measured in prescriptions
Healthcare is where this series' subject stops being abstract. The outage's units weren't records or dollars first; they were medically necessary authorizations delayed at three-quarters of surveyed hospitals, independent pharmacies fronting the cost of medications on trust, practices weeks from missing payroll for clinicians still seeing patients, and people rationing or skipping medication over a payment system they'd never heard of. The 190 million records now permanently in circulation carry diagnoses, treatments, and Social Security numbers, the kind of data that, as the 23andMe post put it, cannot be reset. When the systems that move care stop, the risk lands on bodies. That is the standard to which healthcare infrastructure security should be held, and the standard this incident failed.
"The Basics Scale."
The Change Healthcare breach closes this series because it contains it. The missing multi-factor authentication from the Snowflake campaign. The quiet dwell that priced M&S. The concentration that turned MOVEit's and CDK's vendors into everyone's problem. The manual weeks and continuity math of MGM. The vendor-inherited attack surface of Caesars and Harrods, here in acquisition form. And the final word on ransoms, written by the criminals themselves when they stole the payment from each other and leaked the data anyway. Every one of those failures was ordinary. Together, at the center of American healthcare, they produced the most consequential cyberattack in the country's history.
The lesson of eighteen months of breach analysis is not that attackers are extraordinary. It is that basics compound: every missing control multiplies through concentration, dwell time, and dependence until a password becomes a national event. Organizations don't get to choose whether they hold single points of failure. They choose whether anyone has named them, hardened them, and rehearsed their loss, before the login that tests it. In every incident this series has covered, that choice was made in advance, by default or by design. It always is.
BECAUSE THE BIGGEST BREACH IN HEALTHCARE HISTORY NEEDED ONLY THE SMALLEST MISSING CONTROL.
Sources
BleepingComputer, "Change Healthcare hacked using stolen Citrix account with no MFA," April 30, 2024: https://www.bleepingcomputer.com/news/security/change-healthcare-hacked-using-stolen-citrix-account-with-no-mfa/
TechTarget, "Change Healthcare breached via Citrix portal with no MFA," April 30, 2024: https://www.techtarget.com/searchsecurity/news/366582824/Change-Healthcare-breached-via-Citrix-portal-with-no-MFA
The HIPAA Journal, "Change Healthcare Responding to Cyberattack," February 19, 2025: https://www.hipaajournal.com/change-healthcare-responding-to-cyberattack/


Comments