Immune — Self Heal, an iStudio Technologies product

Healthcare · United States · February 2024

Change Healthcare Ransomware Attack

The February 2024 ransomware attack on Change Healthcare disrupted medical claims and payments nationwide, affecting an estimated 100 million people and becoming one of the costliest healthcare cyberattacks on record.

What happened

In February 2024, Change Healthcare — a subsidiary of UnitedHealth Group's Optum and one of the largest processors of medical claims in the United States — was struck by a ransomware attack that would become one of the most disruptive cyber events the American healthcare system has ever experienced. Change Healthcare sits at the plumbing layer of U.S. healthcare, handling a very large share of the country's insurance claims, eligibility checks, and prescription transactions. When it went down, the effects rippled outward to hospitals, clinics, and pharmacies across the nation.

The attack was publicly attributed in reporting to the ALPHV/BlackCat ransomware operation, a prolific ransomware-as-a-service group. According to later testimony and public reporting, the attackers reportedly gained access using compromised remote-access credentials on a system that did not have multi-factor authentication enabled. Once inside, they moved through the environment before deploying ransomware and exfiltrating a very large volume of sensitive data.

On February 21, 2024, Change Healthcare took systems offline to contain the intrusion. That containment step — necessary as it was — meant that the services thousands of healthcare providers relied on simply stopped working. Pharmacies could not process claims. Providers could not verify insurance eligibility or submit bills. The disruption was immediate and national in scope.

The impact

The operational impact landed hardest on the providers downstream of Change Healthcare. Pharmacies were unable to run insurance claims, forcing patients to pay out of pocket or go without medication. Hospitals and physician practices, unable to submit claims for reimbursement, faced sudden and severe cash-flow crises — some reported burning through reserves within weeks as billions of dollars in payments stalled in the system.

The financial toll was extraordinary. UnitedHealth Group publicly disclosed that the total costs associated with the attack ran into the billions of dollars over the course of 2024, encompassing response, restoration, and financial assistance extended to struggling providers. A ransom payment of a reported US$22 million was also widely reported.

The data-exposure dimension may prove the most consequential over time. The breach was estimated to affect roughly 100 million individuals, making it one of the largest exposures of protected health information in U.S. history. The compromised data reportedly included health information, insurance details, and personal identifiers — the kind of information that fuels fraud and identity theft for years after the event.

Beyond the balance sheet, the incident exposed a structural fragility: when a single clearinghouse processes such a large fraction of a nation's healthcare transactions, its compromise becomes a systemic event rather than a single-company problem.

How the attack unfolded

  • Initial access: attackers reportedly used stolen remote-access credentials on a server that lacked multi-factor authentication — a foothold that looked like a legitimate login.
  • Reconnaissance and lateral movement: over a period of days, the intruders explored the environment and expanded access toward high-value systems.
  • Exfiltration: a very large volume of sensitive data was copied out before encryption — the hallmark of a double-extortion strategy.
  • Encryption and impact: ransomware was deployed, and Change Healthcare took systems offline to contain the spread, halting national claims and payment processing.

The recovery

Recovery was measured in weeks and months rather than hours. Change Healthcare rebuilt and restored systems in phases, prioritizing the most critical transaction services, while UnitedHealth extended financial assistance to providers left without income.

The prolonged restoration underscored a hard truth about ransomware in interconnected healthcare infrastructure: even with significant resources, bringing complex, deeply integrated systems back safely — and verifying them clean before reconnection — is slow and painstaking work.

How this attack could have been contained

The reported entry point — valid credentials on a system without multi-factor authentication — is exactly the scenario Immune's continuous access verification is designed to catch. Rather than trusting a login because the password was correct, Immune scores behavior continuously, so a credential suddenly reaching unusual systems is flagged even when the login itself looks legitimate.

The long dwell time before encryption is where resilience is won or lost. Immune's network monitoring and deception layer are built to surface the reconnaissance and lateral movement that precede encryption, and to raise a high-confidence alarm the moment an attacker touches a decoy — turning quiet dwell time into an early warning.

Where an attacker does reach the encryption stage, Immune's containment isolates the affected segment automatically and its self-healing recovery restores validated, immutable backups in a defined clinical order — the capability that turns a multi-week outage into a contained incident.

Sources

Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.

Protect against attacks like this

How to defend against healthcare ransomware

Don't let an attack become a shutdown

See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.

Talk to us

See Immune protect your organization

Tell us about your environment and our team will show you exactly how Immune detects, contains, and self-heals through a ransomware attack — including the connected devices your current tools can't reach. We respond within one business day.

  • A working demo on a realistic scenario
  • Agentless coverage for medical and connected devices
  • On-premises and data-sovereignty deployment options
  • A frank look at where Immune fits alongside your stack

Request your demo

Tell us a little about your organization and we'll be in touch.

By submitting, you agree to be contacted about Immune. We respect your privacy and never share your details. See our privacy policy.