EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/ransomware-attack/change-healthcare-attack
113/430

File EL-0318CriticalResolvedRansomware Attack / Critical Infrastructure Cyberattack

Change Healthcare Attack

Also filed as UnitedHealth Group Ransomware Attack · UHG Ransomware Incident

The attack targeted Change Healthcare, a critical payment processing arm of UnitedHealth Group, causing massive disruption to the U.S. healthcare payment system. The ransomware group ALPHV/BlackCat encrypted core systems, leading to widespread service outages for providers and payers nationwide. The incident highlighted the extreme systemic risk posed by single points of failure in critical infrastructure.

  • #ransomware
  • #healthcare
  • #change-healthcare
  • #unitedhealth-group
  • #alphv
  • #blackcat
Notoriety9/10
Event
21 Feb 2024
Disclosed
22 Feb 2024
Target
Change Healthcare
Actor
ALPHV / BlackCat
Scale
Unknown (estimated to be massive, covering core financial records)
Status
Resolved

01Summary

The ransomware attack, attributed to the ALPHV/BlackCat group, began around February 21, 2024, and severely crippled Change Healthcare's operational capabilities. Change Healthcare is a vital intermediary, handling billions of dollars in medical claims and payments across the U.S. The attackers utilized sophisticated methods to gain initial access and deploy their ransomware payload, encrypting critical databases and operational technology. The resulting outage forced hospitals, clinics, and payers to revert to manual, paper-based processes, causing significant delays in care and billing. The incident was a major blow to the stability of the U.S. healthcare financial ecosystem, leading to immediate federal and industry-wide scrutiny of cybersecurity resilience.

02Background

Change Healthcare plays an indispensable role in the American healthcare system, facilitating the complex financial transactions between providers and insurance payers. Its failure represents a systemic risk, as its services are relied upon for everything from billing to claims adjudication. Prior to the attack, the industry was already grappling with increasing cyber threats and the complexity of modern, interconnected digital payment systems.

03Key revelations

  1. 01The attack demonstrated the systemic fragility of the U.S. healthcare payment infrastructure.
  2. 02The incident forced a massive, unplanned shift back to manual, paper-based processes across thousands of providers.
  3. 03It triggered immediate federal and state-level calls for mandatory cybersecurity standards in critical infrastructure.

04Technical analysis

The attack vector is believed to have involved exploiting a vulnerability or compromised credentials, allowing the threat actors to establish a foothold within the network. The ransomware payload, associated with ALPHV/BlackCat, was deployed to encrypt data, effectively locking out legitimate users. The attackers likely utilized lateral movement techniques to maximize the scope of the encryption, targeting core payment processing and claims management systems.

Attack vector
Compromised credentials or exploited vulnerability (specific details remain under investigation)
Attack method
Ransomware deployment and data encryption
Initial access
Compromised credentials or supply chain vector
Lateral movement
Internal network traversal and privilege escalation
Persistence
Backdoors or scheduled tasks (unconfirmed)
Exfiltration
Data exfiltration (potential double extortion tactic)
Tool / malware
ALPHV Ransomware
Malware family
ALPHV
Malware type
Ransomware

MITRE ATT&CK techniques

  • T1562.001
  • T1071.001
  • T1486

05Threat actor

ALPHV/BlackCat is a highly sophisticated, financially motivated ransomware group known for its Ransomware-as-a-Service (RaaS) model. They are noted for their aggressive tactics, including double extortion (data theft and encryption), and targeting large, complex organizations in critical sectors.

Aliases

  • BlackCat
  • ALPHV

MITRE groups

  • T1486
  • T1071.001
  • T1562.001

Attribution sources

  • FBI
  • CISA
  • Industry Security Reports

06Victims and impact

Additional victims

  • UnitedHealth Group
  • Thousands of healthcare providers and payers

Countries affected

  • United States

07Data exposed

Data types

  • Financial records
  • Claims data
  • PII
  • Operational data

Notable documents

  • Internal operational reports (unavailable)
  • Claims processing databases (encrypted)

08Financial damage

The cost includes operational downtime, manual processing costs, and potential long-term systemic damage to the healthcare economy.

09Timeline

  1. 2024-02-21Ransomware attack begins, disrupting Change Healthcare's core services.
  2. 2024-02-22The public is first notified of the massive service outage and operational failure.
  3. 2024-03-15Major systems are reported as partially restored, marking the end of the acute crisis phase.

10Key figures

  • UnitedHealth GroupParent Corporation · UnitedHealth GroupAmericanManaged crisis response and recovery efforts.

11On the record

The disruption to Change Healthcare was unprecedented, affecting the core financial arteries of American healthcare.

Industry Analysts, Describing the systemic impact of the ransomware attack.

12Reaction and fallout

Public reaction

The public reaction was characterized by immediate concern over medical care continuity, with reports of delayed prescriptions and billing issues. Healthcare providers expressed frustration over the lack of immediate, reliable payment processing.

Political impact

The attack led to intense political pressure on federal regulators (CMS, HHS) to mandate stricter cybersecurity standards and improve resilience across the entire healthcare supply chain. It fueled bipartisan calls for federal intervention in critical infrastructure security.

Geopolitical consequences

The incident highlighted the vulnerability of Western economies to sophisticated, financially motivated cyberattacks, prompting increased international dialogue on cyber resilience standards.

13Legal

While no immediate criminal charges were publicly announced against the perpetrators, the incident triggered multiple investigations by federal agencies (DOJ, FBI) into the nature and scope of the attack.

Civil lawsuits

  • Class action lawsuits filed by affected providers and payers seeking damages for operational downtime and financial losses.

14Aftermath

Policy changes

  • Increased focus on mandatory cybersecurity standards for healthcare payment processors.
  • Potential federal mandates for operational redundancy and manual fallback procedures.

Regulatory changes

  • Heightened scrutiny from CMS and HHS regarding vendor risk management and cyber resilience.

Security improvements

  • Accelerated adoption of Zero Trust Architecture (ZTA) within healthcare IT systems.
  • Mandatory segmentation of critical payment processing networks.

15Significance and legacy

Significance

This attack is historically significant because it demonstrated that a single, private-sector technology vendor could become a critical single point of failure for an entire national industry. It shifted the conversation from merely 'data theft' to 'systemic operational collapse' in critical infrastructure.

Legacy

The legacy of the Change Healthcare attack is a permanent elevation of cybersecurity risk in healthcare from an IT concern to a national security and public health emergency. It has accelerated investment in resilient, decentralized, and redundant payment processing systems.

16Disclosure and media

Authentication
Industry consensus and government reports

Media partners

  • Reuters
  • The Wall Street Journal
  • Bloomberg

Publishing organisations

  • FBI
  • CISA

17Related files

Related events

  • Colonial Pipeline Ransomware Attack

Inspired by

  • columbia-aqueduct-attack

18Field notes

  1. 01The manual fallback process required staff to use paper forms and physical checks, a procedure largely considered obsolete in modern healthcare finance.
  2. 02The incident led to temporary, localized slowdowns in prescription fulfillment and medical billing across multiple states.

19Resolution

Recovery involved a multi-phased effort, including the establishment of temporary manual processing centers and the eventual rebuilding of core systems, though full normalization of services took months.

20Sources

Official documents

  • CISA Advisories on Healthcare Ransomware
  • HHS/CMS Operational Guidance Post-Incident

References

  1. [1]Reuters reporting on UHG/Change Healthcare
  2. [2]CISA alerts regarding ransomware threats
  3. [3]The Wall Street Journal coverage of healthcare disruption
Fact sheetEL-0318

Dates

Event
21 Feb 2024
Started
21 Feb 2024
Ended
15 Mar 2024
Duration
22 days
Discovered
21 Feb 2024
Disclosed
22 Feb 2024
Resolved
15 Mar 2024
Ongoing
No

Target

Organisation
Change Healthcare
Type
Technology Company
Sector
Healthcare Payment Processing
Country
United States

Actor

Name
ALPHV / BlackCat
Type
Ransomware Gang
Motivation
Financial extortion through data encryption and service disruption.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Unknown (estimated to be massive, covering core financial records)
Sensitivity
Top Secret
Published
No

Money

Crypto
Bitcoin or Monero (typical for ransomware)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.