UnitedHealth has confirmed that over 100 million people were affected by the data breach (personal and medical) resulting from the Change Healthcare ransomware attack. As a result, it is the largest healthcare data breach in recent years.

In May, UnitedHealth CEO Andrew Wittywarned that “perhaps a third” of Americans’ health data was exposed in the attack.
A month later, Change Healthcare published a breach , warning that the ransomware attack exposed a “significant amount of data” for a significant percentage of American citizens.
See also: Transak hit by serious data breach
Yesterday, the data breach portal of the Office for Civil Rights (OCR) of the US Department of Health and Human Services reported that the total number of victims finally reached 100 million.
“On October 22, 2024, Change Healthcare notified OCR that approximately 100 million individual notifications had been sent regarding this breach,” reads an updated FAQ on the OCR website.
Data breach notifications sent by Change Healthcare, from June, report that a huge amount of sensitive information was stolen during the February ransomware attack:
- Health insurance information
- Health information (such as medical record numbers, providers, diagnoses, medications, test results, images, care and treatment).
- Billing and payment information (such as account, billing codes, payment cards, financial and banking information, payments made and balance due).
- Other personal information, such as social security numbers, driver's license or ID numbers, or passport numbers.
The information exposed in the Change Healthcare data breach may be different for each individual. Also, the medical history of all victims was not disclosed.
See also: Internet Archive hacked again via stolen authentication tokens
Change Healthcare: Ransomware attack
This data breach was caused by a attack that took place in February and affected UnitedHealth subsidiary Change Healthcare. The attack led to widespread outages in the US healthcare system.
The disruption in IT systems prevented doctors and pharmacies from doing their jobs effectively.
The BlackCat, also known as ALPHV, was behind this devastating attack, using stolen credentials to compromise the company's Citrix remote access service (it did not have multi-factor authentication enabled).
During the attack, hackers stole 6 TB of data and eventually encrypted the computers on the network.

UnitedHealth Group admitted to paying the ransom to unlock the files and delete the stolen data. The ransom payment was reportedly $22 million. However, associates of the ransomware gang claimed they still had the company’s data and had teamed up with a new ransomware operation (RansomHub). They then began publishing some of the stolen data, demanding additional payment.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The listing for Change Healthcare on the RansomHub data breach website disappeared a few days later, possibly indicating that United Health paid the ransom a second time.
See also: USDoD: Hacker behind National Public Data breach arrested
UnitedHealth said in April that the Change Healthcare ransomware attack caused $872 million in losses.
In conclusion, the Change Healthcare data breach serves as a wake-up call for all healthcare industry stakeholders to prioritize cybersecurity and continually evolve their defense strategies.
The consequences of a major breach can be many, making it imperative for organizations to invest in advanced security and have an effective incident response plan. With collaboration and vigilance from all parties involved, we can work to create a more secure environment for our personal and medical information.
Additionally, this incident highlights the need for ongoing education and training on cybersecurity best practices in the healthcare industry. There is also a need for stricter regulations and penalties for organizations that fail to protect sensitive data.
It is important to prioritize cybersecurity in the healthcare industry. This will protect patient data but also maintain trust between patients and healthcare providers.
Source: www.bleepingcomputer.com
