UnitedHealth Group and Change Healthcare: MSN

UnitedHealth Group and Change Healthcare: MSN

Cyberattack Disrupts Major U.S. Healthcare Network, Exposing Patient Data

A significant cyberattack has targeted Change Healthcare, a key subsidiary of UnitedHealth Group (UHG), crippling critical systems across the U.S. healthcare sector. The incident, first detected on February 21, 2024, forced the company to disconnect over 111 systems to contain the breach, disrupting prescription processing, insurance claims, and payment operations nationwide.

The attack, attributed to the BlackCat (ALPHV) ransomware group, exploited vulnerabilities in Change Healthcare’s infrastructure, leading to widespread outages. The disruption has left pharmacies, hospitals, and clinics unable to verify insurance coverage or process transactions, causing delays in patient care and financial strain on providers. Some healthcare facilities have resorted to manual workarounds, while others report cash flow shortages due to halted reimbursements.

UnitedHealth Group confirmed the breach stemmed from compromised credentials, though the full extent of data exposure remains under investigation. The incident has drawn scrutiny from U.S. lawmakers and regulators, including the Department of Health and Human Services (HHS), which is assessing compliance with HIPAA and potential risks to patient privacy. Early reports suggest sensitive data including medical records and personal information may have been accessed or exfiltrated.

The attack underscores the growing threat of ransomware to critical infrastructure, with healthcare increasingly targeted due to its reliance on interconnected digital systems. Change Healthcare processes 15 billion transactions annually, handling roughly one in three U.S. patient records, making this one of the most disruptive healthcare cyber incidents to date. Recovery efforts are ongoing, but the full impact on providers and patients is still unfolding.

Source: https://www.msn.com/en-ca/money/general/l3harris-names-insider-mehta-ceo-after-kubasik-exits-over-conduct-breach/ar-AA2ahRSg?ocid=finance-verthp-feeds

UnitedHealth Group TPRM report: https://www.rankiteo.com/company/unitedhealth-group

Change Healthcare TPRM report: https://www.rankiteo.com/company/change-healthcare

"id": "chauni1786986177",
"linkid": "change-healthcare, unitedhealth-group",
"type": "Ransomware",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Pharmacies, hospitals, clinics, '
                                              'and patients nationwide',
                        'industry': 'Healthcare',
                        'location': 'U.S.',
                        'name': 'Change Healthcare',
                        'type': 'Subsidiary'},
                       {'industry': 'Healthcare',
                        'location': 'U.S.',
                        'name': 'UnitedHealth Group (UHG)',
                        'type': 'Parent Company'}],
 'attack_vector': 'Compromised credentials',
 'data_breach': {'data_exfiltration': 'Possible',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Medical records, personal '
                                             'information'},
 'date_detected': '2024-02-21',
 'description': 'A significant cyberattack has targeted Change Healthcare, a '
                'key subsidiary of UnitedHealth Group (UHG), crippling '
                'critical systems across the U.S. healthcare sector. The '
                'incident forced the company to disconnect over 111 systems to '
                'contain the breach, disrupting prescription processing, '
                'insurance claims, and payment operations nationwide. The '
                'attack, attributed to the BlackCat (ALPHV) ransomware group, '
                'exploited vulnerabilities in Change Healthcare’s '
                'infrastructure, leading to widespread outages. The disruption '
                'has left pharmacies, hospitals, and clinics unable to verify '
                'insurance coverage or process transactions, causing delays in '
                'patient care and financial strain on providers.',
 'impact': {'data_compromised': 'Medical records and personal information',
            'identity_theft_risk': 'High',
            'operational_impact': 'Disrupted prescription processing, '
                                  'insurance claims, and payment operations '
                                  'nationwide; delays in patient care; '
                                  'financial strain on providers',
            'systems_affected': '111 systems disconnected'},
 'initial_access_broker': {'entry_point': 'Compromised credentials'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'root_causes': 'Compromised credentials'},
 'ransomware': {'data_exfiltration': 'Possible',
                'ransomware_strain': 'BlackCat (ALPHV)'},
 'regulatory_compliance': {'regulations_violated': 'HIPAA',
                           'regulatory_notifications': 'Department of Health '
                                                       'and Human Services '
                                                       '(HHS)'},
 'response': {'containment_measures': 'Disconnected over 111 systems',
              'recovery_measures': 'Ongoing'},
 'threat_actor': 'BlackCat (ALPHV)',
 'title': 'Cyberattack Disrupts Major U.S. Healthcare Network, Exposing '
          'Patient Data',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.