October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

UnitedHealth Paid a $22 Million Ransom After the Change Healthcare Cyberattack—What Was Confirmed

UnitedHealth did pay approximately $22 million after the Change Healthcare ransomware attack, but the payment did not guarantee deletion of stolen data or end the healthcare, regulatory and patient-impact fallout.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. UnitedHealth Group paid approximately $22 million in Bitcoin after the February 2024 ransomware attack on its Change Healthcare subsidiary. CEO Andrew Witty later told Congress that he personally authorized the payment, saying the priority was protecting patients’ personal health information. The attacker identified itself as ALPHV/BlackCat, also known in government descriptions as Noberus. The payment did not prove that stolen data was deleted, end the investigation, or immediately restore healthcare services.

What is confirmed about the $22 million payment?

Early reports used blockchain analysis, cybercrime-forum posts and reporting to connect a roughly 350-Bitcoin transaction—valued at about $22 million at the time—to the Change Healthcare attack. UnitedHealth subsequently acknowledged that a ransom had been paid. On May 1, 2024, Witty confirmed under oath that he made the decision to pay. His testimony is the clearest public confirmation of the payment: Senate testimony by Andrew Witty.

That confirmation does not establish that UnitedHealth paid a particular individual or that the money went directly to the core leadership of ALPHV/BlackCat. The transaction was associated with an address linked to the ransomware operation, which used affiliates to carry out intrusions.

Who carried out the attack?

Change Healthcare said the intruder represented itself as ALPHV/BlackCat. The Congressional Research Service described BlackCat/ALPHV as a Russia-linked cybercrime organization that claimed responsibility: CRS report IN12330.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“ALPHV hacked Change Healthcare” is therefore too simple. Ransomware-as-a-service operations typically separate the central developers or administrators from affiliates who obtain access, steal data and deploy malware. The evidence supports saying that an actor claiming to be ALPHV/BlackCat was behind the attack, while the specific people who breached the network and the people who controlled the payment may not have been identical.

Change Healthcare attack timeline

  1. February 12, 2024: According to Witty’s testimony, attackers used compromised credentials to enter a Change Healthcare Citrix remote-access portal. The portal did not have multifactor authentication enabled.
  2. February 21, 2024: Ransomware was deployed and the intrusion was discovered. Change isolated affected systems and disconnected additional systems to contain the attack. UnitedHealth disclosed the incident in an SEC filing.
  3. March 1, 2024: Blockchain reporting linked a 350-Bitcoin payment to a Bitcoin address associated with the ransomware operation.
  4. April 22, 2024: UnitedHealth said its preliminary review had found files containing protected health information (PHI) and personally identifiable information (PII). It also reported that 22 screenshots allegedly taken from exfiltrated files had appeared on the dark web for about a week.
  5. May 1, 2024: Witty testified to Congress that he personally authorized the ransom payment.

The dates describe different stages—initial access, ransomware deployment, payment, data review and public confirmation—not one single event.

Why did UnitedHealth pay?

Witty said the decision was made primarily to protect personal health information. In a crisis affecting claims, prescriptions and provider payments, management also faced pressure to restore operations and limit prolonged disruption.

A ransom payment is a crisis trade-off, not a guaranteed purchase of safety:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Reasons companies cite for paying: possible decryption keys, reduced pressure to publish stolen data, faster recovery and avoidance of extended patient-care or cash-flow disruption.
  • Reasons against paying: it finances criminal groups, may encourage further attacks, can create sanctions or legal issues, and does not guarantee that data will be deleted or that every participant will honor an agreement.

UnitedHealth’s choice does not prove that paying was either obviously rational or obviously reckless. It shows the practical conflict between immediate healthcare continuity and the long-term harm of funding extortion.

Was the money paid to BlackCat or an affiliate?

Public reporting tied the Bitcoin to an ALPHV/BlackCat-associated address, but the organization was not a transparent company with a published payment ledger. A purported affiliate later alleged that the central group kept the ransom instead of paying the affiliate’s share. That dispute is described in a congressional memorandum and remains an attributed claim, not a fully established accounting.

The most accurate description is that UnitedHealth paid approximately $22 million in connection with the attack to an address associated with the ALPHV/BlackCat operation. The public record does not prove which operators ultimately controlled or received all of the funds.

Why one attack disrupted healthcare nationwide

Change Healthcare operates between providers, insurers, pharmacies and payment systems. Its services support claims transmission, eligibility checks, pharmacy transactions and payments. UnitedHealth said in its April 22 update that Change handled about 6% of U.S. healthcare payments. At that point, payment processing had recovered to approximately 86% of pre-incident levels and pharmacy processing to 99%; those were recovery measurements for that update, not permanent market-share figures: UnitedHealth’s April 22 update.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Because so many organizations depended on the intermediary, the outage produced effects beyond UnitedHealth itself:

  • pharmacies struggled to process prescriptions and insurance claims;
  • providers used manual claims and payment workarounds;
  • eligibility verification became harder or slower;
  • medical practices and pharmacies faced delayed reimbursement and cash-flow pressure;
  • patients encountered problems obtaining medicines or confirming coverage.

The incident exposed concentration risk: a single technology provider can become a bottleneck for a large part of the healthcare payment system.

What data was exposed?

UnitedHealth’s initial targeted sampling found files containing PHI and PII. The company said it had not seen evidence at that stage that doctors’ charts or full medical histories had been exfiltrated. That was a preliminary finding, not proof that no medical information was exposed.

These terms describe different things and should not be treated as interchangeable:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Files observed or sampled: material investigators examined directly.
  • People potentially affected: individuals whose information may have been present in compromised systems.
  • People notified: individuals for whom notification obligations were triggered.
  • Specific data elements confirmed: the particular identifiers or health information tied to a person.
  • Data published or misused: information proven to have been posted or used for fraud.

The latest official figure identified from the Department of Health and Human Services was approximately 192.7 million affected individuals, reported by Change Healthcare to the HHS Office for Civil Rights on July 31, 2025. That later figure should not be backdated to the February 2024 ransom reports. HHS explains the reporting figure and its HIPAA investigation on its Change Healthcare cybersecurity incident FAQ.

Did paying the ransom make the stolen data disappear?

No reliable public evidence proves that every copy of the stolen information was deleted. UnitedHealth said 22 screenshots allegedly from exfiltrated files, some containing PHI and PII, had been posted on the dark web for approximately a week as of April 22, 2024. It said no further publication of PHI or PII had occurred “at this time,” while continuing to monitor the situation.

Later, RansomHub reportedly claimed to possess Change Healthcare data. A congressional memorandum noted the claim but did not confirm whether UnitedHealth paid RansomHub a second ransom. Such claims should remain allegations.

Even when an attacker supplies a decryption tool or promises deletion, a victim generally cannot verify that all copies, backups, screenshots or affiliate-held archives are gone. Payment also cannot stop another criminal group from reposting or reusing data.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What security weakness allowed the intrusion?

Witty testified that compromised credentials were used against a Citrix portal without multifactor authentication. Attackers then moved laterally, exfiltrated data and deployed ransomware. The missing MFA was a major identified control failure, but it was not the entire causal chain.

  • credential protection and privileged-account controls;
  • remote-access configuration;
  • network segmentation that limits lateral movement;
  • monitoring and response speed;
  • backup isolation and restoration testing;
  • governance of subsidiaries, vendors and concentrated infrastructure.

Adding MFA would reduce exposure to stolen passwords, but it cannot by itself solve weak segmentation, excessive privileges or inadequate detection.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Financial and regulatory consequences

The ransom was only one cost. The Congressional Research Service reported that UnitedHealth estimated the incident could cost more than $1.5 billion, including response and broader business consequences: CRS analysis.

That total can include system restoration, incident-response specialists, provider financial assistance, delayed or lost revenue, legal work, patient notification, credit-monitoring services, litigation and regulatory compliance. It should not be confused with the $22 million payment itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

HHS’s Office for Civil Rights opened investigations into whether a breach of PHI occurred and whether Change Healthcare and UnitedHealth complied with HIPAA requirements. Restoring systems therefore did not end notification, remediation or regulatory duties.

What patients and providers should do

Not everyone who used a pharmacy, insurer or provider connected to Change Healthcare was necessarily affected. Use official notification and support channels, not links in unsolicited messages.

  • Review health-insurance explanation-of-benefits statements for unfamiliar claims, providers, diagnoses or prescriptions.
  • Be cautious with unexpected calls, emails or texts requesting insurance, payment or identity information.
  • Ask a provider whether its records or billing transactions were included in a breach notification.
  • Use credit monitoring or identity-theft protection when it is officially offered or when your information is confirmed affected.
  • Keep copies of breach notices and report suspected medical-identity theft promptly to the relevant insurer or provider.

What this incident means for ransomware policy

The case illustrates why a ransom decision cannot be evaluated only by asking whether systems came back online. Paying may support an urgent recovery effort, yet still leave stolen data, affiliate disputes, regulatory exposure and patient harm unresolved. Refusing to pay may avoid funding criminals, but it can prolong outages in an interconnected healthcare system.

For healthcare organizations, the practical lessons are stronger remote-access authentication, segmented networks, tightly controlled privileged accounts, isolated and tested backups, rapid breach assessment and contingency plans for manual claims and payment processing. For policymakers, the incident raises questions about ransomware economics, reporting rules and the resilience of highly concentrated healthcare intermediaries.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.