October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Change Healthcare Hackers Used Stolen Credentials to Access a Portal Without MFA, UHG CEO Said

UHG CEO Andrew Witty said attackers used compromised credentials to access a Change Healthcare Citrix portal without MFA, then moved laterally and deployed ransomware nine days later. Here’s what the disclosure establishes—and what it doesn’t.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Attackers entered a Change Healthcare remote-access portal using compromised credentials, and the portal did not require multifactor authentication (MFA), UnitedHealth Group CEO Andrew Witty told Congress in 2024. They moved through the network, took data and deployed ransomware on February 21—nine days after the access Witty described. His testimony identified a serious gap, but did not explain how the credentials were obtained or establish the full scope of the breach.

What UnitedHealth’s CEO disclosed

Andrew Witty, then CEO of UnitedHealth Group (UHG), described the intrusion in written testimony ahead of a May 1, 2024, Senate Finance Committee hearing. Change Healthcare, a major healthcare technology and payment-processing company, was part of UHG. Witty said attackers used compromised credentials to reach a Citrix remote-access portal that lacked MFA, then moved laterally, exfiltrated data and deployed ransomware. The committee hearing page links to his testimony; TechCrunch’s April 30 report summarizes the disclosure.

This was Witty’s account to lawmakers, not a detailed public forensic report. It establishes the access method he described, but not every step or system involved in the intrusion.

How the attack unfolded

Date or period What was publicly reported
Nine days before February 21, 2024 Witty said attackers gained access using compromised credentials. This interval places the access around February 12, but that date is inferred, not an independently confirmed timestamp.
Before February 21 Attackers moved laterally through the environment and exfiltrated data, according to Witty’s account. The public description does not establish when each action occurred.
February 21, 2024 Ransomware was deployed, prompting UHG’s containment response, including shutting down or disconnecting affected systems.
April 22, 2024 UHG shared preliminary findings about potentially affected information and reported restoration progress.
April 30–May 1, 2024 Witty’s written testimony was reported publicly on April 30; he appeared at the Senate Finance Committee hearing on May 1.
July 19, 2024 Change Healthcare filed an initial breach report with HHS’s Office for Civil Rights (OCR), listing 500 individuals while it continued determining the final number.

The nine-day interval is the time between the access and ransomware deployment described by Witty. It does not prove that the attackers had no earlier access, or that all malicious activity began on the inferred date.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What “stolen credentials” and “no MFA” mean

Credentials are not necessarily just a password

Credentials are information or devices used to prove identity—commonly a username and password, but potentially a token, certificate or other authentication material. “Compromised credentials” means attackers had valid authentication information accepted by the portal. Witty’s cited account did not say how they obtained it. Phishing, password reuse, malware, an insider and other explanations should not be treated as established facts.

When attackers sign in with valid credentials, their activity can resemble that of a legitimate user. That makes identity monitoring, device checks and review of unusual access important alongside defenses against software vulnerabilities.

MFA adds another barrier

MFA requires more than one kind of proof—for example, a password plus a hardware security key, passkey, authenticator approval or device-bound certificate. On a password-only portal, possession of the password may be enough to enter. In this incident, the absence of MFA removed an important barrier to using the compromised credentials; the public evidence does not establish that MFA would certainly have stopped the attack.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Not all second factors offer equal resistance to attack. SMS codes may be exposed to interception or SIM swapping; push approvals can be abused through repeated prompts; and one-time codes can be phished. Phishing-resistant methods such as FIDO2 security keys and passkeys can provide stronger protection, while conditional access can also consider device health, location and login risk. MFA still cannot by itself address every threat, including session-token theft, account-recovery abuse or weaknesses elsewhere in a network.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Citrix was the access route, not a proven software flaw

Citrix technology can give employees and contractors remote access to internal applications or desktops. The public account describes attackers using credentials at a Citrix portal without MFA; it does not say they exploited a Citrix software vulnerability. The distinction matters: the disclosed failure concerned the portal’s access controls, not proof that Citrix itself caused the breach.

What is known—and unknown—about exposed data

In an April 22, 2024, update, UHG said preliminary sampling found files containing protected health information (PHI) and personally identifiable information (PII) that could cover a substantial proportion of people in America. The company also said it had not seen evidence at that point that doctors’ charts or full medical histories had been exfiltrated. Those were preliminary, time-limited company statements, not a final inventory of affected information. UHG’s update gives its wording and status figures.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

HHS’s OCR FAQ, updated March 14, 2025, says Change Healthcare’s July 19, 2024, initial breach report listed 500 individuals—the minimum threshold for posting—while the company was still determining the final number. That initial filing should not be mistaken for the eventual total. The FAQ does not establish a final affected-person count, and the preliminary UHG statement does not prove that every person’s full medical record was taken. HHS’s FAQ describes the report and the agency’s response.

Why the disruption reached providers and patients

Change Healthcare processed transactions connecting healthcare providers, pharmacies and payers. When its systems were taken offline or disrupted, the effects reached beyond UHG’s own network: claims and payment processing, pharmacy transactions, eligibility checks and authorizations were affected. The incident showed how reliance on a major intermediary can turn one company’s cyberattack into a business-continuity problem across healthcare.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In its April 22, 2024, update, UHG said pharmacy services were near normal, with 99% of pre-incident pharmacies able to process claims; medical claims were flowing at near-normal levels; payment processing was at about 86% of pre-incident levels; and about 80% of Change Healthcare functionality had been restored on major platforms. UHG also said its payment-processing operations represented about 6% of U.S. healthcare payments. These are company-reported measures for that date, not independent audits or permanent figures. TechCrunch reported that Change processed claims for around half of U.S. residents; that figure is attributed reporting, not a government-certified market-share measure.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

UHG confirmed paying a ransom, and Witty later told the Senate Finance Committee the decision was his, according to TechCrunch. The report also said another extortion group, RansomHub, later claimed to possess stolen data. A payment does not prove that attackers deleted copies, that data will not be published, or that systems will be restored. Those outcomes cannot be inferred from the fact of payment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Regulatory oversight and breach notification

HHS OCR opened investigations into Change Healthcare and UHG concerning whether a breach of unsecured PHI occurred and whether the companies complied with HIPAA. An investigation is not a finding of wrongdoing. The HHS FAQ explains the investigation and notification framework.

Under HIPAA, covered entities generally must notify affected individuals and HHS after a reportable breach, and in certain cases notify the media. A business associate must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovering a breach. A covered entity can delegate notification work to a business associate, but the notification responsibility still has to be met. Healthcare organizations that used Change therefore needed to determine whether their own patients’ information was involved and clarify notification responsibilities under their contracts and response plans.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

Security lessons for healthcare organizations

The specific disclosure is a reminder that “we use MFA” is not a useful assurance unless the organization knows which accounts and systems are covered. HHS’s HIPAA risk-analysis guidance can help organizations assess where electronic PHI is stored, accessed and exposed.

Close identity and remote-access gaps

  • Inventory every internet-facing portal, remote desktop or virtual desktop system, vendor connection and administrative interface—including legacy systems.
  • Require MFA for workforce, contractor and privileged access; review service, emergency and break-glass accounts separately rather than assuming standard enrollment covers them.
  • Prefer phishing-resistant authentication for high-risk users and systems where feasible, and protect account recovery and help-desk reset processes.
  • Remove stale accounts, eliminate shared accounts where possible, and limit each identity to the access it needs.

Limit what a successful login can reach

  • Use conditional-access policies and device-trust checks to evaluate whether a login comes from an expected, managed device and whether its context is unusual.
  • Segment critical systems, separate administrative accounts and use time-limited or just-in-time privilege where practical.
  • Restrict remote-management tools and monitor for unusual internal movement, large data staging or unexpected outbound transfers.
  • Retain logs that allow investigators to reconstruct identity, privilege and data-access activity.

Prepare to operate during an outage

  • Test alternate workflows for claims, pharmacy transactions, eligibility checks and authorizations before a third-party service is unavailable.
  • Maintain immutable or offline backups and test recovery, not just backup creation.
  • Set incident-response responsibilities and patient-notification roles in advance, including how vendors will report incidents and provide affected-data information.

These measures reduce different parts of the risk; no single control guarantees that ransomware or data theft will be prevented. The central lesson is that a password-only remote portal can turn compromised credentials into an entry point, while the resulting impact depends on what attackers can reach, whether their activity is detected, and how well essential services can continue.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.