Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Change Healthcare Ransomware Attack: What the HIPAA Investigation Found—and What It Didn’t

The Change Healthcare ransomware attack disrupted claims, pharmacy transactions and payments nationwide. OCR opened a HIPAA investigation—not a finding of wrongdoing—and HHS later reported about 192.7 million affected individuals.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The February 2024 ransomware attack on Change Healthcare disrupted claims, pharmacy transactions and payments across the United States. On March 13, 2024, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) opened an investigation into whether protected health information was breached and whether Change Healthcare and its parent, UnitedHealth Group, complied with HIPAA. The announcement opened an investigation; it did not find that either company violated the law.

The incident also exposed a personal-finance problem for patients and providers: when a central claims processor goes offline, practices can struggle to collect revenue, pharmacies can face prescription-processing delays, and patients may have difficulty obtaining care or medication. HHS later reported that Change Healthcare told OCR about 192.7 million affected individuals—a 2025 estimate, not information available when the investigation began.

What happened to Change Healthcare?

Change Healthcare was a UnitedHealth Group subsidiary that handled electronic claims and payment transactions connecting providers, insurers, pharmacies and other parts of the health-care system. It was not simply an insurer or a hospital’s internal IT provider. The disruption showed how an intermediary that processes transactions for many organizations can become a point of systemic risk.

A 2022 Department of Justice antitrust complaint alleged that about half of U.S. medical claims passed through Change Healthcare’s electronic data-interchange clearinghouse. That figure is an allegation in litigation, not an independently verified current market-share measure. Ars Technica’s contemporaneous report discusses the allegation and the attack.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Key dates

  • February 21, 2024: UnitedHealth disclosed that Change Healthcare systems were experiencing a cyberattack.
  • Late February: Systems were taken offline, disrupting claims and payment functions.
  • February 29: UnitedHealth attributed the attack to the ransomware operation AlphV, also known as BlackCat. This is the company’s attribution.
  • March 6–15: Federal agencies announced emergency measures as providers faced difficulty submitting claims and receiving payment.
  • March 13: OCR announced its HIPAA investigation.
  • July 19: Change Healthcare filed a breach report with OCR, according to HHS.
  • October 2024–July 2025: The reported estimate of affected individuals increased over time.
  • July 31, 2025: Change Healthcare notified OCR that approximately 192.7 million individuals had been affected, according to HHS.

Sources: Ars Technica and HHS OCR’s incident FAQ.

What did OCR investigate?

OCR said it would examine whether a breach of protected health information (PHI) occurred and whether Change Healthcare and UnitedHealth Group complied with the HIPAA Privacy, Security and Breach Notification Rules. The March 13, 2024, OCR letter described the investigation as a response to the incident’s unprecedented scale and impact on patient care and health-care operations.

An investigation is not a finding of liability. A ransomware attack and a HIPAA violation are not interchangeable: an organization can suffer an attack despite having safeguards, while an enforcement case would turn on whether it met applicable legal duties. HIPAA requires safeguards and processes; it does not guarantee that a breach will never occur.

How the HIPAA rules differ

  • Privacy Rule: Sets limits on uses and disclosures of PHI.
  • Security Rule: Requires covered entities and business associates to protect electronic PHI with administrative, physical and technical safeguards.
  • Breach Notification Rule: Governs notice after an impermissible use or disclosure of unsecured PHI.

Which organizations can have responsibilities?

Change Healthcare’s HIPAA role could vary by service and relationship: it may act as a covered entity, a business associate, or both. UnitedHealth Group and affiliated entities can have their own or overlapping duties. Hospitals, health plans, pharmacies and other affected organizations may also have obligations under HIPAA, including maintaining appropriate business-associate agreements and making required breach notifications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OCR said its primary investigative focus was Change Healthcare and UnitedHealth Group; its interest in other organizations connected to the incident was secondary. The fact that a vendor is involved does not automatically remove a covered entity’s own compliance responsibilities.

Why did the outage affect care and providers’ finances?

Claims processing is part of a provider’s revenue cycle: a practice provides care, submits a claim, and waits for payment. When a major transaction processor is unavailable, providers may have trouble sending claims or receiving payments even if their own clinical systems still work. Pharmacies also experienced prescription-processing problems, and some patients had difficulty obtaining medication or care.

Delayed collections can put pressure on payroll, rent and other bills, with smaller practices and community providers particularly exposed to cash-flow gaps. The outage also forced organizations to consider alternate clearinghouses, paper claims, payer-specific arrangements and manual workarounds. Those options can take time and staff to activate, and they are not equivalent to normal high-volume electronic processing.

CMS said the attack affected physicians and other providers, with particular concern for small practices and community-based providers. It directed Medicare contractors to provide information about switching clearinghouses and accepting paper claims where necessary. See CMS’s statement on the attack and its statement on continued response measures.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What emergency financial measures did the government offer?

CMS created the Change Healthcare/Optum Payment Disruption program to address claims-related cash-flow problems for eligible Medicare providers and suppliers. It offered accelerated payments to eligible Part A providers and advance payments to eligible Part B suppliers. These were temporary, repayable payments—not grants or a general bailout for every affected health-care organization.

Under the program’s terms, eligible payments could represent up to approximately 30 days of claims payments. CMS said repayment would generally occur through automatic recoupment from future Medicare claims over 90 days; any remaining balance would then be subject to demand. The details and eligibility limits are in CMS’s program fact sheet.

CMS later reported that it had made 4,722 Part B advance payments totaling more than $717.18 million and that the program would conclude on July 12, 2024. Those figures describe the Part B program, not all financial effects of the attack. CMS’s closure announcement provides the totals and end date.

For Medicaid and CHIP, CMS also issued guidance allowing states to use certain flexibilities and interim payments to help affected providers maintain operations. See the CMS guidance on state flexibilities. Emergency measures addressed cash-flow and administrative problems; they did not eliminate ordinary billing obligations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What can the investigation examine?

OCR’s public announcement did not identify a specific failed safeguard. Questions an investigation of this kind could examine include whether organizations assessed and managed risk, restricted access appropriately, monitored systems, responded to the incident, and met breach-notification duties. These are investigative questions, not claims that a particular control was absent at Change Healthcare or UnitedHealth.

  • Whether risk analyses covered critical systems and remote access, and whether identified risks were managed.
  • Whether access controls, including controls on privileged accounts, were appropriate.
  • Whether systems were monitored for unauthorized access and vulnerabilities were addressed in a timely way.
  • Whether network design, tested backups and recovery procedures supported restoration of critical services.
  • Whether incident-response and business-continuity plans addressed ransomware and the loss of a major transaction processor.
  • Whether business-associate relationships and oversight were appropriate and breach-notification decisions were timely and consistent.

The outage and the privacy investigation are separate issues: restoring transaction services would not, by itself, establish whether data-security or notification duties were met.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Was patient information stolen, and how many people were affected?

When OCR announced its investigation in March 2024, the full scope of data exposure was not known publicly. Change Healthcare later filed a breach report. HHS’s FAQ says the company notified OCR on July 31, 2025, that approximately 192.7 million individuals had been affected.

“Affected” is not the same as a confirmed count of people whose complete medical records were taken, nor is it a count of people who experienced identity theft or fraud. HHS’s reported figure does not establish that every individual’s full record was exfiltrated or misused. The public information cited here does not specify the exact data elements for every affected person or establish the extent of any resulting misuse. The estimate is a later reported development, not a number known when OCR opened its investigation. See HHS’s incident FAQ.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does the incident show about health-care concentration risk?

Organizations can maintain separate clinical networks and still depend on a small number of outside companies for claims, eligibility checks, pharmacy transactions or payments. An outage at one intermediary can therefore disrupt many otherwise independent providers. This is third-party risk even when the vendor does not deliver care directly: it may control a workflow that providers need to get paid or patients need to obtain services.

Continuity plans need to account for an unavailable intermediary, not only a malware incident inside one hospital. Alternate clearinghouses and paper procedures may be available but hard to activate at scale, particularly when many organizations seek alternatives at once. The episode also illustrates why vendor oversight, tested workarounds and contingency planning matter to financial operations as well as cybersecurity.

The Government Accountability Office described widespread effects on providers and patient care and estimated approximately $874 million in losses associated with the incident in its review of health-care cybersecurity leadership and response. That is GAO’s estimate of losses, not a measure of the breach’s full social or health impact. See GAO’s report.

What remains unresolved?

The sources cited here establish the investigation’s announced scope and the later reported impact estimate, but do not establish a final public OCR finding about HIPAA compliance. They also do not detail every data element involved, the extent of any misuse, or which safeguards were in place before the attack. A reported number of affected individuals should not be mistaken for a finding about individual harm or the legal outcome.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.