The February 2024 ransomware attack on Change Healthcare disrupted claims, pharmacy transactions and payments across the United States. On March 13, 2024, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) opened an investigation into whether protected health information was breached and whether Change Healthcare and its parent, UnitedHealth Group, complied with HIPAA. The announcement opened an investigation; it did not find that either company violated the law.
The incident also exposed a personal-finance problem for patients and providers: when a central claims processor goes offline, practices can struggle to collect revenue, pharmacies can face prescription-processing delays, and patients may have difficulty obtaining care or medication. HHS later reported that Change Healthcare told OCR about 192.7 million affected individuals—a 2025 estimate, not information available when the investigation began.
What happened to Change Healthcare?
Change Healthcare was a UnitedHealth Group subsidiary that handled electronic claims and payment transactions connecting providers, insurers, pharmacies and other parts of the health-care system. It was not simply an insurer or a hospital’s internal IT provider. The disruption showed how an intermediary that processes transactions for many organizations can become a point of systemic risk.
A 2022 Department of Justice antitrust complaint alleged that about half of U.S. medical claims passed through Change Healthcare’s electronic data-interchange clearinghouse. That figure is an allegation in litigation, not an independently verified current market-share measure. Ars Technica’s contemporaneous report discusses the allegation and the attack.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
Key dates
- February 21, 2024: UnitedHealth disclosed that Change Healthcare systems were experiencing a cyberattack.
- Late February: Systems were taken offline, disrupting claims and payment functions.
- February 29: UnitedHealth attributed the attack to the ransomware operation AlphV, also known as BlackCat. This is the company’s attribution.
- March 6–15: Federal agencies announced emergency measures as providers faced difficulty submitting claims and receiving payment.
- March 13: OCR announced its HIPAA investigation.
- July 19: Change Healthcare filed a breach report with OCR, according to HHS.
- October 2024–July 2025: The reported estimate of affected individuals increased over time.
- July 31, 2025: Change Healthcare notified OCR that approximately 192.7 million individuals had been affected, according to HHS.
Sources: Ars Technica and HHS OCR’s incident FAQ.
What did OCR investigate?
OCR said it would examine whether a breach of protected health information (PHI) occurred and whether Change Healthcare and UnitedHealth Group complied with the HIPAA Privacy, Security and Breach Notification Rules. The March 13, 2024, OCR letter described the investigation as a response to the incident’s unprecedented scale and impact on patient care and health-care operations.
An investigation is not a finding of liability. A ransomware attack and a HIPAA violation are not interchangeable: an organization can suffer an attack despite having safeguards, while an enforcement case would turn on whether it met applicable legal duties. HIPAA requires safeguards and processes; it does not guarantee that a breach will never occur.
How the HIPAA rules differ
- Privacy Rule: Sets limits on uses and disclosures of PHI.
- Security Rule: Requires covered entities and business associates to protect electronic PHI with administrative, physical and technical safeguards.
- Breach Notification Rule: Governs notice after an impermissible use or disclosure of unsecured PHI.
Which organizations can have responsibilities?
Change Healthcare’s HIPAA role could vary by service and relationship: it may act as a covered entity, a business associate, or both. UnitedHealth Group and affiliated entities can have their own or overlapping duties. Hospitals, health plans, pharmacies and other affected organizations may also have obligations under HIPAA, including maintaining appropriate business-associate agreements and making required breach notifications.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #2
OCR said its primary investigative focus was Change Healthcare and UnitedHealth Group; its interest in other organizations connected to the incident was secondary. The fact that a vendor is involved does not automatically remove a covered entity’s own compliance responsibilities.
Why did the outage affect care and providers’ finances?
Claims processing is part of a provider’s revenue cycle: a practice provides care, submits a claim, and waits for payment. When a major transaction processor is unavailable, providers may have trouble sending claims or receiving payments even if their own clinical systems still work. Pharmacies also experienced prescription-processing problems, and some patients had difficulty obtaining medication or care.
Delayed collections can put pressure on payroll, rent and other bills, with smaller practices and community providers particularly exposed to cash-flow gaps. The outage also forced organizations to consider alternate clearinghouses, paper claims, payer-specific arrangements and manual workarounds. Those options can take time and staff to activate, and they are not equivalent to normal high-volume electronic processing.
CMS said the attack affected physicians and other providers, with particular concern for small practices and community-based providers. It directed Medicare contractors to provide information about switching clearinghouses and accepting paper claims where necessary. See CMS’s statement on the attack and its statement on continued response measures.
What emergency financial measures did the government offer?
CMS created the Change Healthcare/Optum Payment Disruption program to address claims-related cash-flow problems for eligible Medicare providers and suppliers. It offered accelerated payments to eligible Part A providers and advance payments to eligible Part B suppliers. These were temporary, repayable payments—not grants or a general bailout for every affected health-care organization.
Under the program’s terms, eligible payments could represent up to approximately 30 days of claims payments. CMS said repayment would generally occur through automatic recoupment from future Medicare claims over 90 days; any remaining balance would then be subject to demand. The details and eligibility limits are in CMS’s program fact sheet.
CMS later reported that it had made 4,722 Part B advance payments totaling more than $717.18 million and that the program would conclude on July 12, 2024. Those figures describe the Part B program, not all financial effects of the attack. CMS’s closure announcement provides the totals and end date.
For Medicaid and CHIP, CMS also issued guidance allowing states to use certain flexibilities and interim payments to help affected providers maintain operations. See the CMS guidance on state flexibilities. Emergency measures addressed cash-flow and administrative problems; they did not eliminate ordinary billing obligations.
Recommended Free Tools
Rank #4
What can the investigation examine?
OCR’s public announcement did not identify a specific failed safeguard. Questions an investigation of this kind could examine include whether organizations assessed and managed risk, restricted access appropriately, monitored systems, responded to the incident, and met breach-notification duties. These are investigative questions, not claims that a particular control was absent at Change Healthcare or UnitedHealth.
- Whether risk analyses covered critical systems and remote access, and whether identified risks were managed.
- Whether access controls, including controls on privileged accounts, were appropriate.
- Whether systems were monitored for unauthorized access and vulnerabilities were addressed in a timely way.
- Whether network design, tested backups and recovery procedures supported restoration of critical services.
- Whether incident-response and business-continuity plans addressed ransomware and the loss of a major transaction processor.
- Whether business-associate relationships and oversight were appropriate and breach-notification decisions were timely and consistent.
The outage and the privacy investigation are separate issues: restoring transaction services would not, by itself, establish whether data-security or notification duties were met.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Was patient information stolen, and how many people were affected?
When OCR announced its investigation in March 2024, the full scope of data exposure was not known publicly. Change Healthcare later filed a breach report. HHS’s FAQ says the company notified OCR on July 31, 2025, that approximately 192.7 million individuals had been affected.
“Affected” is not the same as a confirmed count of people whose complete medical records were taken, nor is it a count of people who experienced identity theft or fraud. HHS’s reported figure does not establish that every individual’s full record was exfiltrated or misused. The public information cited here does not specify the exact data elements for every affected person or establish the extent of any resulting misuse. The estimate is a later reported development, not a number known when OCR opened its investigation. See HHS’s incident FAQ.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesBest Value
What does the incident show about health-care concentration risk?
Organizations can maintain separate clinical networks and still depend on a small number of outside companies for claims, eligibility checks, pharmacy transactions or payments. An outage at one intermediary can therefore disrupt many otherwise independent providers. This is third-party risk even when the vendor does not deliver care directly: it may control a workflow that providers need to get paid or patients need to obtain services.
Continuity plans need to account for an unavailable intermediary, not only a malware incident inside one hospital. Alternate clearinghouses and paper procedures may be available but hard to activate at scale, particularly when many organizations seek alternatives at once. The episode also illustrates why vendor oversight, tested workarounds and contingency planning matter to financial operations as well as cybersecurity.
The Government Accountability Office described widespread effects on providers and patient care and estimated approximately $874 million in losses associated with the incident in its review of health-care cybersecurity leadership and response. That is GAO’s estimate of losses, not a measure of the breach’s full social or health impact. See GAO’s report.
What remains unresolved?
The sources cited here establish the investigation’s announced scope and the later reported impact estimate, but do not establish a final public OCR finding about HIPAA compliance. They also do not detail every data element involved, the extent of any misuse, or which safeguards were in place before the attack. A reported number of affected individuals should not be mistaken for a finding about individual harm or the legal outcome.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




