Independent Reporting · Not Legal or Security Advice · Verify With the Breached Company · Editorial Policy

Cybersecurity — UnitedHealth Breach Investigation Guide: Evidence, Notices, and Verification

The documented evidence concerns the Change Healthcare ransomware breach and related HIPAA investigations of Change Healthcare and UnitedHealth Group. It confirms a large protected health information breach, but not a final finding that either company violated HIPAA. The records also separate three issues readers often confuse: the estimated number affected, the number notified, and the information exposed. Here is how to evaluate each one and act on a notice.

Table of Contents

What the official record establishes

Protected health information, or PHI, is health and identifying information covered by HIPAA. HHS's Office for Civil Rights opened investigations into whether unsecured PHI was breached and whether Change Healthcare and UnitedHealth Group complied with HIPAA. Change reported the ransomware-related breach to OCR on July 19, 2024.

OCR later recorded an estimate of approximately 192.7 million affected people as of July 31, 2025, according to the agency's Change Healthcare cybersecurity incident guidance. These facts establish the incident's reported scope and the existence of federal investigations. The supplied evidence does not include a final OCR determination about HIPAA compliance.

What information may have been exposed

Change's filed sample notice says an unauthorized actor accessed and copied some system data between February 17 and 20, 2024. Change detected suspicious activity on February 21.

The information differed by person. According to the notice filed with the California Department of Justice, it could include: A notice does not mean every listed category applied to its recipient. It describes the categories that potentially appeared in the affected data.

  • Names, addresses, dates of birth, phone numbers, or email addresses
  • Health-insurance member or policy identifiers
  • Diagnoses, test results, medications, treatment, or other medical information
  • Claims, billing, payment, or banking information
  • Social Security numbers or government identification numbers

Why notice totals and impact estimates differ

OCR recorded that Change had sent about 130 million individual notices by January 24, 2025, while the estimated affected population then stood near 190 million. The notice count therefore was not a final count of affected people. UnitedHealth later said the vast majority of the estimated 190 million affected people had received individual or substitute notice.

Its 2024 Form 10-K said the final number would be filed with OCR. Substitute notice can be used when current addresses are unavailable. Someone may therefore encounter a public notice rather than receive a personal letter, and the absence of a letter does not by itself establish that the person was unaffected.

How to verify a breach notice

A genuine HIPAA breach notice should identify the incident, describe the information involved, explain protective steps, summarize investigation or mitigation work, and provide a contact method. Check a notice against those elements before responding: Change's filed notice offered two years of IDX credit monitoring and identity-restoration services, but enrollment was required.

It also warned that credit monitoring might be unavailable without a U.S. credit history, a U.S. or territorial address, and a valid Social Security number.

  • Confirm that it identifies Change Healthcare and the February 2024 incident.
  • Look for a description of the data categories that may apply.
  • Confirm that it explains available protective services and how to enroll.
  • Use independently obtained company or agency information to check contact details before providing personal data.
  • Keep the notice and record any enrollment confirmation.

Choosing practical protections

UnitedHealth said it was unaware of misuse and had not found electronic medical-record databases in the analyzed data. Those statements limit what the company reported finding; they do not identify which data categories applied to any particular person. Match your response to the potentially exposed information.

Review claims and payment records if the notice mentions medical or financial data. Protect insurance and government identifiers as well as ordinary financial accounts. If identifying or financial information may have been exposed, consider freezing your credit separately with Equifax, Experian, and TransUnion. The Federal Trade Commission says a credit freeze is free, blocks new credit accounts until lifted, and does not affect your credit score.


You Might Also Like

Owed money from a settlement? Check what is open at OpenClassActions.com. Caring for someone with dementia? Find practical guides at HelpDementia.com. Working out a skin routine? Evidence-based answers at AcneAdvocate.com. Forgot the name of a movie? Identify it at FindThisMovie.com.

We use cookies to run this site, measure how it’s used, and show ads. Choose “Essentials only” to limit cookies to what the site needs to work. Privacy Policy. Cookie Policy.