The title does not identify a single incident; the closest documented national-scale U.S. event is the February 2024 Change Healthcare ransomware attack.
Attackers stole data and deployed ransomware, which locks systems or data to extort the victim. Change Healthcare processes health and personal information for healthcare providers and insurers. The breach therefore reached far beyond people who dealt directly with the company.
Table of Contents
- What happened and when
- Who may have been exposed
- Why the outage mattered
- Notification duties and personal response
What happened and when
Attackers used compromised credentials to enter a Change healthcare Citrix portal on February 12, 2024. The portal lacked multi-factor authentication. They exfiltrated data and deployed ransomware nine days later, according to UnitedHealth Group CEO testimony to the U.S. House.
Change Healthcare filed an HHS breach report on July 19, 2024, confirming that protected health information had been breached. On July 31, 2025, the company told HHS that approximately 192.7 million people were affected, according to the HHS Office for Civil Rights. The first report's 500-person figure was a reporting threshold, not the final victim count. The later total shows why early breach listings can substantially understate an incident's eventual scale.
Who may have been exposed
Potential victims include people whose healthcare providers or insurers used Change Healthcare. A person did not need a direct Change Healthcare account or relationship to have information in the company's systems. UnitedHealth's early review found files containing protected health information, known as PHI, or personally identifiable information, known as PII.
It reported no evidence that doctors' charts or complete medical histories were exfiltrated, according to the company's April 2024 incident update. That statement has an important limit: it describes what the early review had confirmed. It does not establish that every potentially affected person had the same information exposed or that no other sensitive records were involved.
Why the outage mattered
The attack also interrupted healthcare operations. It disrupted claims, payments, pharmacy processing, and access to care, affecting organizations and patients even before the exposure review was complete. By April 2024, Change Healthcare's payment processing represented about 6% of U.S.
healthcare payments. Its processing volume had recovered to approximately 86% of its pre-incident level. Those figures distinguish this incident from a breach involving data theft alone. The attack affected both confidentiality and the systems healthcare organizations relied on to conduct routine business.
Notification duties and personal response
HHS says a HIPAA-covered organization must notify affected people and the agency without unreasonable delay after discovering a breach. A business associate must notify the covered organization no later than 60 calendar days after discovery.
People who receive a notice should use any offered identity-protection services and watch for activity that does not match their care or finances. Change Healthcare's substitute breach notice recommends checking: Anyone who may be affected should keep the notice and document unfamiliar entries before contacting the health plan, provider, financial institution, or reporting agency involved.
- Health-plan explanations of benefits for unfamiliar services
- Provider statements for care not received
- Bank and payment-card activity for unknown charges
- Credit reports for accounts or inquiries not recognized
- Tax returns and related records for suspicious activity
You Might Also Like
- Healthcare Data Breach News 2026 Guide: exposure, response, and recovery; Key Facts and Questions to Ask
- Personal Data Stolen Explained: Timeline, Exposure, and Response
- What Is New With Healthcare Data Breach News in August 2026? Latest breach notices and security advisories and Key Takeaways