Independent Reporting · Not Legal or Security Advice · Verify With the Breached Company · Editorial Policy

Healthcare Data Breach Explained: Timeline, Exposure, and Response

The title does not identify a single incident; the closest documented national-scale U.S. event is the February 2024 Change Healthcare ransomware attack.

Attackers stole data and deployed ransomware, which locks systems or data to extort the victim. Change Healthcare processes health and personal information for healthcare providers and insurers. The breach therefore reached far beyond people who dealt directly with the company.

Table of Contents

What happened and when

Attackers used compromised credentials to enter a Change healthcare Citrix portal on February 12, 2024. The portal lacked multi-factor authentication. They exfiltrated data and deployed ransomware nine days later, according to UnitedHealth Group CEO testimony to the U.S. House.

Change Healthcare filed an HHS breach report on July 19, 2024, confirming that protected health information had been breached. On July 31, 2025, the company told HHS that approximately 192.7 million people were affected, according to the HHS Office for Civil Rights. The first report's 500-person figure was a reporting threshold, not the final victim count. The later total shows why early breach listings can substantially understate an incident's eventual scale.

Who may have been exposed

Potential victims include people whose healthcare providers or insurers used Change Healthcare. A person did not need a direct Change Healthcare account or relationship to have information in the company's systems. UnitedHealth's early review found files containing protected health information, known as PHI, or personally identifiable information, known as PII.

It reported no evidence that doctors' charts or complete medical histories were exfiltrated, according to the company's April 2024 incident update. That statement has an important limit: it describes what the early review had confirmed. It does not establish that every potentially affected person had the same information exposed or that no other sensitive records were involved.

Why the outage mattered

The attack also interrupted healthcare operations. It disrupted claims, payments, pharmacy processing, and access to care, affecting organizations and patients even before the exposure review was complete. By April 2024, Change Healthcare's payment processing represented about 6% of U.S.

healthcare payments. Its processing volume had recovered to approximately 86% of its pre-incident level. Those figures distinguish this incident from a breach involving data theft alone. The attack affected both confidentiality and the systems healthcare organizations relied on to conduct routine business.

Notification duties and personal response

HHS says a HIPAA-covered organization must notify affected people and the agency without unreasonable delay after discovering a breach. A business associate must notify the covered organization no later than 60 calendar days after discovery.

People who receive a notice should use any offered identity-protection services and watch for activity that does not match their care or finances. Change Healthcare's substitute breach notice recommends checking: Anyone who may be affected should keep the notice and document unfamiliar entries before contacting the health plan, provider, financial institution, or reporting agency involved.

  • Health-plan explanations of benefits for unfamiliar services
  • Provider statements for care not received
  • Bank and payment-card activity for unknown charges
  • Credit reports for accounts or inquiries not recognized
  • Tax returns and related records for suspicious activity

You Might Also Like

Owed money from a settlement? Check what is open at OpenClassActions.com. Caring for someone with dementia? Find practical guides at HelpDementia.com. Working out a skin routine? Evidence-based answers at AcneAdvocate.com. Forgot the name of a movie? Identify it at FindThisMovie.com.

We use cookies to run this site, measure how it’s used, and show ads. Choose “Essentials only” to limit cookies to what the site needs to work. Privacy Policy. Cookie Policy.