What happened and who it touched

Change Healthcare, one of the largest medical billing and insurance companies in the United States, suffered a ransomware attack in February 2024 that exposed personal information belonging to millions of people. The breach affected patients, healthcare providers, and insurance companies — essentially anyone who had a claim processed, a prescription filled, or a bill sent through Change Healthcare's systems.

The attack disrupted pharmacies, hospitals, and doctor's offices for weeks because Change Healthcare handles the behind-the-scenes work that keeps healthcare running: processing insurance claims, managing prescription refills, and routing billing information between providers and insurers. When their systems went down, healthcare workers couldn't verify insurance coverage or submit claims electronically.

The company announced that the breach exposed names, dates of birth, Social Security numbers, insurance information, medical record numbers, and healthcare claim details for an estimated 100 million people — though the exact number has shifted as the investigation continued. That scale makes it one of the largest healthcare data breaches on record.

Key Takeaways

  • Change Healthcare processes insurance claims and prescription information for most major U.S. healthcare providers, so the breach potentially affected anyone who used healthcare services in 2023 or early 2024.
  • Exposed data included names, dates of birth, Social Security numbers, insurance member IDs, and medical claim information — the exact combination that identity thieves use most effectively.
  • You do not need to have been a Change Healthcare customer directly; the company processes claims behind the scenes for hospitals, pharmacies, and insurance companies you may use.
  • The company offered free credit monitoring and identity theft protection for two years to affected individuals, though enrollment required knowing you were affected.

How to know if your information was exposed

Change Healthcare sent notification letters to people whose information was confirmed in the breach, but the timing was slow — notifications began in June 2024, four months after the attack. The letter included information about free credit monitoring and identity theft protection services the company was offering.

If you received a letter from Change Healthcare or its parent company UnitedHealth Group, your information was exposed. If you did not receive a letter but used healthcare services (filled prescriptions, visited a doctor, submitted an insurance claim) between January 2023 and February 2024, your information may still have been in their systems. There is no way to confirm your exposure with certainty unless you received direct notification.

You can also check the U.S. Department of Health and Human Services breach notification database, which lists all reported healthcare data breaches. Search for "Change Healthcare" to see the official filing, though it will not tell you whether your specific information was involved.

What information was at risk

The breach exposed different types of information depending on what healthcare services you used. Most commonly exposed were names, dates of birth, and Social Security numbers. Insurance member IDs, group health plan numbers, and healthcare claim information were also compromised for many people.

Some individuals had additional sensitive data exposed, including medical record numbers, diagnosis codes, and prescription information. The exact details depended on what information Change Healthcare held about each person — a patient who only filled one prescription through a pharmacy would have less information exposed than someone with multiple insurance claims from a hospital stay.

The combination of name, date of birth, and Social Security number is particularly valuable to identity thieves because it is enough to open credit accounts, file fraudulent tax returns, or explore for loans in someone else's name. This is why the breach was treated as high-risk even though no financial account numbers or credit card information was exposed.

What happened to the attackers and the company

A ransomware group called BlackCat claimed responsibility for the attack. Ransomware is malicious software that encrypts a company's files and systems, making them unusable until the company pays a ransom. BlackCat demanded payment and threatened to sell the stolen data if Change Healthcare did not comply.

Change Healthcare paid a ransom — the company confirmed it paid $22 million to recover access to its systems. The attackers also claimed they deleted the stolen data rather than selling it, though there is no way to verify that claim independently. Some security researchers have questioned whether the data was truly destroyed.

The U.S. Department of Health and Human Services Office for Civil Rights, which oversees healthcare privacy law, launched an investigation into whether Change Healthcare failed to protect patient information adequately. The company also faced multiple lawsuits from affected individuals and healthcare providers. As of late 2024, no final penalties or settlements had been announced.

Steps to take if you were notified

If you received a notification letter, the first step is to enroll in the free credit monitoring and identity theft protection service that Change Healthcare offered. The letter included instructions and a website or phone number to use. This service typically runs for two years and includes credit report monitoring, identity theft insurance, and alerts if someone tries to open accounts in your name.

You should also place a fraud alert with the three major credit bureaus — Equifax, Experian, and TransUnion. A fraud alert tells creditors to verify your identity before opening new accounts in your name. You can place a fraud alert for free by contacting any one of the three bureaus; they are required to notify the others. The alert lasts one year and can be renewed.

Consider placing a credit freeze if you want stronger protection. A credit freeze prevents creditors from accessing your credit report entirely unless you temporarily lift it, which makes it much harder for someone to open accounts in your name. Freezes are free in most states and last until you remove them. You place a freeze separately with each of the three bureaus.

Monitor your credit reports regularly for suspicious activity. You can request a free credit report from each bureau once per year at annualcreditreport.com. Spread your requests throughout the year so you have a fresh report every few months rather than all at once.

What this breach means for healthcare privacy

The Change Healthcare breach exposed a structural weakness in how U.S. healthcare data flows. Because a single company processes claims for so many providers and insurers, a breach at that company affects millions of people across the entire healthcare system. There is no way for individual patients to avoid using Change Healthcare's services — the company operates invisibly behind the scenes.

The breach also raised questions about whether healthcare companies invest enough in security. Change Healthcare is owned by UnitedHealth Group, one of the largest and most profitable healthcare companies in the world, yet the attack succeeded in encrypting their systems for weeks. Security experts noted that the company had known vulnerabilities that had not been patched.

As a patient, you have limited control over which companies handle your health information. You cannot choose to avoid Change Healthcare because you do not interact with it directly — your doctor's office or pharmacy makes that choice. What you can do is monitor your credit and financial accounts for signs of fraud, and understand that healthcare data breaches are now common enough that credit monitoring and fraud alerts are practical precautions.

Frequently Asked Questions

Do I need to worry if I did not receive a notification letter?

Not necessarily. Change Healthcare's notifications were incomplete and slow — some people affected by the breach may not have received letters. If you used healthcare services between January 2023 and February 2024, assume your information may have been exposed and take the same precautions: place a fraud alert, monitor your credit reports, and watch for suspicious account openings or charges.

Can I sue Change Healthcare for the breach?

Multiple lawsuits have been filed by affected individuals and healthcare providers. Whether you can join a lawsuit depends on the specific case and your location. You can search for "Change Healthcare lawsuit" to find current cases, though most are still in early stages and settlements have not been reached. Any settlement would likely require you to have been notified of the breach or to prove your information was exposed.

What if I see fraudulent charges or accounts opened in my name?

Contact the creditor or bank when ready and report the fraud. Then file a report with the Federal Trade Commission at identitytheft.gov, which creates an official record of the fraud. If the fraudulent accounts are recent, you may also want to file a police report, though this is not always necessary. Keep copies of all documentation.

Is the free credit monitoring actually useful?

Credit monitoring alerts you if someone tries to open new accounts in your name, which is helpful. However, it does not prevent fraud — it only tells you after it happens. A credit freeze is stronger protection because it stops new accounts from being opened without your permission. Many people use both: a freeze for ongoing protection and monitoring to catch anything that slips through.

Will my health insurance rates go up because of this breach?

No. Health insurance rates are set based on claims history, age, location, and plan type — not on whether your information was exposed in a breach. The breach does not affect your coverage or your rates.