Timeline

  • February 21, 2024: ALPHV/BlackCat ransomware attack on Change Healthcare
  • March 2024: UnitedHealth pays $22M ransom; ALPHV exit scams affiliates
  • April 2024: RansomHub (likely same affiliates) threatens to publish stolen data
  • October 2024: HHS confirms 100M+ individuals affected notification submitted
  • February 2025: Full system restoration completed (~12 months post-attack)

Why It Was So Devastating

Change Healthcare processes ~40% of all US medical claims. The attack disrupted:

  • Prescription processing at 90,000+ pharmacies
  • Claims submission for thousands of providers
  • Prior authorization workflows across the US

Small practices had to close. Hospitals lost millions per day in revenue cycle disruption.

Lessons for IT/Security Teams

  1. Single points of failure in third-party integrations are existential risks in healthcare
  2. MFA was not enabled on the Citrix VPN portal used for initial access
  3. Segment healthcare clearinghouse connections from internal networks
  4. Test business continuity plans that assume complete loss of key SaaS/clearinghouse integrations