Timeline
- February 21, 2024: ALPHV/BlackCat ransomware attack on Change Healthcare
- March 2024: UnitedHealth pays $22M ransom; ALPHV exit scams affiliates
- April 2024: RansomHub (likely same affiliates) threatens to publish stolen data
- October 2024: HHS confirms 100M+ individuals affected notification submitted
- February 2025: Full system restoration completed (~12 months post-attack)
Why It Was So Devastating
Change Healthcare processes ~40% of all US medical claims. The attack disrupted:
- Prescription processing at 90,000+ pharmacies
- Claims submission for thousands of providers
- Prior authorization workflows across the US
Small practices had to close. Hospitals lost millions per day in revenue cycle disruption.
Lessons for IT/Security Teams
- Single points of failure in third-party integrations are existential risks in healthcare
- MFA was not enabled on the Citrix VPN portal used for initial access
- Segment healthcare clearinghouse connections from internal networks
- Test business continuity plans that assume complete loss of key SaaS/clearinghouse integrations