Change Healthcare, Inc. Data Breach
Change Healthcare Massive Network Breach Affects 192.7M
What happened in the Change Healthcare, Inc. data breach?
The Change Healthcare, Inc. data breach was reported on July 19, 2024 and affected 192,700,000 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Minnesota. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Change Healthcare, Inc. Breach Details
Change Healthcare Network Server Breach Report
Opening Summary
Change Healthcare, Inc., a major healthcare technology and business services company based in Minnesota, experienced a significant data breach involving unauthorized access to its network servers. The breach was discovered and reported to the U.S. Department of Health and Human Services on July 19, 2024, affecting approximately 192.7 million individuals. This represents one of the largest healthcare data breaches in recent history, impacting patients across the United States who received services through healthcare providers utilizing Change Healthcare's systems and platforms.
Company Response and Investigation
Change Healthcare initiated a comprehensive investigation following the discovery of unauthorized access to its network infrastructure. The company engaged cybersecurity experts and law enforcement to determine the scope and nature of the breach. Upon confirmation of the incident, Change Healthcare began the process of notifying affected individuals in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured protected health information (PHI). The company also notified the HHS Office for Civil Rights and relevant state attorneys general as required by federal regulations.
Technical Details of the Breach
The breach occurred through unauthorized access to Change Healthcare's network servers, which typically indicates a compromise of the company's IT infrastructure rather than a physical theft of devices or documents. Network server breaches of this magnitude often result from sophisticated cyber attacks such as ransomware deployment, exploitation of unpatched vulnerabilities, credential compromise, or advanced persistent threats (APTs). The fact that this breach affected network servers—the central repositories of healthcare data—suggests that attackers gained elevated access to systems containing vast quantities of patient information across multiple healthcare organizations. The scale of the breach (192.7 million individuals) indicates that the compromised servers likely contained consolidated data from numerous healthcare providers and payers who rely on Change Healthcare's services for claims processing, billing, pharmacy services, and other critical healthcare operations.
Organizational Context
Change Healthcare, Inc. is one of the largest independent healthcare technology and business services companies in the United States. The company provides critical infrastructure and services to healthcare providers, payers, and patients, including claims processing, payment and revenue cycle management, pharmacy benefit management, clinical information exchange, and network connectivity solutions. Change Healthcare operates across all 50 states and serves thousands of healthcare organizations, from small independent practices to large hospital systems and major insurance companies. The company's extensive reach means that a breach of its systems has cascading effects across the entire healthcare ecosystem, potentially affecting patients who may not even be directly aware they use Change Healthcare's services.
Impact on Affected Individuals
The breach potentially exposed protected health information for approximately 192.7 million individuals, representing a substantial portion of the U.S. population. Given the scope of Change Healthcare's operations, affected individuals include patients who received healthcare services from providers using Change Healthcare's systems, as well as individuals whose information was processed through the company's claims, billing, or pharmacy platforms. The breach notification process began in July 2024, with affected individuals receiving notification through their healthcare providers and insurers. Notifications included information about the breach, the types of data potentially exposed, and recommended protective measures. The scale of this breach necessitated coordinated notification efforts across multiple state jurisdictions and healthcare organizations.
Industry Context and HIPAA Implications
Under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), covered entities and business associates must notify affected individuals of breaches of unsecured PHI. Change Healthcare, as a business associate to numerous healthcare providers and payers, bears responsibility for notifying affected parties and implementing corrective measures. This breach underscores the critical importance of strong cybersecurity measures in healthcare organizations that serve as central repositories for patient data. Network server breaches affecting business associates have become increasingly common as healthcare organizations consolidate data and rely on third-party vendors for essential services. The 192.7 million individuals affected represents a scale that exceeds most previous healthcare breaches, highlighting the systemic risks posed by centralized healthcare data infrastructure. Healthcare organizations and payers are required to conduct risk assessments, implement security safeguards, and maintain business associate agreements that include specific security and breach notification requirements.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Change Healthcare, Inc. Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review healthcare bills and explanation of benefits (EOB) statements carefully for unauthorized services, claims, or charges; contact your healthcare provider or insurance company immediately if you identify suspicious activity
Change passwords for healthcare-related accounts, insurance portals, and any online accounts that may have been affected; use strong, unique passwords and enable multi-factor authentication where available
Consider enrolling in credit monitoring and identity theft protection services if offered by Change Healthcare or your healthcare provider; monitor for suspicious communications requesting personal or health information
Place a fraud alert with the Federal Trade Commission (FTC) and consider filing a report at IdentityTheft.gov if you suspect identity theft; keep documentation of all breach-related communications and notifications
Contact your healthcare providers and insurance companies to verify that your account information is accurate and that no unauthorized services have been billed to your account
Be cautious of phishing emails, calls, or texts claiming to be from healthcare providers or offering breach-related services; verify communications directly with your provider before providing any information
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Minnesota Breaches
Search all breaches reported in Minnesota
Active Lawsuit: Change Healthcare Data Breach Lawsuits
Multiple class action lawsuits have been filed against Change Healthcare and UnitedHealth Group following the massive 2024 data breach that affected over 100 million patients.
Check your eligibility