Cyberattack on Change Healthcare disrupted US pharmacies and claims processing

Organization
Change Healthcare
Exploit
Ransomware
Industry
Healthcare Technology

Change Healthcare, the claims and payments processor owned by UnitedHealth Group through its Optum subsidiary, was hit by a cyberattack on February 21, 2024. The company disconnected its systems to contain the intrusion, triggering an outage that ran across the U.S. healthcare system.

More than 100 Change Healthcare applications were taken offline, spanning pharmacy, medical records, clinical, dental, patient engagement and payment services. Pharmacies and military treatment facilities could not verify insurance coverage, calculate copayments or submit prescription claims, and several reverted to manual processing. The American Hospital Association advised member hospitals to disconnect from Optum systems until they were independently judged safe.

In a filing with the Securities and Exchange Commission the following day, UnitedHealth said a suspected nation-state associated threat actor had gained access to Change Healthcare systems. The company said other UnitedHealth systems were unaffected.

Early reports suggested the attackers had exploited vulnerabilities in ConnectWise's ScreenConnect remote access software. ConnectWise responded that Change Healthcare did not appear to be a direct customer. UnitedHealth later determined that attackers had entered on February 12 using stolen credentials on a Citrix remote access portal that lacked multi-factor authentication.

The ALPHV/BlackCat ransomware group claimed the attack on February 26 and said it had taken six terabytes of data. Change Healthcare confirmed the group's involvement on February 29.

Sources