From Health 201FailSystems

how automated healthcare fails, how you'd know, and what to do at each tier — every claim sourced, reviewed continuously


Incident

Change Healthcare ransomware and national claims/pharmacy clearinghouse outage

Attackers used stolen credentials on a Change Healthcare Citrix remote-access portal that had no multi-factor authentication, then deployed ransomware nine days later. Disconnecting the clearinghouse stalled pharmacy claims, medical claims and payments across the US.

PathConnectivity & data → Human handoff

Sources checked when written 26 September 2026

TierProviders' own clinical systems stayed up; claims, pharmacy benefit checks and prior authorisation were done manually or delayed. How tiers are assigned.

What happened

According to UnitedHealth Group CEO Andrew Witty's Senate testimony, attackers used compromised credentials on 12 February 2024 to reach a Change Healthcare Citrix portal that had no multi-factor authentication. They moved laterally, took data, and deployed ALPHV/BlackCat ransomware on 21 February. UnitedHealth cut connectivity to Change's data centres to stop the spread, and rebuilt the environment over the following weeks. Change handles information, claims and payments between physicians, pharmacists, health plans and governments. Witty testified that pharmacists had to submit claims manually, that by 7 March 99% of pre-incident pharmacies could process claims, and that by late April more than $6.5 billion had been advanced to providers as accelerated payments and loans. An American Hospital Association survey of nearly 1,000 hospitals (9–12 March 2024) found 94% reported financial impact and 74% reported direct impact on patient care. Nearly 40% said patients had trouble getting care because utilization requirements such as prior authorization were delayed, and about two-thirds reported difficulty switching to another clearinghouse. HHS later cited the attack in its January 2025 proposal to strengthen the HIPAA Security Rule.[1,2,3,4,5]

Documented harm

Direct patient-care impact reported by 74% of surveyed hospitals, including delayed access where prior authorization could not be processed (AHA survey). No individual clinical harm is quantified in the sources reviewed.

What it teaches

Sources

  1. Testimony of Andrew Witty, CEO, UnitedHealth Group, before the Senate Finance Committee: 'Hacking America's Health Care: Assessing the Change Healthcare Cyber Attack and What's Next'. US Senate Committee on Finance, 1 May 2024. Primary Testimony / filing · link checked 2026-09-26
  2. AHA Survey: Change Healthcare Cyberattack Significantly Disrupts Patient Care, Hospitals' Finances. American Hospital Association, 15 March 2024. Secondary Journalism · link checked 2026-09-26
  3. Change Healthcare Cyberattack Underscores Urgent Need to Strengthen Cyber Preparedness for Individual Health Care Organizations and as a Field. American Hospital Association, 2025. Secondary Official report · link checked 2026-09-26
  4. UnitedHealth hikes number of Change cyberattack breach victims to 190 million. Healthcare Dive (Emily Olsen), 27 January 2025. Secondary Journalism · link checked 2026-09-26
  5. HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (NPRM, FR Doc 2024-30983). HHS Office for Civil Rights, Federal Register 90(3):898-1022, 6 January 2025. Primary Regulation · link checked 2026-09-26

All incidents · Connectivity & data · Cascades · Human handoff

Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.

Dealing with an incident right now? This site is a reference, not an incident-response service. Activate your organisation's emergency operations plan and incident command, and: