Attackers used stolen credentials on a Change Healthcare Citrix remote-access portal that had no multi-factor authentication, then deployed ransomware nine days later. Disconnecting the clearinghouse stalled pharmacy claims, medical claims and payments across the US.
PathConnectivity & data → Human handoff
Sources checked when written 26 September 2026
TierProviders' own clinical systems stayed up; claims, pharmacy benefit checks and prior authorisation were done manually or delayed. How tiers are assigned.
What happened
According to UnitedHealth Group CEO Andrew Witty's Senate testimony, attackers used compromised credentials on 12 February 2024 to reach a Change Healthcare Citrix portal that had no multi-factor authentication. They moved laterally, took data, and deployed ALPHV/BlackCat ransomware on 21 February. UnitedHealth cut connectivity to Change's data centres to stop the spread, and rebuilt the environment over the following weeks. Change handles information, claims and payments between physicians, pharmacists, health plans and governments. Witty testified that pharmacists had to submit claims manually, that by 7 March 99% of pre-incident pharmacies could process claims, and that by late April more than $6.5 billion had been advanced to providers as accelerated payments and loans.
An American Hospital Association survey of nearly 1,000 hospitals (9–12 March 2024) found 94% reported financial impact and 74% reported direct impact on patient care. Nearly 40% said patients had trouble getting care because utilization requirements such as prior authorization were delayed, and about two-thirds reported difficulty switching to another clearinghouse. HHS later cited the attack in its January 2025 proposal to strengthen the HIPAA Security Rule.[1,2,3,4,5]
Documented harm
Direct patient-care impact reported by 74% of surveyed hospitals, including delayed access where prior authorization could not be processed (AHA survey). No individual clinical harm is quantified in the sources reviewed.
What it teaches
A single third-party clearinghouse can be a national single point of failure even when no hospital is breached.
Remote-access portals without MFA remain a primary entry point.
Contract for, and test, a second clearinghouse or manual submission path before you need it.
Plan cash-flow continuity as part of clinical continuity: payment outages hit care delivery within days.
One clearinghouse was a single point of failure for a large share of US claims, pharmacy and prior-authorization traffic.
Switching supplier during a crisis was hard for most hospitals; alternates must be enrolled beforehand.
A missing MFA control on one remote-access portal was the latent condition that let the cascade start.
Disconnecting to contain the attack was defensible, and it was also what stopped the downstream services.
Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.
Dealing with an incident right now? This site is a reference, not an incident-response service. Activate your organisation's emergency operations plan and incident command, and:
Power loss, disaster or resource needs: go through your local or county emergency management. They escalate to the state, and the state requests FEMA support; hospitals do not call FEMA directly.
A medical device problem: report it to the manufacturer and to FDA MedWatch.
Outside the US: your national emergency number and national cyber agency (in the UK, NCSC).