The Change Healthcare breach exposed patient records across the entire U.S. health system

In February 2024, Change Healthcare — a major processor that handles billing, insurance claims, and patient records for thousands of hospitals and clinics — was hit by a ransomware attack. The breach exposed personal information belonging to millions of patients, including names, dates of birth, Social Security numbers, insurance details, and medical information. Because Change Healthcare processes data for such a large portion of the American healthcare system, the breach touched nearly every type of healthcare provider: hospitals, doctor's offices, pharmacies, mental health clinics, and insurance companies.

The attack disrupted healthcare services for weeks. Hospitals couldn't process insurance claims, pharmacies couldn't fill prescriptions, and clinics couldn't access patient records. By the time Change Healthcare restored most systems, the damage was already done — the attackers had already stolen the data and later released portions of it online.

Key Takeaways

  • If you received medical care at a hospital, clinic, or pharmacy in the United States, your information was likely exposed in this breach, regardless of which insurance company you use.
  • The stolen data included names, dates of birth, Social Security numbers, insurance information, and medical records — everything needed to commit identity theft or insurance fraud.
  • Change Healthcare sent breach notification letters to affected individuals starting in April 2024, but not everyone received one even if their data was exposed.
  • You can check whether your information was included in the breach by searching the HHS Breach Notification Portal using your name and date of birth.
  • Free credit monitoring and identity theft protection were offered to affected individuals, though enrollment windows have closed for some offers.

Which healthcare providers were connected to Change Healthcare

Change Healthcare processes claims and patient data for the majority of U.S. healthcare providers. This includes large hospital systems like UnitedHealth Group-owned facilities, independent hospitals, urgent care clinics, dialysis centers, mental health providers, and pharmacies. The company also handles data for insurance companies, both large national carriers and smaller regional plans.

If you received any medical care in 2023 or early 2024 — whether inpatient, outpatient, emergency, or pharmacy services — there is a significant chance your information passed through Change Healthcare's systems. The company processes roughly 15 billion healthcare transactions per year, making it one of the largest healthcare data processors in the country.

Small independent practices and rural clinics were affected alongside major medical centers. Change Healthcare's reach extended across all 50 states, making this one of the broadest healthcare breaches in U.S. history by the number of people potentially affected.

What information was stolen in the breach

The attackers accessed a wide range of sensitive personal and medical data. Names, dates of birth, and Social Security numbers were exposed for millions of people. Insurance information — including member IDs, policy numbers, and plan details — was also compromised. Medical records, diagnoses, treatment information, and prescription data were included in the stolen files.

In some cases, financial information like bank account numbers and payment card details were exposed, though not for all affected individuals. The specific data stolen varied depending on which systems the attackers accessed and what information each healthcare provider stored in Change Healthcare's systems.

This combination of data — personal identifiers plus medical and insurance information — is particularly valuable to criminals. It can be used to file fraudulent insurance claims, obtain prescription medications, open accounts in someone else's name, or commit medical identity theft.

How to learn about your information was exposed

The U.S. Department of Health and Human Services maintains the HHS Breach Notification Portal, a searchable database of all reported healthcare breaches. You can search by your name and date of birth to see if you appear in the Change Healthcare breach records. Visit the portal at breachportal.hhs.gov and use the search function to look for your information.

Change Healthcare also sent notification letters to individuals whose information was confirmed to be exposed. These letters began arriving in April 2024 and continued through the summer. The letters included information about free credit monitoring and identity theft protection services. However, not everyone whose data was exposed received a letter — some individuals may have been affected but not notified due to incomplete contact information in the healthcare provider's records.

If you received a notification letter, it will specify which of your information was exposed and provide details about the monitoring services available to you. Keep this letter, as it contains enrollment codes and deadlines for the free services offered.

Free credit monitoring and identity theft protection offered

Change Healthcare and affected healthcare providers offered free credit monitoring and identity theft protection services to exposed individuals. The specific services varied depending on which notification letter you received, but most included two years of free credit monitoring, identity theft insurance, and access to fraud resolution services.

Enrollment windows for these services have already closed for many offers. If you received a notification letter, check the deadline printed on it. Some enrollment periods ended in late 2024, while others may extend into 2025 depending on when the letter was sent. Contact the monitoring service provider listed in your letter if you are unsure whether you can still enroll.

Even if you missed the enrollment window for the free service, you have other options. You can place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) at no cost. A credit freeze prevents anyone from opening new accounts in your name without your permission.

Steps to protect yourself after the breach

Start by placing a fraud alert with at least one of the three credit bureaus. A fraud alert tells lenders to verify your identity before opening new accounts. You can place an alert by contacting Equifax, Experian, or TransUnion — notifying one bureau will trigger them to notify the others. The alert lasts one year and is free.

If you want stronger protection, consider a credit freeze. A freeze locks your credit file so that no one can open new accounts without unfreezing it first. You must request a freeze with each of the three bureaus separately. Freezes are free and remain in place until you remove them, though you may need to temporarily unfreeze your credit if you apply for a loan or credit card.

Monitor your credit reports regularly for suspicious activity. You are may have access to to one free credit report per year from each of the three bureaus through annualcreditreport.com. Spread your requests throughout the year — get one report every four months — so you can check for unauthorized accounts or inquiries. Watch for medical bills you did not receive, insurance claims for services you did not use, or accounts opened in your name.

Review your healthcare bills and insurance statements carefully. Look for charges you do not recognize or claims for services you did not receive. Contact your healthcare provider or insurance company immediately if you spot anything suspicious. Medical identity theft can be harder to catch than financial identity theft because the fraudulent charges may not appear on your credit report.

What happened to the stolen data

The attackers behind the Change Healthcare breach were a ransomware group known as BlackCat (also called ALPHV). They encrypted Change Healthcare's systems and demanded payment in exchange for the decryption key. When Change Healthcare did not pay the full ransom, the group began releasing stolen data online in batches starting in March 2024.

Portions of the stolen data have been posted on the dark web and shared among criminal networks. However, not all of the data has been released publicly. Some of it remains in the hands of the attackers or has been sold to other criminal groups. This means the risk of misuse extends beyond what has already appeared online.

Law enforcement agencies, including the FBI and the Department of Justice, investigated the breach. The investigation confirmed the scope of the exposure and helped identify the attackers, though recovery of the stolen data was not possible.

Frequently Asked Questions

Do I need to do anything if I didn't receive a notification letter?

You may still have been affected even without a letter. Search the HHS Breach Notification Portal to confirm. If your information was exposed, take the protective steps outlined above — place a fraud alert or credit freeze and monitor your credit reports. You can also contact your healthcare provider or insurance company to ask whether your data was involved in the breach.

Can I sue Change Healthcare or my healthcare provider over the breach?

Multiple lawsuits have been filed against Change Healthcare and some healthcare providers. However, healthcare breach lawsuits are complex and outcomes vary. Consult with an attorney who specializes in data breach cases if you want to explore this option. Many law firms offer free consultations to discuss whether you have a claim.

Will my health insurance rates go up because of the breach?

The breach itself should not cause your insurance rates to increase. Insurance rates are based on your age, health status, location, and plan type — not on whether your information was exposed in a breach. If your rates increase, it would be for reasons unrelated to the Change Healthcare breach.

How long should I monitor my credit after this breach?

Continue monitoring your credit reports for at least three years after the breach. Identity thieves sometimes wait months or even years before using stolen information. The longer you monitor, the better your chances of catching fraudulent activity before it causes serious damage.

What if I see fraudulent charges or accounts opened in my name?

Contact the creditor or financial institution immediately to report the fraud. File a report with the Federal Trade Commission at reportidentitytheft.ftc.gov. Keep detailed records of all fraudulent accounts and charges, and consider filing a police report in your jurisdiction. These steps create an official record that can help you dispute charges and recover from identity theft.