Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatransomware-group-operationmass-credential-exposureoperational-disruption

Impact and Response to the Change Healthcare Ransomware Attack

Updated 3mo agoFirst seen Dec 11, 20252 sources

A ransomware attack on Change Healthcare, a major processor of health insurance claims, exposed the personal health information of over 190 million people and caused widespread disruption across the U.S. healthcare system. Hospitals and clinics were unable to process claims or receive payments, leading to severe cash-flow crises that threatened their operations. In response, the Centers for Medicare and Medicaid Services implemented the Change Healthcare/Optum Payment Disruption Accelerated and Advance Payment program, providing $3.3 billion in emergency relief, though only 11% of hospitals received funds, with rural and unaffiliated hospitals being less likely to benefit. Research from the University of Minnesota analyzed the effectiveness of this relief program and highlighted areas for improvement in future emergency funding responses.

The American Hospital Association reported that the Change Healthcare incident was the largest single healthcare data breach in recent years, accounting for the majority of the 259 million records compromised in 2024. The breach underscored the vulnerability of healthcare data, particularly when stored unencrypted and managed by business associates rather than hospitals themselves. The incident has prompted calls for improved asset inventories, better tracking of business associates, and stronger data protection measures to mitigate the risk of similar large-scale breaches in the future.

Share:
Impact and Response to the Change Healthcare Ransomware Attack
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Dec 10, 20256mo ago

Health Affairs study finds CHOPD relief often missed hardest-hit hospitals

A University of Minnesota School of Public Health research brief published in Health Affairs found that only 11% of hospitals received CHOPD funds despite $3.3 billion being distributed, and that rural and unaffiliated hospitals were disproportionately excluded. Using FOIA-obtained data, the researchers concluded that more than 300 hospitals with significant losses received no relief, while many recipients received payments exceeding their actual Medicare revenue losses.

Oct 3, 20259mo ago

AHA says 33 million records were breached in 364 hacks by Oct. 3

As of October 3, 2025, the AHA reported that 33 million Americans' health records had been compromised in 364 hacking incidents. It said this was a significant decrease from the prior year's total, which had been heavily influenced by the Change Healthcare incident.

Dec 31, 20241y ago

AHA reports 259 million breached records in prior year

The American Hospital Association said the previous year set a record with 259 million breached health records, driven largely by the Change Healthcare ransomware attack. The figure was cited as a benchmark for comparing 2025 healthcare breach trends.

Jan 1, 20242y ago

CMS launches CHOPD emergency relief program

Following the Change Healthcare attack in 2024, CMS established the Change Healthcare/Optum Payment Disruption Accelerated and Advance Payment (CHOPD) program to provide emergency financial relief to affected hospitals. Nearly 4,400 U.S. hospitals applied for support under the program.

Change Healthcare ransomware attack disrupts claims and payments

In 2024, a ransomware attack on Change Healthcare/Optum disrupted claims submission and payment processing across the U.S. healthcare sector, creating cash-flow crises for providers. The incident also exposed personal health information of more than 190 million people.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Organizations
10 linked
Change HealthcareCenters for Medicare and Medicaid ServicesVerizon CommunicationsDataBreachesUniversity Of MinnesotaAmerican Hospital AssociationhhsNational Institute of Standards and TechnologyHealth AffairsOptum
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Impact and Response to the Change Healthcare Ransomware Attack | Mallory