On February 21, 2024, ransomware was deployed into the Change Healthcare (CHC) computer system. Once it was discovered, CHC immediately disconnected its systems to prevent further spread. As a result, hospitals, physicians’ offices, and pharmacies could not process claims, leaving many patients without access to care.1 More than 90% of the nation’s 70,000 pharmacies were required to implement electronic work-arounds, whereas the remaining 10% used offline methods.2
According to an American Hospital Association survey conducted in March 2024, 94% of hospitals reported financial impact, with approximately 60% reporting a daily loss of at least $1 million due to the incident. Although many hospitals could implement work-arounds, the majority found the process difficult and expensive.3
About the Authors
Josephine M. Gresko is a PharmD candidate at the Virginia Commonwealth University School of Pharmacy in Richmond.
Joseph L. Fink III, JD, DSc (Hon), BSPharm, FAPhA, is professor emeritus of pharmacy law and policy as well as former Kentucky Pharmacists Association Professor of Leadership at the University of Kentucky College of Pharmacy in Lexington.
CHC is a medical billing clearinghouse responsible for 15 billion medical claims annually, or approximately 40% of all claims. It was acquired in 2022 and merged with Optum as a subsidiary of UnitedHealth Group. CHC needed technological upgrades due to the company’s age at its acquisition. It was discovered that the attacked server did not use multifactor authentication, a current industry standard.1 The ransomware group claiming responsibility for the incident, BlackCat/ALPHV, allegedly used compromised credentials to gain access to CHC’s system and deploy the ransomware while stealing data.4
Ransomware is malware that denies users access to data by encrypting it with a key known only to the hacker. The decryption key can only be acquired if the user pays the ransom, usually in cryptocurrency.5 It has been estimated that CHC paid about 350 bitcoins (US $22 million).4
Data from the incident show that an estimated one-third of Americans had their health information leaked.1 CHC is unable to confirm what specific data were involved with the leak, but possibilities include contact information, health insurance information, protected health information, or billing identification such as Social Security numbers. In June 2024, CHC started notifying impacted individuals.6