A cyberattack affecting Change Healthcare caused widespread disruption to healthcare payment and pharmacy claims processing in the United States. UnitedHealth Group (Change Healthcare’s parent company) disclosed the incident and its impacts through SEC filings, describing significant operational disruption and material financial effects across the business. Subsequent filings and earnings-related documents discussed ongoing remediation costs and impacts, reflecting the scale of financial risk from a high-availability healthcare transaction intermediary being taken offline.
First reported February 21, 2024Ransomwaremed overall confidence
Healthcare providers and pharmacies dependent on Change Healthcare transactions
Patients affected by delays in claims and pharmacy services
UnitedHealth Group / Change Healthcare operations
Initial access
unknown
Impact
service_disruption
financial_loss
encryption
extortion
Attribution
unknownlow confidence
Public filings describe the incident and impacts; specific actor attribution is not asserted here from the included SEC documents.
CVEs and ATT&CK
No CVE or ATT&CK association is captured in this curated record.
Mitigations
Now
Maintain offline/immutable backups and regularly test restoresEnables recovery without paying ransom and reduces business downtime when systems are encrypted or wiped.
Soon
Segment networks and restrict administrative privilegesSlows attacker movement and limits the blast radius of ransomware deployment across the enterprise.
Later
Harden endpoints/servers with EDR and restrict remote admin toolsImproves detection and blocking of ransomware behaviors and common lateral-movement mechanisms used to deploy payloads.
Detection ideas
Detect mass file encryption or destructive file operations
Alert on rapid renames/overwrites across many directories, creation of ransom notes, and high-entropy writes by unfamiliar processes.
Data sources: EDR telemetry, File integrity monitoring, Windows Security Event Logs
Detect lateral movement and remote execution used for ransomware deployment
Look for PsExec/SMB service creation, remote scheduled tasks, or WMIC usage followed by execution of the same binary on multiple hosts.
Data sources: EDR telemetry, Windows Security Event Logs, Network flow logs