user Admin_Adham
17th Mar, 2026 12:00 AM
Test

Change Healthcare Breach Still Affecting Docs, Hospitals

When her billing program first went down in February 2024, Catherine Mazzola, MD, shrugged. Computer systems go down all the time. In a few hours, the New Jersey-based pediatric neurosurgeon assumed she would be back up and running. Two days later, her practice’s bank account had not received any deposits.

If this didn’t change quickly, Mazzola wouldn’t be able to pay her employees. Her practice would quickly go under.

“I literally just went into my little office, closed the door, and I cried for about 10-15 minutes. What is going on now? How could this be happening?” she said.

As the crisis grew, Mazzola began to hear rumors about widespread outages of the Change Healthcare billing platform. She phoned Optum Health, a subsidiary of UnitedHealth Group that owned the platform, to ask what was going on. Change Healthcare had been hacked, officials told her. It would be weeks, even months, before the system was functional. Until then, Mazzola had no way to submit most of her claims or receive payment.

The Change Healthcare ransomware attack 2 years ago is believed to be the largest medical system security breach in American history, imperiling physicians’ livelihoods and hospitals’ financial survival for months.

SUGGESTED FOR YOU

Change Healthcare’s platform, a healthcare clearinghouse that processes insurance claims and payments, touches almost 40% of the country’s 15 billion annual healthcare claims. Approximately 190 million people in America had their healthcare data exposed by the hack.

“The majority of cyber risk exposure that hospitals face is from insecure third-party technology. They have to do a better job, because when we’re disrupted, it’s no longer just a data theft crime; it’s a threat to life issue,” said John Riggi, national advisor for cybersecurity and risk at the American Hospital Association.

‘A Million Dollars in the Hole’

For physicians with small, independent practices, like Philadelphia-area pediatrician Christine Meyer, MD, the fallout continues to be catastrophic.

“I’m still a million dollars in the hole,” Meyer said. Large loans are helping fill the gap.

The sheer size of the hack meant that government officials and researchers alike have pored over its every detail. On February 12, 2024, hackers from the ransomware group ALPHV/Black Cat first gained access to Change Healthcare through a remote access portal that was not secured with industry-standard two-factor authentication.

By February 21, workers at Change Healthcare noticed the intrusion and shut down the system to prevent further damage.

That was when Mazzola and Meyer found themselves abruptly unable to send claims and receive payment through the system.

Change Healthcare’s owner, UnitedHealth, filed a report with the Securities and Exchange Commission the next day, when it formally notified the government about the hack.

It wasn’t until February 29 that UnitedHealth correctly identified ALPHV/Black Cat as the likely perpetrators of the hack.

In early March, UnitedHealth paid a $22 million bitcoin ransom to ALPHV, who promptly disappeared, along with vast troves of stolen data. While UnitedHealth was able to recover some of the missing data — enough to determine what was stolen and begin the process of rebuilding its system — it reported that 22 screenshots of allegedly stolen files containing personal and health information were posted for about a week on a dark-web site run by the attackers.

“A lot of things have become increasingly digitized. Everything that I do in a hospital on a daily basis to take care of patients relies on connected technology,” said Jeff Tully, anesthesiologist and co-director of the UCSD Center for Healthcare Cybersecurity, La Jolla, California. “There’s no single magic vulnerability. Defenders have to be perfect 100% of the time, and the attackers have to get lucky once.”

In the meantime, patients said they either couldn’t fill their prescriptions or had to pay for them in cash, according to TechCrunch. Hospitals and physicians had to revert to paper billing.

“There was a disruption, not only to the revenue cycle but directly to patient care. Elective surgeries were delayed. Care was disrupted,” Riggi said.

Emergency Loans Kept Practices Afloat

Both Meyer and Mazzola scrambled to identify sources of cash flow to keep their practices running: home equity loans, credit cards, and retirement savings. Only emergency loans from UnitedHealth Group of $750,000 and $535,000, respectively, kept their practices afloat, they said.

“The early weeks were all about just survival. The loan kept us going. We were able to keep our doors open until our cash flow started to recover,” Meyer said.

But no sooner had the money hit Mazzola’s account than UnitedHealth began demanding repayment.

“I was really shocked and surprised when all of a sudden, we were getting multiple emails saying you have 2 weeks to repay the loan,” she said. “I told them I’m willing to repay the loan, but right now, we’re just getting back on our feet, and all I can afford to pay is $10,000 a month.”

In early 2025, Mazzola noticed that her claims from UnitedHealth were not being paid. She phoned the company and was told that they were garnishing her reimbursements to repay the loan. That such a large corporation was clawing back money it only needed to fork over because of its own negligence made Mazzola furious.

To address the billing backlog, Meyer’s office staff worked overtime. Mazzola hired extra help. These steps added extra expenses just to recoup their losses. The physicians say it took close to a year for their practices to begin to feel normal again.

“There’s only a couple of providers of similar scale providing similar functions. So if you take out one, that’s going to be felt fairly widely across the entire ecosystem,” Tully said.

Searching for Accountability

Regulators and legislators have grilled UnitedHealth executives under oath to better understand what made the medical system so susceptible to this attack and to begin the slow process of developing better safeguards against future hacks.

While many hospitals and practices have returned to business as usual, many physicians can’t forget just how vulnerable they were. What they lost wasn’t just money, but trust that the system would operate as it should. At a moment when medicine is working to regain the trust of many of its patients, providers are also struggling with these lessons.

“We don’t trust the systems that we’re forced to use,” Mazzola said. “It creates this fear in your heart. It used to be you saw a patient, you submitted a bill, you worked hard, and you would get paid. And then in February of 2024, we learned how fragile this digital system is.”


Share This Article

Comments

Leave a comment