What the Change Healthcare breach taught us about health data infrastructure trust
Photo by laura adai on Unsplash

What the Change Healthcare breach taught us about health data infrastructure trust

By Jason Alan Snyder·May 11, 2026

The Change Healthcare breach exposed 100 million patient records and paralyzed claims processing for months. But the deeper failure was not the ransomware itself. It was the absence of any trust verification layer across health data infrastructure, meaning no one could confirm what data had been altered, accessed, or corrupted after the attack.

The February 2024 ransomware attack on Change Healthcare exposed protected health information for over 100 million Americans. It was the largest healthcare data breach in U.S. history. But the breach itself was only half the story.

The other half is what happened after. Health systems could not verify which records had been accessed, altered, or corrupted. Claims processing froze for weeks. Providers lost billions in delayed reimbursements. And no one had a systematic way to confirm the integrity of the data flowing back online.

That is the infrastructure trust problem. Security tells you whether someone got in. Trust tells you whether the data that came out the other side is still reliable.

How the Change Healthcare breach actually happened

The attack began with compromised credentials on a Citrix remote access portal that lacked multi-factor authentication. The ALPHV/BlackCat ransomware group used those credentials to move laterally through Change Healthcare's network for nine days before deploying ransomware on February 21, 2024.

Change Healthcare, owned by UnitedHealth Group, processes approximately 15 billion healthcare transactions per year. It touches nearly one in every three U.S. patient records. When it went down, the blast radius was not limited to one hospital or one insurer. It hit the connective tissue of the entire U.S. healthcare payment system.

UnitedHealth Group confirmed it paid a $22 million ransom. Total costs exceeded $2.87 billion through Q3 2024, including breach remediation, provider support, and lost revenue.

What are the lessons from the Change Healthcare ransomware attack?

The most cited lesson is the obvious one: enforce multi-factor authentication everywhere. That is correct but insufficient.

The harder lesson is that healthcare has built massive centralized data chokepoints with no integrity verification layer. When a single entity processes 15 billion transactions annually and has no mechanism to confirm data fidelity after a breach, the entire system operates on blind trust.

Three structural lessons stand out:

Single points of failure are systemic risk. Consolidation in health data infrastructure means a single breach can cascade across thousands of providers and hundreds of payers simultaneously.

Security is not the same as trust. Firewalls and encryption protect data at rest and in transit. They say nothing about whether a record was modified, whether its provenance chain is intact, or whether it is still clinically accurate after an incident. As we have written before, HIPAA compliance alone does not guarantee data trust.

Post-breach data integrity is uncharted territory. After the Change Healthcare systems came back online, providers had to assume their data was intact. There was no scoring mechanism, no automated verification, no way to flag records that might have been tampered with during the nine-day window of unauthorized access.

Is the data breach at Change Healthcare legit?

Yes. The U.S. Department of Health and Human Services Office for Civil Rights confirmed the breach. UnitedHealth Group disclosed it in SEC filings and public statements. The breach notification process reached over 100 million individuals. It is the most extensively documented healthcare cyberattack in history.

Recent incidents confirm this is not an isolated pattern. MedPageToday reported in March 2026 that medical device maker Stryker experienced a cyberattack affecting its surgical technology platforms, defibrillators, and cardiac monitors. Separately, health data for 500,000 members of the U.K. Biobank project was found listed for sale on Alibaba. The attack surface in healthcare keeps expanding.

What insurance companies are affected by the Change Healthcare breach?

Change Healthcare's network connects to virtually every major U.S. health insurer. UnitedHealthcare was directly affected as a subsidiary of the same parent company. Aetna, Cigna, Humana, Blue Cross Blue Shield affiliates, and hundreds of regional plans experienced claims processing disruptions. The American Hospital Association reported that 94% of hospitals experienced financial impact from the attack.

What is the most hacked website in the world?

Healthcare is consistently the most targeted industry for cyberattacks, not a single website. The average cost of a healthcare data breach reached $10.93 million in 2023, according to IBM's Cost of a Data Breach Report. That is more than double the cross-industry average. Healthcare has held the top position for 13 consecutive years.

The reason is simple: health data is worth more on the black market than credit card numbers. A single health record sells for up to $250, compared to $5 for a credit card number. And unlike a credit card, you cannot cancel your medical history.

Key statistics

Change Healthcare breach by the numbers
Change Healthcare breach by the numbers

  • 100 million+ patient records exposed in the Change Healthcare breach, the largest in U.S. healthcare history
  • $2.87 billion in costs reported by UnitedHealth Group through Q3 2024
  • 94% of U.S. hospitals reported financial impact from the attack (American Hospital Association)
  • 15 billion healthcare transactions processed annually through Change Healthcare before the breach
  • 9 days of undetected attacker access before ransomware deployment
  • Why security alone does not solve the trust problem

    DTI dimensions most degraded after a data breach
    DTI dimensions most degraded after a data breach

    After the Change Healthcare systems were restored, every downstream provider and payer had to make a judgment call: can we trust the data flowing through this pipe again?

    Most had no tools to answer that question. There was no provenance score on individual records. No automated concordance check between pre-breach and post-breach data states. No recency verification to confirm that restored records reflected the most current clinical information.

    This is the gap that data trust infrastructure is designed to fill. Security protects the perimeter. Trust scores the contents.

    The Data Trust Index scores every health data record from 0 to 100 across eight dimensions: Provenance (25%), Consent (20%), Recency (15%), Quality (10%), Concordance (10%), Validation (10%), Breadth (5%), and Stability (5%). In a post-breach scenario, Provenance, Concordance, and Recency are the three dimensions that degrade fastest and matter most.

    When SuperTruth onboarded 105,000 diagnostic records from imaware, the DTI Engine identified integrity gaps that manual review had missed entirely. Processing time dropped from three weeks to two hours. That kind of automated trust verification is exactly what the post-breach recovery playbook is missing.

    What changes from here

    The Change Healthcare breach forced a reckoning. HHS proposed new cybersecurity requirements for HIPAA-covered entities in December 2024. Congress held multiple hearings. UnitedHealth Group's CEO testified before the Senate Finance Committee.

    But most of the proposed fixes focus on preventing the next breach. Stronger passwords. Better network segmentation. Faster incident reporting. Those are necessary. They are not sufficient.

    The missing layer is data integrity verification that operates continuously, not just at the perimeter, not just after an incident, but as a scoring function applied to every record at the point of ingestion and every time that record is queried. Audit trails must become a first-class infrastructure component, not an afterthought.

    Healthcare cannot afford to keep rebuilding trust on faith after every breach. It needs a system that measures trust, scores it, and makes it queryable.

    The DTI Engine scores every health data record 0 to 100 across 8 trust dimensions before your AI model sees it. If your team is evaluating data integrity after a breach, building post-incident recovery protocols, or deploying clinical AI on data that has passed through centralized infrastructure, schedule a conversation with the SuperTruth commercial team or (215) 918-4140.

    Further reading:

  • DTI™ Engine
  • Health systems solution
  • What HIPAA does not tell you about data trust
  • Infrastructure trust vs data trust: why most healthcare data platforms miss the point
  • Why audit trails are the foundation of health AI accountability
  • Jason Alan Snyder

    Jason Alan Snyder

    Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.

    About SuperTruth · LinkedIn · Substack · jasonalansnyder.com

    See it in practice

    DTI scores the record, not the patient.

    8 dimensions. 0 to 100. Travels with every record permanently.

    See the DTI Engine
    Share
    What the Change Healthcare breach taught us about health data infrastructure trust | SuperTruth