In February 2024, attackers gained access to Change Healthcare, a UnitedHealth Group subsidiary that processes approximately forty percent of all medical claims in the United States.
- Share of US medical claims
- ~40%
- People whose data was compromised
- ~190,000,000
- Proportion of Americans
- Close to one in two
- Initial access mechanism
- A stolen credential
- Multifactor on that portal
- None
Compromised-records figure as stated by UnitedHealth Group.
The initial access mechanism was not sophisticated. Attackers used stolen credentials to log into a Citrix remote access portal that did not require multifactor authentication. That is not an exotic technique. It is one of the most commonly documented initial access vectors in incident reporting, cited in breach after breach across industries and years.
The disclosures that followed were extensive. Form 8-K notifications. Congressional testimony. HHS guidance. Viewed from inside the regulatory framework, the response was thorough. Notifications were timely. Disclosures were filed.
What the regulatory process did not produce was a structured account of how a platform processing forty percent of national medical claims came to operate a critical remote-access portal without multifactor authentication. Those findings emerged gradually, in investigative journalism and congressional questioning, months later. They were not a product of the disclosure system.