Data

The Change Healthcare Data Breach: Why It Became an Architecture Failure

Quick Summary
  • The Change Healthcare data breach disrupted claims, payments, eligibility checks, and prior authorizations across the U.S. healthcare system.
  • About 94% of hospitals reported financial losses, 74% said patient care was affected, and nearly 60% lost more than $1 million a day.
  • Many affected hospitals were never hacked; they were impacted because they relied on the same clearinghouse.
  • The breach exposed a security problem, but the outage exposed an architecture problem.

 

This blog explains the entire incident, why switching clearinghouses is difficult, how healthcare organizations can keep their systems running during a vendor outage, and how to build more reliable healthcare integration systems.

Table of Contents

Introduction

A hospital can have good security, no malware on its systems, no data breach of its own, but still face serious problems. The chart below shows how the number of individuals affected by healthcare data breaches has changed over the years.

Individuals affected by healthcare data breaches

That is exactly what happened during the February 2024 Change Healthcare cyberattack.

Change Healthcare is a healthcare technology company (now part of UnitedHealth Group’s Optum, following the 2022 acquisition) that helps hospitals, pharmacies, and insurance companies manage important tasks such as claims, patient eligibility checks, prior authorizations, and payments.

When attackers shut down its systems, the breach affected 192.7 million individuals and involved sensitive healthcare and personal information.(source)

However, the long-term impact of the Change Healthcare data breach came from something else: it showed how much of the healthcare system depends on a small number of shared vendors, and how difficult it becomes for organizations to continue operating when one of these vendors fails.

So, let’s understand in detail what happened during the Change Healthcare breach attack, why hospitals with no security failures of their own still experienced major disruption, and what healthcare organizations can do to remain operational when a critical vendor fails.

Understanding the Change Healthcare Data Breach 2024

Have a look at what happened through a chronological timeline.

Infographic explaining why security hardening alone cannot prevent healthcare outages, covering vendor risks, HIPAA compliance, and operational resilience.

What Happened?

The Change Healthcare data breach began on February 12, 2024. Hackers broke into the company’s network using stolen login credentials. They stayed hidden inside the system for nine days before launching the ransomware attack on February 21.

During that time, they stole about 4 TB of data. UnitedHealth Group later paid $22 million. But it didn’t work; the hacker who got the payment kept the money and leaked the data anyway.

How Attackers Got In

The attackers did not exploit a Citrix software vulnerability. They simply logged in using stolen login credentials that belonged to a low-level support employee. Those details gave them access to a Citrix remote access portal, one that didn’t have multi-factor authentication (MFA) turned on.

Although this Citrix portal came to UnitedHealth through the 2022 acquisition, it was never brought up to UnitedHealth’s security standards.

This detail matters because many reports wrongly describe this as a “Citrix vulnerability.” In truth, the attackers just used valid login details on a system that was missing one extra layer of protection.

Impact of the Change Healthcare Data Breach

  • Claims processing came to a halt, so providers couldn’t submit insurance claims.
  • Patient eligibility checks and prior authorizations were disrupted, and patient care was delayed as a result.
  • E-prescribing and payment processing were affected, affecting pharmacies, hospitals, clinics, and insurers nationwide.
  • UnitedHealth’s cyberattack-related costs through Q3 2024 totaled $2.457 billion. (source)
  • Healthcare providers took significant losses because claims and payments could not be processed during the downtime.

Why the Change Healthcare Breach Itself Is Not the Main Lesson

The absence of multi-factor authentication (MFA) allowed the hackers to gain access to the network. This is the security failure. However, the overall lesson here is about the software architecture.

A failure in one system should not disrupt the entire healthcare system.

Whether it remains localized or leads to a national-level Change Healthcare outage depends on the healthcare clearinghouse architecture, system design, and service connectivity.

Why Hospitals That Were Never Breached Still Went Down

Most Change Healthcare data breach articles mention how attackers entered, but they do not explain why hospitals across the country stopped billing. To understand that, we need to look at the role Change Healthcare played in the healthcare ecosystem.

Change Healthcare's Role in the Ecosystem

Change Healthcare worked as a healthcare clearinghouse, connecting healthcare providers with insurance companies. It handled important transactions such as:

  • Eligibility verification
  • Prior authorizations
  • Claims submission
  • Remittance processing
  • E-prescribing

The company processed billions of healthcare transactions annually and supported a large portion of U.S. healthcare payment workflows.

Also, because so many organizations depended on it, a disruption affected the entire healthcare ecosystem.

The Hidden Single Point of Failure

One of the biggest lessons from the Change Healthcare data breach is that many hospitals and healthcare providers relied on one integration partner for all of their insurance transactions.

After the incident, the American Hospital Association (AHA) found that when the clearinghouse went offline, they didn’t have a backup system or another provider to keep things running.

The AHA also found that the impact was different for every organization. Hospitals with stronger cash reserves, backup integration partners, or less dependence on Change Healthcare recovered more quickly than those that relied on it for almost everything.

Stats AHA Survey Revealed

The AHA survey showed how serious the Change Healthcare data breach and the resulting outage became across the healthcare industry:

  • 94% of hospitals reported a financial impact.
  • 74% said patient care was directly affected.
  • 33% reported the disruption affected more than half of their revenue.
  • Nearly 60% reported losing more than $1 million per day at the peak of the outage.
  • Two-thirds of hospitals said switching to another clearinghouse was difficult or very difficult. (source)

These numbers show that the biggest challenge was not just the cyberattack. It was the lack of an alternative when a critical service became unavailable.

Reid Health: A Real-World Example of Third-Party Risk

Reid Health is a regional healthcare system in Indiana that did not suffer from the Change Healthcare data breach directly but still experienced severe issues as it relied on Change Healthcare for claims submission and revenue cycle management processes.

As Reid Health’s CIO Muhammad Siddiqui stated:

“This event was a wake-up call, but systemic change requires stronger collaboration between healthcare providers, vendors and regulatory agencies,” he said. “Proactive cybersecurity measures, more stringent vendor accountability and improved response frameworks must remain top priorities to prevent a repeat of this crisis.” (source)

This shows that even without being directly attacked, a company may suffer from severe consequences.

Security Failure vs Architecture Failure

The Change Healthcare data breach was a security failure. The widespread disruption, however, was an architecture failure across the healthcare ecosystem.

There were two failures here, and they belong to different teams.

The security failure was how the attackers got in: a remote access portal with no MFA. That is a gap a security team owns, and fixing it lowers the odds of a break-in.

The architecture failure was why one break-in took down hospitals that were never touched.

They had wired everything to a single clearinghouse with no backup path, so when it went down, they went down too. That is not a missing security control. It is a design choice about how much you depend on one vendor.

The lesson: strong security helps stop the attack. Resilient architecture decides whether that attack stays contained or turns into a nationwide outage. You need both.

What Actually Happens When a Clearinghouse Goes Down

Most healthcare organizations treat “the clearinghouse” as one integration: if it’s down, it’s down. In practice, it handles several distinct HIPAA transaction types, and each breaks a different part of hospital operations on its own timeline.

Transaction What It Does What Happens If It's Down When You Notice the Impact
270/271 Eligibility Checks if a patient's insurance is active before a visit Staff can't confirm insurance, which delays patient registration Within hours
278 Prior Auth Requests approval from the insurer before certain treatments Surgeries, imaging, and other treatments may be delayed Within hours
837P/I/D Claims Sends insurance claims for payment Claims cannot be submitted, so payments are delayed Within days
276/277 Claim Status Checks the status of submitted claims Billing teams can't see whether claims are approved or denied Within days
835 Remittance Automatically records insurance payments Payments may arrive, but they have to be processed manually Within weeks

Insurance eligibility checks and prior authorizations are affected almost immediately because they happen in real time. Claims and payments take longer to show problems, but over time they have the biggest impact because they delay revenue.

The important point is that every transaction fails differently. Understanding these dependencies helps you decide which services need backup paths first.

Why You Can't Simply Switch to Another Clearinghouse

The Change Healthcare data breach showed that switching to another clearinghouse during an emergency is far more difficult than many organizations expected.

1. Setting Up a New Clearinghouse Takes Time

During a healthcare clearinghouse outage, switching to a new clearinghouse is not something you can do in a day. Before you can send claims, each insurance company must approve the new connection. This process usually takes 2 to 4 weeks for each payer.

Setting up the clearinghouse also takes time. A basic setup may take 1 to 2 weeks, while a larger enterprise setup can take 4 to 8 weeks.

2. Insurance Companies May Not Allow an Immediate Switch

Some insurance companies accept claims through only one approved clearinghouse at a time. In some cases, only one active registration is allowed.

This means that even if you have another clearinghouse ready, you may still have to wait for the insurance company to approve it before you can use it.

That is why simply adding another vendor is not enough. The setup and testing must be completed before an outage happens.

3. Keeping a Backup Requires Planning

Maintaining a standby clearinghouse is not simple or inexpensive. According to the AHA, organizations need a second vendor relationship, active payer registrations, and regular testing to ensure the backup works when needed.

If we talk about what happened during the outage:

  • SSI Group accepted emergency 837 electronic claims from affected providers.
  • Office Ally onboarded new practices within days.
  • Availity launched its Lifeline support program, supporting 300,000+ providers affected by the outage. (Source)

The organizations that recovered the fastest were the ones that already had backup plans in place.

4. Getting Back to Normal Also Takes Time

Recovery did not end when Change Healthcare came back online. Many providers had to set up their payer connections again before normal operations could resume.

The lesson is simple: switching to another clearinghouse is not a quick fix. A backup only works if it is planned, set up, and tested before an outage occurs.

How to Build a Healthcare Integration Layer That Keeps Running During Outages

There are going to be times when incidents like Change Healthcare outages cannot always be prevented, but they can be planned for. Here are some practical ways to keep important systems running even when a clearinghouse goes down.

Use a Routing Layer Between Your System and the Clearinghouse

  • Do not connect your EHR or practice management system directly to one clearinghouse.
  • Add a transaction routing layer that handles X12 transactions, payer mapping, and where each transaction is sent.
  • This makes the clearinghouse a setting that can be changed instead of a fixed part of your system, making it much easier to switch vendors.

Plan a Backup for Each Insurance Company

  • Plan clearinghouse redundancy for each payer, not just by adding another clearinghouse.
  • If a payer allows two clearinghouses, set up the second one in advance and regularly send a small amount of live traffic through it to make sure it works.
  • If a payer allows only one clearinghouse, use the payer’s online portal as the backup and keep transactions in a durable queue until they can be sent.
  • A backup that has never been tested may not work during an outage.

Store Claims Instead of Rejecting Them

  • Never reject a claim because a clearinghouse or downstream service is unavailable.
  • Store every transaction in a durable queue, retry automatically with backoff, and replay it after the service is restored.
  • Design the queue to support multi-week outages and ensure claims still meet timely filing deadlines.

Have a Backup for Every Type of Transaction

  • Eligibility: Use cached coverage information and a payer portal as a backup.
  • Prior authorization: Route urgent requests directly through the payer portal.
  • Claims: Queue claims automatically and use manual bulk uploads when necessary.
  • Remittance: Receive 835 files through an alternate path and reconcile them later.

Test Your Recovery Plan Regularly

  • Set a separate Recovery Time Objective (RTO) for each business function instead of one target for the entire clearinghouse.
  • Example targets: 4 hours for clearinghouse connectivity, 8 hours for payment posting, and same day for eligibility verification.
  • Test your failover process at least twice a year because a recovery plan that has never been tested cannot be trusted.

These practices do not prevent every outage, but they help keep critical healthcare operations running when one happens.

Healthcare Integration Resilience Checklist

Use this checklist to see if your healthcare integration is ready for an outage like the Change Healthcare data breach. The more boxes you can check, the better prepared your organization is.

✓ Check if: Why it Matters
Your integration layer can switch between clearinghouses without changing EHR workflows. Prevents a single clearinghouse from becoming a single point of failure.
Per-payer routing rules and enrollment requirements are documented. Reduces delays when rerouting transactions.
Secondary clearinghouse connections are pre-enrolled and tested where permitted. Enables faster recovery during an outage.
Claims are stored in a durable queue and can be replayed after service restoration. Prevents transaction loss.
Eligibility checks can fall back to cached responses when live services are unavailable. Allows patient registration to continue.
Critical prior authorizations have an alternate submission path. Keeps urgent patient care moving.
Monitoring tracks the health of each transaction type (837, 835, 270/271, etc.). Identifies failures before they affect operations.
Recovery Time Objectives (RTOs) are defined and tested regularly. Ensures recovery plans work in practice, not just on paper.

Why Security Hardening Alone Will Not Prevent the Next Outage

With years of experience at Bacancy, our experts have come up with top reasons why security hardening alone will not prevent the next outage, such as the Change Healthcare data breach.

Strengthen Your Security Foundation

  • Protect every remote access point with phishing-resistant MFA, including systems inherited through acquisitions.
  • Segment your network so one compromised system cannot access claims, identity, and payment systems.
  • Encrypt PHI so that if any healthcare information is stolen, it cannot be read.
  • Design systems such that they can be rebuilt from code rather than relying on backups that might have already been compromised.

Security Controls Cannot Prevent a Vendor Outage

  • Security measures discussed above will certainly decrease chances of an attack on your company.
  • However, they will not prevent a business interruption when a breach happens to a critical vendor, such as a clearinghouse.
  • Preventing attacks and maintaining operations during a vendor outage require two different strategies.

What the Proposed HIPAA Security Rule Covers

  • These proposed requirements, including MFA, encryption, network segmentation, asset management, and vulnerability assessment, are included in the proposed HIPAA Security Rule released in January 2025.
  • The HIPAA Security Rule is at its proposal stage as of mid-2026, where the comment period ended in March 2025, and several healthcare organizations have requested HHS to amend or withdraw the proposal.
  • In mid-2026, HHS pushed final action back from May 2026 to July 2027 and moved the rule to its long-term regulatory agenda, so there is no confirmed timeline for a final rule. (source)

Compliance Does Not Equal Operational Resilience

  • Even if the proposed rule is finalized, it does not require organizations to build a second claims route or backup clearinghouse.
  • Compliance helps improve security, but it does not guarantee that healthcare operations will continue during a vendor outage.

Need complete visibility across your healthcare operations?

Leverage our healthcare data analytics services to connect disparate data sources and gain real-time insights for smarter decisions.

Vendor Risk Is an Industry Reality

  • In early 2026, TriZetto Provider Solutions disclosed a security incident affecting about 3.4 million people.
  • The Change Healthcare data breach is a reminder that every healthcare vendor can become a target, regardless of its size.
  • Every healthcare organization should design its systems to continue operating when a critical vendor becomes unavailable.

Build for Failure Not Just Prevention

  • Breaches are becoming more common, not less. Large healthcare data breaches climbed from 741 in 2024 to 772 in 2025, the highest number ever recorded in a single year. (source)
  • The lesson is simple. You cannot prevent every attack, so do not plan as if you can. Assume something will go down at some point, whether it is your own system or a vendor you depend on.
  • Build your operations so that when it happens, work keeps moving with as little disruption as possible.

How Bacancy Helps You Build Resilient Healthcare Integration Systems

Healthcare organizations need systems that can keep running when a critical vendor becomes unavailable. At Bacancy, our EHR integration services help healthcare organizations build secure, reliable, and resilient integration systems. Here’s what we can help you with.

Start With a Dependency Map

  • We review your complete claims process, from EHR/PMS → Billing System → Clearinghouse → Payer.
  • We identify which insurance companies support two clearinghouses and which rely on only one.
  • We provide a payer-by-payer dependency map and an RTO gap analysis so you can see where the biggest risks are before making changes.

Build a Flexible Routing Layer

  • We build a transaction routing layer between your healthcare systems and the clearinghouse.
  • We manage EDI X12 claims processing, including X12 transaction generation, payer mapping, and transaction routing, in one central place.
  • This reduces your dependence on a single clearinghouse and makes it much easier to change routing when needed.

Make Claims More Resilient

  • We build durable queues that safely store claims and replay them when systems are available again, helping you meet filing deadlines.
  • We create backup workflows for eligibility checks, prior authorization, claims, and remittance processing.
  • This helps keep your revenue cycle running even during a vendor outage.

Test Recovery Before an Outage Happens

  • We help you create and test healthcare disaster recovery and failover plans before they are needed.
  • We regularly test routing, queuing, and recovery processes to make sure they work.
  • This gives you confidence that your backup processes will be ready during an outage.

Healthcare Integration Expertise

  • Our team supports transactions such as 837P/I/D, 835, 270/271, 276/277, and 278 from the field of healthcare.
  • Our integration support includes leading EHR applications such as Epic, Cerner, Athenahealth, and MEDITECH.
  • We also build healthcare integration solutions using HL7 and FHIR standards for healthcare interoperability and secure data sharing between systems.

Start with a dependency map. If you are unsure about how long your organization will be able to process claims in the absence of the clearinghouse, we can assist you in identifying risks and developing a better healthcare integration architecture overall.

Conclusion

The Change Healthcare data breach incident was not just a cybersecurity threat; it was an example of how failure in one vendor can affect the entire process from claims to payments to patients’ well-being. Strong security helps prevent attacks. Resilient integration architecture is essential for healthcare system resilience, helping healthcare organizations continue operating when a critical vendor becomes unavailable.

Closing that gap requires more than strong security. It requires backup routing, tested failover plans, and recovery processes built in advance. This is where we offer healthcare IT consulting services to help healthcare organizations identify vendor dependencies, build backup paths, and test them before an outage happens, so claims, payments, and patient care keep running no matter what fails.

FAQ

Was a Citrix vulnerability exploited in the Change Healthcare data breach?

No. The attackers got in using stolen login credentials on a Citrix remote access portal that did not have MFA enabled. There was no confirmed Citrix software vulnerability involved.

Would MFA alone have prevented it?

Why couldn't hospitals just switch to another clearinghouse?

Can you use two clearinghouses at the same time?

How long does it take to stand up a backup clearinghouse?

What is a clearinghouse abstraction layer?

How do you design a degraded mode for eligibility checks?

What is the difference between cybersecurity resilience and operational resilience?

Does the proposed HIPAA Security Rule require network segmentation?

How long did providers take to recover from the Change Healthcare outage?

Vivek Chhatbar

Vivek Chhatbar

Healthcare Full Stack Developer at Bacancy

Delivers end-to-end healthcare solutions covering frontend, backend and cloud deployment.

MORE POSTS BY THE AUTHOR