On February 21, 2024, a ransomware attack struck Change Healthcare—the largest medical claims clearinghouse in the United States—triggering what the American Hospital Association characterized as the most significant and consequential cyberattack on the U.S. healthcare system in history. The incident was attributed to ALPHV/BlackCat, a Russia-linked ransomware group previously associated with the 2021 Colonial Pipeline disruption, underscoring how threat actors targeting critical infrastructure operate across multiple sectors with consistent and damaging effect.
The attack’s entry point was a compromised credential on a Citrix remote access portal that lacked multi-factor authentication—a fundamental security gap that allowed attackers to penetrate systems processing approximately $1.5 trillion in U.S. medical claims annually. Once inside, ALPHV/BlackCat employed double-extortion tactics, simultaneously encrypting systems and exfiltrating an estimated 4 to 6 terabytes of data. The stolen information included protected health information, Social Security numbers, driver’s license and passport numbers, and financial payment card data. A July 2024 breach report to federal regulators confirmed the scope of exposed personally identifiable and health information extended to a substantial proportion of people across the United States.
The operational consequences were immediate and severe. Change Healthcare’s electronic data interchange systems connected thousands of providers, payers, and pharmacies nationwide. When those systems went offline, the disruption cascaded across the entire healthcare sector, forcing manual claims processing and alternative clearing arrangements. Revenue losses for affected healthcare providers reached an estimated $100 million per day during the outage, with smaller organizations facing acute insolvency risk.
The crisis exposed the systemic fragility embedded in centralized vendor dependencies—a single point of failure capable of immobilizing a critical national infrastructure sector.
A ransom payment of approximately $22 million in cryptocurrency was reported in connection with the attack, reportedly made to secure deletion promises from the attackers. The payment itself illustrated the economic calculus that sustains ransomware operations: concentrated data aggregation in vendor systems creates leverage that operators can monetize rapidly, regardless of downstream consequences for patients or providers. Large payments of this kind risk incentivizing further attacks, as increased ransom payments signal to other threat actors that healthcare targets will yield substantial returns. ALPHV/BlackCat’s willingness to publicly claim responsibility reflected the group’s established pattern of high-visibility attacks designed to maximize pressure on victims.
The Change Healthcare incident made clear that third-party vendor relationships represent one of the most consequential and underexamined risk surfaces in healthcare cybersecurity. The American Hospital Association called for urgent action at both the organizational and sectorwide level, citing vendor incidents as evidence that existing cyber preparedness frameworks are insufficient for the concentration risk now embedded in the industry.
As healthcare organizations increasingly rely on centralized AI-enabled platforms for claims processing, prior authorization, and data exchange, the attack surface expands in proportion to that dependence—and the consequences of a single vendor compromise grow correspondingly larger for every stakeholder connected to it.







