The Claims Clearinghouse Market, 2022-2024
Ask an American what happens after a doctor's visit and most will describe something vague: the office "bills the insurance," and eventually a statement arrives. Almost nobody can name the machinery in between. That machinery has a name — the claims clearinghouse — and for roughly half of the United States, by early 2024, that machinery was a single company: Change Healthcare.
A clearinghouse is a translator and a switchboard. A medical practice generates a claim in its practice-management software; the claim must reach one of hundreds of payers — commercial insurers, Medicare administrative contractors, state Medicaid programs — each with its own formats, edits, and quirks. Rather than build hundreds of connections, providers send everything to a clearinghouse, which validates the claim, translates it into the payer's dialect of the X12 837 standard, routes it, and carries the responses — acknowledgments, rejections, remittances — back the other way. The same rails carry eligibility checks, prior authorization transactions, and electronic pharmacy claims adjudicated in real time while a patient stands at the counter.
Change Healthcare was the largest of these switchboards. By its own figures it touched one in three American patient records and processed about 15 billion healthcare transactions a year — on the order of $1.5 trillion in claims. In 2022, UnitedHealth Group, the largest health company in the world, acquired Change for $13 billion and folded it into its Optum subsidiary, over the objections of the Department of Justice, which had sued to block the deal on antitrust grounds and lost. The DOJ's case had centered on data and market power. What happens when half the country's medical billing runs through one set of servers went unasked in that courtroom.
The answer arrived on February 21, 2024.
Network Intrusion, February 2024
The intrusion did not begin on February 21. According to the timeline UnitedHealth CEO Andrew Witty later gave the United States Congress, attackers first entered Change Healthcare's network on February 12 — nine days before anyone noticed.
The attackers logged into a Citrix remote-access portal — the kind of system that lets employees and contractors reach internal applications from outside — using compromised credentials. The portal did not have multi-factor authentication enabled. No exploit was needed: a username and a password, likely purchased or harvested from an infostealer log, typed into a login page that asked for nothing else.
The absence of MFA on that portal would become the single most-quoted fact of the entire incident. Multi-factor authentication had been, by 2024, a baseline expectation for a decade; it was required by UnitedHealth's own stated policy. Witty, under oath before the Senate Finance Committee in May 2024, could offer no explanation beyond the fact that Change Healthcare's technology estate was old, recently acquired, and still being brought up to the parent company's standards. Change had been assembled through years of mergers — Emdeon, WebMD's business side, McKesson's technology unit — and its infrastructure was a sediment of decades. The Citrix portal with password-only authentication was one grain of that sediment.
For nine days the attackers moved laterally through the network, escalating privileges, mapping the environment, and exfiltrating data. Then, on February 21, they detonated ransomware.
ALPHV and Ransomware-as-a-Service
The ransomware was deployed by an affiliate of ALPHV, also known as BlackCat, at the time one of the most prolific ransomware-as-a-service operations in the world and a group with a documented appetite for healthcare targets.
Ransomware-as-a-service explains much of what followed. ALPHV's core operators did not, themselves, break into Change Healthcare. They built and maintained the ransomware, ran the payment and negotiation infrastructure, and operated a leak site for extortion. Independent "affiliates" carried out intrusions and deployed the malware, splitting proceeds with the operators — typically keeping 70 to 90 percent. The affiliate in this case was reportedly an experienced access broker-turned-operator known in criminal forums as "Notchy."
Two months earlier, in December 2023, the FBI and international partners had announced a takedown of ALPHV's infrastructure, seizing its leak site and releasing a decryption tool. ALPHV "unseized" its site within days, posted a defiant message removing its previous rule against attacking hospitals, and carried on. The takedown had wounded the brand without dismantling the organization, and may have made its operators both more reckless and more inclined toward an exit.
Systems Disconnection, February 21, 2024
When Change Healthcare's security teams found the ransomware on the morning of February 21, they did the only thing that reliably stops an encryption event in progress: they disconnected. Not selectively — wholesale. More than a hundred Change Healthcare applications went dark at once: claims submission, remittance, eligibility, clinical data exchange, pharmacy switching, payment services.
As a piece of incident response, the disconnection was defensible, even praised. It plausibly stopped the attackers from spreading into Optum, UnitedHealthcare, and the rest of the UnitedHealth empire, and Witty would testify that the blast radius was contained to Change. But the same act that protected UnitedHealth transferred the damage, instantly and completely, onto everyone downstream. Every provider, pharmacy, and payer wired into Change's rails discovered — most of them that morning, with no warning beyond a terse status page — that the pipes were simply gone.
The first visible symptom, within hours, was at pharmacy counters. Pharmacies could not run electronic claims to determine copays or confirm coverage. Some reverted to paper. Some asked patients to pay cash and seek reimbursement later. Some, particularly small independents, simply could not dispense against unknowable prices. Military pharmacies as far away as bases in Europe reported disruptions. For patients, this was the incident: the prescription that suddenly cost $800, the insulin refill delayed, the pharmacist apologizing for a computer problem no one could explain.
The pharmacy disruption resolved within days as pharmacies rerouted to other switches. The claims themselves took longer to recover.
Provider Cash Flow Disruption
A medical practice is, financially, a machine that converts services into claims and claims into cash on a roughly two-to-six-week cycle. Payroll, rent, and supply costs are continuous; revenue arrives as the payers remit. Interrupt the claims flow and the machine keeps consuming cash while producing none.
That is precisely what happened, at national scale, for weeks. Providers who used Change as their clearinghouse could not submit claims. Providers who used other clearinghouses were often still affected, because Change also sat on the payer side of many connections, or handled their eligibility checks, or processed their remittances. The American Hospital Association called it the most significant cyberattack on the U.S. health care system in history. Surveys in March 2024 found the great majority of hospitals reporting revenue impact, and a third of physician practices unable to make payroll or forced to tap personal funds and lines of credit. Estimates of withheld payments ran to more than $100 million per day at the peak. Small practices — the rural clinic, the solo psychiatrist, the physical-therapy office — had the least buffer and the least ability to stand up an alternate clearinghouse quickly, since switching requires re-enrollment with each payer, a process measured in weeks.
UnitedHealth began offering assistance: a temporary funding program of no-interest advances, later expanded under heavy criticism that its initial terms were meager and its repayment demands aggressive. The company would ultimately advance over $9 billion to providers, and would later draw fresh criticism for the vigor with which it clawed those advances back. The federal government improvised too — CMS allowed accelerated Medicare payments and encouraged payers to relax prior-authorization and timely-filing rules — but there was no playbook. Nothing in the nation's emergency machinery contemplated the failure of a billing intermediary as a public-health event.
Restoration was incremental. Pharmacy services returned first, in early March. Electronic payments resumed mid-March. Claims flow through the main clearinghouse — Assurance and related platforms — restarted in the second half of March, and the backlog took months to drain. Some Change products never came back at all; customers were migrated or simply left.
Ransom Payment and Second Extortion, March-April 2024
On March 1, 2024, a payment of 350 bitcoin — about $22 million — moved into a wallet associated with ALPHV. Witty later confirmed to Congress what blockchain analysts had already inferred: UnitedHealth paid the ransom. He called it one of the hardest decisions he had ever made, and framed it as an attempt to protect patient data.
ALPHV's operators took the $22 million and vanished — an "exit scam," in the argot of the underground. They posted a fake law-enforcement seizure banner on their own leak site and stiffed their affiliate, Notchy, of his share. Notchy, who claimed to still hold the stolen data — ALPHV had taken the money, but the affiliate had the terabytes — took that data to a different extortion operation, RansomHub, which listed Change Healthcare on its leak site in April and demanded payment again. Portions of data were published as proof. Whether any second payment was made has never been confirmed.
UnitedHealth paid $22 million to a party that then lost control of, or never surrendered, the data. The money bought nothing verifiable. It did, however, fund and advertise the criminal ecosystem: security researchers documented a wave of new ransomware activity against healthcare targets in the months after the payment became public.
Breach Scope and Financial Impact
The final accounting took more than a year to stabilize, and each revision was worse.
UnitedHealth initially estimated the breach affected "a substantial proportion of people in America." By October 2024 the figure filed with regulators was 100 million individuals, already the largest healthcare data breach ever reported to the U.S. government. In January 2025 it was revised to about 190 million: more than half the population of the United States. The compromised data varied by individual but spanned names, Social Security numbers, diagnoses, medications, test results, and insurance and banking information.
The direct financial toll on UnitedHealth exceeded $3 billion in response costs, on top of the provider advances. The company's CISO at the time of the attack became a subject of congressional scrutiny when it emerged he had not held a full-time security role before taking the job. Lawsuits consolidated into multidistrict litigation. The Office for Civil Rights at HHS opened a rare public investigation into whether Change itself — the covered entity's business associate — had complied with the HIPAA Security Rule. Congress, across multiple hearings, returned repeatedly to a question that had nothing to do with malware: how had the health system been allowed to develop a single point of failure this large?
Contributing Factors and Aftermath
The absence of MFA on the Citrix portal was real and causal, but it explains little on its own. Every large enterprise harbors forgotten portals; the harder questions concern the conditions that let one forgotten portal become a $3 billion, 190-million-person event.
Change entered UnitedHealth carrying decades of merged-and-remerged infrastructure, and the integration was, by Witty's own testimony, incomplete when the attackers arrived. Security due diligence in M&A tends to be a checklist exercise priced into the deal. This case argues for treating an acquired network as hostile until inventoried, and for making basic control parity — MFA everywhere, in this instance — a gating condition of connectivity rather than a post-close aspiration.
The most consequential decisions were made years before the intrusion, by executives and antitrust courts, when the industry allowed claims processing to consolidate to the point that one company's incident response could freeze cash flow for a third of American providers. Resilience regulation in finance has long recognized systemically important institutions; healthcare had no equivalent concept, no requirement that a systemically important intermediary maintain segmented, independently survivable services, and no obligation for its customers to maintain a tested secondary route. After February 2024, "who is your clearinghouse's backup, and have you actually enrolled?" became a standard question in provider risk assessments. It had rarely been asked before.
Disconnecting everything protected UnitedHealth and devastated its dependents. That is not an argument against disconnection. It is an argument that a utility-scale intermediary's incident-response plan is not private. Providers widely described communication in the first days as inadequate: status updates without timelines, no clarity about what data was compromised, assistance programs that arrived late and lean. An entity whose failure is a sector-wide event owes the sector a crisis plan, drilled in advance, that includes the people downstream.
The ALPHV exit scam is the cleanest demonstration on record that payment purchases neither deletion nor silence, only a claim on the goodwill of people whose profession is extortion. The $22 million also served as marketing for attacks on the sector that paid it.
One hundred ninety million people cannot meaningfully "monitor their credit" as remediation. When a single breach covers most of a population, the policy conversation has to shift from individual notification-and-monitoring rituals toward questions of data minimization and retention. Why did a claims switch hold enough historical clinical and financial detail on 190 million people to make this possible at all?
The pipes were eventually rebuilt, much of the restored infrastructure stood up fresh, with help from Google, Microsoft, Amazon, and Mandiant, arguably leaving Change more modern than before. Providers diversified clearinghouses. Congress drafted bills tying Medicare payment to minimum cybersecurity standards. UnitedHealth remained, after the attack as before it, the indispensable intermediary of American healthcare finance.
Healthcare cybersecurity, this episode showed, is not primarily about hospitals' firewalls or clinicians' phishing training. The gravest risk had migrated to the administrative substrate — the translators and switchboards patients never see — where a single password, on a single portal, at a single company, proved sufficient to disrupt prescriptions in all fifty states within hours. </content>