UnitedHealth Group’s subsidiary Change Healthcare faces multiple lawsuits following a massive ransomware attack that exposed the personal information of 192.7 million individuals—nearly doubling earlier estimates and making it one of the largest healthcare breaches in U.S. history. The litigation targets Change Healthcare, UnitedHealth Group, and Optum (another UnitedHealth subsidiary) over allegations that outdated systems, inadequate security controls, and delayed breach notifications enabled attackers to steal sensitive medical and financial data between February 17-20, 2024. When Nebraska’s Attorney General filed suit in December 2024, the case exposed not just a cybersecurity failure but systemic negligence: UnitedHealth knew about the intrusion by February 21 but took months to notify the public while customers lost access to critical healthcare services.
The breach’s ripple effects extended far beyond data theft. A two-month systems outage forced healthcare providers to halt payment processing, deny prior authorizations, and prevent patients from obtaining prescriptions—consequences that triggered a wave of separate lawsuits from major healthcare systems. Indiana University Health filed its own suit in February 2026 seeking $66 million in damages, while UnitedHealth admitted to paying a $22 million ransom that didn’t prevent the data leak anyway. The litigation raises a fundamental question for healthcare consumers: When a major insurance technology company fails to implement basic security measures, who bears the cost?.
Table of Contents
- What Is the Change Healthcare Data Breach Litigation and Why Are UnitedHealth and Optum Being Targeted?
- Scale and Scope of the Breach: Understanding the 192.7 Million Affected
- Critical Security Failures That Led to the Breach
- The Financial Burden on Healthcare Providers and Patients
- Key Litigation Details and Legal Claims
- Settlement Discussions and Ongoing Legal Actions
- What This Means for Healthcare Cybersecurity Going Forward
- Conclusion
What Is the Change Healthcare Data Breach Litigation and Why Are UnitedHealth and Optum Being Targeted?
The Change Healthcare data breach litigation is a series of coordinated lawsuits challenging UnitedHealth Group, its insurance processing subsidiary Optum, and Change Healthcare over a 2024 ransomware attack that compromised decades’ worth of sensitive patient records. The breach wasn’t a sophisticated zero-day exploit targeting advanced AI systems—it exploited well-known vulnerabilities that should have been patched years ago. Nebraska Attorney General Mike Peterson filed the first major lawsuit on December 16, 2024, in Lancaster County District Court, alleging that these companies failed to implement industry-standard security practices and then concealed the breach’s true scope from affected individuals.
UnitedHealth and Optum are being targeted because they own Change Healthcare and bore responsibility for its security posture. Under HIPAA, covered entities and business associates must implement reasonable administrative, physical, and technical safeguards to protect patient data. The lawsuits allege that UnitedHealth and Optum failed this obligation by allowing Change Healthcare to operate systems vulnerable to attack, then compounded the failure by delaying breach notifications and misrepresenting how many people were affected. Judge Susan Strong of Lancaster County allowed Nebraska’s lawsuit to survive a motion to dismiss in early 2025, finding sufficient evidence that the defendants’ conduct was not merely negligent but demonstrated a pattern of indifference to patient privacy.

Scale and Scope of the Breach: Understanding the 192.7 Million Affected
The final tally of 192.7 million affected individuals—released by Change healthcare in July 2025—represents a staggering breach that touches roughly 58% of the U.S. population. This number evolved over time: initial estimates suggested 100 million affected, then 190 million, before settling at 192.7 million. The delay in determining the final count itself became evidence of the companies’ disorganization. Within that broader number, approximately 900,000 Nebraskans had their personal information stolen, making it a state-level crisis that motivated the Attorney General’s lawsuit.
The affected data included more than just names and addresses. Stolen records contained Social security numbers, health insurance information, medical diagnoses, medication histories, and financial banking details. A healthcare worker in Nebraska, for example, might have their complete medical history (including mental health treatment and prescription records) linked to their financial accounts and Social Security number—a treasure trove for identity thieves and medical fraudsters. The breach window (February 17-20, 2024) meant attackers had undetected access to ongoing transactions and communications as Change Healthcare processed claims and authorizations across thousands of healthcare providers. One critical limitation of the public disclosure is that Change Healthcare has not clearly itemized which specific data elements were stolen from which individuals, making it difficult for victims to assess their precise exposure.
Critical Security Failures That Led to the Breach
The litigation revealed that Change Healthcare operated with security practices that would have been considered outdated even ten years ago. The company lacked multifactor authentication (MFA)—a basic control that requires users to verify their identity through multiple methods beyond just a password. It’s comparable to a bank that doesn’t require a PIN to withdraw funds, only an account number; the vulnerability is so obvious that auditors routinely flag it as a critical finding. Additionally, Change Healthcare’s IT systems were poorly segmented, meaning attackers who breached one part of the network could potentially access other systems without additional obstacles. The most damaging failure involved backup systems.
Change Healthcare stored backup copies of its data on systems connected to the same network as its primary systems, violating a fundamental principle of disaster recovery and ransomware defense. When attackers gained access to primary systems, they could move laterally to backup systems and encrypt everything, leaving Change Healthcare with no clean copy to restore from. This is equivalent to keeping your only fire extinguisher in a room filled with flammable materials. UnitedHealth’s response—offering $9 billion in no-interest advances to healthcare providers to keep them solvent during the outage—tacitly acknowledged that the company’s negligence had created an operational crisis. The two-month systems outage that followed the attack’s discovery halted payment processing, preventing healthcare providers from getting paid for services rendered and forcing many to delay vendor payments and employee wages.

The Financial Burden on Healthcare Providers and Patients
UnitedHealth Group disclosed in its financial filings that the Change Healthcare breach cost the company an estimated $3.09 billion, with potential for further increases as litigation continues. Of that, approximately $799 million was directly attributed to incident response costs in 2025. But these numbers represent only UnitedHealth’s expenses—they don’t fully capture the broader economic damage to the healthcare ecosystem. Indiana University Health filed suit in February 2026 seeking $66 million in damages, reflecting the real costs that healthcare providers absorbed when systems went offline and payment processing stopped.
When Change Healthcare’s systems shut down for two months, healthcare providers couldn’t access insurance eligibility information, couldn’t submit claims for processing, and couldn’t obtain prior authorizations for patient treatments. A surgery center in Indiana, for example, had to defer non-emergency procedures because it couldn’t verify insurance coverage or get authorization from insurers. Patients faced delays obtaining critical medications, and some couldn’t fill prescriptions for diabetes or heart medications. The comparison is stark: UnitedHealth paid a $22 million ransom to the attackers hoping to recover data and prevent its public release, yet the data was leaked anyway—a cautionary tale about the ineffectiveness of paying extortion demands. The financial burden ultimately passed through to healthcare providers, insurance companies, and patients in the form of higher premiums and deferred care.
Key Litigation Details and Legal Claims
The Nebraska lawsuit filed by Attorney General Mike Petersen names Change Healthcare, UnitedHealth Group, and Optum as defendants and makes several core allegations: that these companies failed to implement reasonable security safeguards required by HIPAA; that they failed to quickly detect the breach and respond appropriately; that they delayed notifying affected individuals; and that they misrepresented the scope of the breach by initially understating how many people were affected. Judge Susan Strong allowed the case to survive the defendants’ motion to dismiss, effectively ruling that Nebraska had presented sufficient evidence of wrongdoing to proceed to the next phase. Parallel to Nebraska’s action, Indiana University Health filed its own lawsuit on February 19, 2026, in Minnesota U.S. District Court, claiming $66 million in damages for the costs it incurred during the outage.
Federal judges ordered settlement discussions to begin on April 30, 2025, with U.S. Magistrate Judge Dulce J. Foster overseeing negotiations. The presence of settlement discussions doesn’t indicate wrongdoing—it’s a routine part of litigation—but it reflects that both sides see potential resolution rather than clear victory at trial. A limitation of the current litigation timeline is that it may take years to resolve, while affected individuals remain exposed to identity theft and fraud risks in the interim.

Settlement Discussions and Ongoing Legal Actions
Settlement negotiations between the defendants and plaintiffs began in April 2025 under the supervision of U.S. Magistrate Judge Dulce J. Foster. These discussions typically involve both sides estimating potential damages, assessing litigation risks, and negotiating a compensation structure. In healthcare breach cases, settlements often include a combination of direct compensation to affected individuals, funding for credit monitoring and identity theft protection services, and organizational reforms requiring the defendant to implement stronger security controls.
The amount ultimately offered will depend on factors including the number of verified claimants, the types of harm documented (identity theft, fraud, emotional distress), and the defendants’ assessment of their litigation exposure. Other healthcare organizations have joined the litigation or are considering separate suits. The involvement of multiple healthcare providers—from large systems like Indiana University Health to smaller clinics affected by the operational outage—creates a complex multi-party litigation environment. Each organization can pursue damages for its specific losses, but consolidated settlement discussions may be more efficient. An important consideration for individuals seeking compensation is that class action settlements typically require affected parties to file claims proving their membership in the affected class; not filing a claim means forgoing compensation, even if the case settles.
What This Means for Healthcare Cybersecurity Going Forward
The Change Healthcare breach has already shifted how regulators and healthcare organizations approach cybersecurity compliance. The Department of Health and Human Services Office for Civil Rights (OCR) increased scrutiny of healthcare entities’ security practices, and other healthcare companies have accelerated investments in multifactor authentication, network segmentation, and backup isolation—controls that Change Healthcare should have implemented years ago. The litigation signals that security negligence carries consequences: significant financial liability, reputational damage, and years of legal entanglement. This creates incentives for the industry to stop treating HIPAA compliance as a checkbox exercise and to invest in genuine security resilience.
The broader lesson is that healthcare’s growing dependence on centralized technology platforms like Change Healthcare creates systemic risk. When one company’s security failure cascades across thousands of healthcare providers and affects 192.7 million individuals, the breach becomes a public health issue, not just a private corporate incident. Future litigation and regulatory action may focus on whether large healthcare technology intermediaries should be required to maintain higher security standards, submit to third-party security audits, and carry insurance adequate to compensate for breaches. The fact that Change Healthcare’s two-month outage prevented patients from accessing critical healthcare services underscores why cybersecurity isn’t just a data protection issue—it’s a patient safety issue.
Conclusion
The Change Healthcare data breach litigation represents one of the most significant healthcare cybersecurity failures in U.S. history, with 192.7 million individuals affected and ongoing lawsuits against UnitedHealth Group, Optum, and Change Healthcare. The case reveals a preventable disaster: outdated IT systems, absent multifactor authentication, poorly segmented networks, and backup systems connected to primary systems—all failures that could have been remedied for a fraction of the $3.09 billion cost UnitedHealth ultimately absorbed. The litigation process, overseen by federal judges and involving settlement negotiations, will likely result in compensation for affected individuals and mandatory security improvements, though final resolution may take years.
If you believe you were affected by the Change Healthcare breach, monitor your credit reports and medical billing statements for suspicious activity, and watch for official announcements about settlement processes. Many affected individuals are entitled to free credit monitoring and identity theft protection services. The litigation may eventually provide direct monetary compensation, but prevention through personal vigilance is essential in the interim. For healthcare providers and policymakers, the case serves as a stark reminder that cybersecurity investments aren’t optional expenses—they’re fundamental to patient safety and organizational responsibility.
You Might Also Like
- Capital Health Data Breach Settlement Resolves Claims Over Hospital Cyberattack
- Lakeview Loan Servicing Data Breach Settlement Covers Borrowers Affected by Cyber Incident
- Krispy Kreme Data Breach Settlement Claims Consumer Information Was Compromised
Open Settlements You Can Claim Now
Browse current class action settlements accepting claims — several require no proof of purchase:
