unitedhealth confirms data breach affected 190 million americans

Health Data Breach: What Happened and What to Do (2026 Update)

Table of Contents

Add a header to begin generating the table of contents
UnitedHealth confirms data breach affected 190 million Americans, a number that has since been revised upward, and that headline figure is only part of a bigger story most coverage still hasn’t connected. What started as a single ransomware attack on a UnitedHealth subsidiary in 2024 turned out to be the first of two major incidents within the same corporate family, together touching nearly 200 million people. This guide walks through both breaches, explains how they’re connected, and covers exactly what you should do if your information was involved. We’ll also answer the practical questions people are actually searching for, like whether a breach notification letter is legitimate or a scam. By the end, you’ll have the complete, current picture, not just the version that was accurate in early 2025.

The Short Version

In February 2024, ransomware attackers breached Change Healthcare, a UnitedHealth Group subsidiary that processes roughly 15 billion healthcare transactions a year. The attack exposed data belonging to 192.7 million people, making it the largest healthcare data breach ever reported to U.S. regulators. Less than a year later, in February 2025, a second UnitedHealth Group subsidiary called Episource suffered its own ransomware attack, exposing data for another 5.4 million people. Combined, the two incidents affected close to 200 million Americans.

Understanding UnitedHealth Group’s Structure

To understand this data breach, it helps to know how UnitedHealth Group is organized. UnitedHealth Group (UHG) is the parent company, and it operates through two main divisions. UnitedHealthcare is the health insurance business most people recognize. Optum is the healthcare services and technology division, and it’s the one that owns both Change Healthcare and Episource.
Neither Change Healthcare nor Episource is the insurance company itself. They’re technology and data-processing subsidiaries that sit behind the scenes, handling claims, billing codes, and insurance verification for providers and insurers across the country. That’s exactly why the breaches were so damaging: because these companies process data quietly in the background, most patients had never heard of either one before their information was exposed.

Breach One: Change Healthcare (February 2024)

How It Happened

Attackers linked to the ALPHV/BlackCat ransomware group gained access to Change Healthcare’s network on February 12, 2024, through a Citrix remote access portal that didn’t have multi-factor authentication enabled. They spent roughly nine days moving through internal systems undetected before deploying ransomware on February 21, 2024, the day the attack was publicly discovered and Change Healthcare began shutting down its systems.
UnitedHealth Group’s CEO later confirmed to Congress that the compromised entry point lacked multi-factor authentication, and that Change Healthcare hadn’t updated its internal security procedures following UHG’s acquisition of the company in October 2022. Senator Ron Wyden put it bluntly: the hack could have been stopped with basic cybersecurity practices.

The Ransom Payment and What Went Wrong Next

UnitedHealth paid a $22 million ransom in Bitcoin on March 1, 2024, in exchange for a promise that the stolen data would be destroyed. That promise didn’t hold. The ransomware group’s leadership took the payment and shut down operations without paying the affiliate hacker who had actually carried out the attack. That affiliate kept a copy of the stolen data and partnered with a second group, RansomHub, to launch a separate extortion attempt in April 2024. Patient data began showing up on dark web leak sites regardless of the ransom that had already been paid.

Who Was Affected

Change Healthcare’s final confirmed number is 192.7 million individuals, roughly 57% of the U.S. population at the time. Individual notification letters started going out in late July 2024 and continued through 2025. The exposed data varied by person but could include:

Category Data Involved
Health information Medical record numbers, providers, diagnoses, medications, test results, treatment details
Insurance information Health plan details, insurer names, member and group ID numbers, Medicare and Medicaid IDs
Billing and claims Claim numbers, account numbers, billing codes
Personal identifiers Names, addresses, dates of birth, phone numbers, email addresses, and in some cases Social Security numbers
Financial information Payment card and banking details in limited cases

For most people affected, Social Security numbers weren’t part of the exposure, but the combination of detailed medical history, insurance information, and personal identifiers still adds up to an unusually complete profile of someone’s health and financial life.

Breach Two: Episource (February 2025)

Less than a year after Change Healthcare, another Optum subsidiary was hit. Episource, a medical coding and risk adjustment company that Optum acquired in 2023, detected suspicious activity on its network on February 6, 2025. Investigators later determined attackers had been inside the system for about ten days before that, between January 27 and February 6.
Episource shut down affected systems immediately, brought in outside cybersecurity investigators, and notified law enforcement. Notification letters to affected individuals began going out on a rolling basis starting April 23, 2025, and the breach was formally reported to the California Attorney General in June 2025.
According to the HHS Office for Civil Rights breach portal, 5,418,866 individuals were affected. Exposed data could include names, addresses, phone numbers, dates of birth, Social Security numbers in some cases, health insurance details, Medicare and Medicaid identification numbers, and protected health information such as diagnoses and treatment records.

The Pattern Nobody’s Naming: Acquired Companies, Unaudited Security

Here’s the detail that connects both incidents and that most coverage of the UnitedHealth data breach doesn’t spell out directly: both Change Healthcare and Episource were companies UnitedHealth Group had acquired, not built in-house, and in both cases, serious security gaps existed at the time of the breach.
UnitedHealth’s own CEO admitted that Change Healthcare’s security procedures hadn’t been updated after the 2022 acquisition. When Episource was breached roughly two years after its own 2023 acquisition, two U.S. senators sent a letter to UHG’s CEO in August 2025 asking directly whether the company had strengthened its cybersecurity due diligence process for acquisitions since the Change Healthcare incident. The fact that lawmakers felt compelled to ask that question, after a second acquired subsidiary was breached, suggests the answer mattered enough to demand an official response.
This isn’t just a footnote. For a company the size of UnitedHealth Group, acquiring dozens of healthcare technology firms over the years, the pattern raises a real structural question: was security posture ever a meaningful part of the acquisition process, or did it come later, if at all? Regulators and legal experts have noted that if HHS investigators find evidence of inadequate risk analysis at either company, UHG could face significant HIPAA enforcement penalties layered on top of the civil litigation already underway.

Both Breaches at a Glance

Change Healthcare (2024) Episource (2025)
Parent company Optum (UnitedHealth Group) Optum (UnitedHealth Group)
Breach window Feb 12 to Feb 21, 2024 Jan 27 to Feb 6, 2025
People affected 192.7 million 5.4 million
Attack type Ransomware (ALPHV/BlackCat) Ransomware
Entry point Citrix portal without MFA Not publicly disclosed
Ransom paid $22 million (Bitcoin) Not publicly confirmed
Acquired by UHG October 2022 2023

 

Current Litigation and Settlement Status

Multiple class action lawsuits related to the Change Healthcare breach have been consolidated into a multidistrict litigation proceeding in the District of Minnesota. Settlement discussions have reportedly been underway, though no global resolution had been finalized as of this writing. Separately, state attorney general lawsuits, including one filed by Nebraska, have survived early motions to dismiss and continue moving forward.
The Episource breach has drawn a formal congressional inquiry rather than reaching the same litigation scale so far, though that could change as more details about the incident become public. If you were affected by either breach, keeping records of any real, documented harm, such as fraudulent charges, time spent on remediation, or fees paid to address identity theft, will matter if a settlement process eventually opens up and requires individuals to file claims.

What to Do If You Were Affected

Check whether you received a notification letter

Change Healthcare’s notification letters went out starting in late July 2024. Episource’s began going out from April 23, 2025. If you received a letter from either company, or from a healthcare provider whose billing runs through either system, your data was confirmed as part of the breach.

Note the credit monitoring deadlines

Change Healthcare offered two years of free credit monitoring and identity theft protection through IDX, with enrollment closing August 26, 2025. If you missed that window, independent credit monitoring is still worth setting up on your own. Episource is separately offering two years of free credit monitoring and identity protection to individuals it notified, with enrollment details included in its letters.

Freeze your credit at all three bureaus

If your Social Security number may have been exposed in either breach, placing a credit freeze with Equifax, Experian, and TransUnion is one of the most effective ways to stop new fraudulent accounts from being opened in your name. Freezes are free, reversible, and don’t affect your existing accounts.

Review your explanation of benefits statements

Because health information, including diagnoses and treatment details, was part of both breaches, medical identity theft is a real risk. Watch your explanation of benefits (EOB) statements from any insurer for services or claims you don’t recognize, since this can be a sign someone else is using your medical identity.

Watch for phishing attempts

Any major, widely reported breach attracts opportunistic scammers who send fake notification emails or texts designed to look official. Be cautious of unsolicited messages asking you to “verify” personal details, and don’t click links or call phone numbers included in messages you didn’t expect.

Is the UnitedHealth Data Breach Notification Real or a Scam?

This is one of the most common questions people have after receiving a letter, so it’s worth answering directly.
The UnitedHealth data breach itself is real, and it has been formally reported to the U.S. Department of Health and Human Services. However, because the breach affected so many people, it has also become a popular disguise for scammers sending fake notifications. If you’re unsure whether a letter or email you received is legitimate, don’t use the phone numbers or links included in the message itself. Instead, go directly to your insurer’s official website, or call the number printed on the back of your insurance card, to confirm whether your information was actually involved.
The same caution applies to unexpected phone calls. If someone contacts you out of the blue claiming to represent Change Healthcare or UnitedHealth and asks you to confirm your Social Security number or payment details, treat it as suspicious regardless of how official it sounds, hang up, and call back using a number you looked up yourself.

Frequently Asked Questions

How many people were affected by the UnitedHealth data breach?
Change Healthcare’s 2024 breach affected 192.7 million people, and the separate 2025 Episource breach affected 5.4 million more, bringing the combined total under the UnitedHealth Group umbrella to nearly 200 million individuals.
Was UnitedHealthcare itself hacked?
No. UnitedHealthcare, the insurance division, wasn’t directly breached in either incident. Both breaches occurred at Optum subsidiaries, Change Healthcare and Episource, though data belonging to UnitedHealthcare members was affected because it passed through those systems during normal claims processing.
What data was exposed in the UnitedHealth data breach?
Exposed data varied by individual but could include medical records, diagnoses, treatment history, insurance information, billing details, names, addresses, dates of birth, and in some cases Social Security numbers and financial information.
Is there a deadline to enroll in free credit monitoring?
Change Healthcare’s credit monitoring enrollment deadline was August 26, 2025. If you missed it, you can still set up independent credit monitoring on your own. Episource’s offer is ongoing for individuals it has notified, based on the enrollment details included in their letters.
Can I still join a lawsuit related to the breach?
Class action lawsuits tied to the Change Healthcare breach are consolidated in a federal court in Minnesota, and settlement discussions are ongoing. If a settlement is eventually reached, affected individuals will likely need to file a claim, so documenting any harm now is worthwhile.

Conclusion

The UnitedHealth data breach isn’t a single event that ended in 2024. It’s an ongoing story involving two separate ransomware attacks at two different UnitedHealth Group subsidiaries, both of which the company had acquired without apparently auditing their security practices closely enough. Nearly 200 million people have been affected between Change Healthcare and Episource combined, and the legal, regulatory, and financial fallout is still unfolding. If you have UnitedHealthcare insurance or have received medical care processed through either system, the safest move is to freeze your credit, monitor your insurance statements, and stay alert for phishing attempts built around the breach itself, while keeping an eye on where the ongoing litigation and any future settlement process lead.

Leave a Comment

Your email address will not be published. Required fields are marked *