Eleven months after the ransomware attack on Change Healthcare, the number keeps growing. On January 24, 2025, UnitedHealth Group updated its estimate: about 190 million people had their data exposed in the February 21, 2024 attack. That is up from the 100 million reported to regulators in October 2024 and makes it, by a wide margin, the largest health data breach ever reported in the United States. The company says its review of the compromised data is substantially complete and that it will file a final number with the HHS Office for Civil Rights later.

The exposed data, according to the substitute notice, can include contact information, health insurance details, health information, and billing and claims data. UnitedHealth says it is not aware of misuse and has not seen full electronic medical record databases in the stolen data. Most affected people have already been notified by letter or through the substitute notice on the company's website.

For a practice, the news is not really about the number. It is about four things you are responsible for: your own notification obligations, your list of vendors who hold your patients' data, the claims from the spring of 2024 that may never have been submitted, and what you would do if the clearinghouse went dark again.

Key takeaways

  • Change Healthcare is a business associate of nearly every practice. The practice, not the vendor, holds the legal duty to notify patients unless that duty was delegated and the delegation is documented.
  • Build a written list of every vendor that touches patient data, with a signed business associate agreement and a security statement for each. The proposed HIPAA Security Rule published this month would require exactly that.
  • Medicare's twelve-month filing limit means dates of service from late February and March 2024 close over the next several weeks. Reconcile arrived appointments against accepted claims for that window now.
  • Write down a second path for claims, eligibility and remittances, and test it once a year.

What UnitedHealth has said, and when

DateWhat happened
February 21, 2024Change Healthcare takes its systems offline after a ransomware attack. Claims, eligibility, remittances and pharmacy transactions stop for a large share of the U.S. health system.
March to April 2024Services restored in stages. CMS announces accelerated payments for Part A and advance payments for Part B providers. UnitedHealth offers temporary funding advances to providers.
June 2024Change Healthcare begins substitute notice and starts mailing individual letters through the summer and autumn.
October 2024UnitedHealth reports about 100 million affected individuals to the HHS Office for Civil Rights.
January 24, 2025UnitedHealth revises the estimate to about 190 million people and says the data review is substantially complete.

If your practice took a temporary funding advance from UnitedHealth or an accelerated payment from Medicare in 2024, pull the agreement and confirm the repayment terms and the balance. Medicare recouped its advances automatically from later remittances; the UnitedHealth advances are interest-free but must be repaid, and the terms are in the agreement your practice signed, not in the news.

Your notification obligations

Change Healthcare is a business associate of nearly every practice that submitted a claim through it, directly or through a billing company or EHR vendor. When a business associate has a breach, the covered entity (the practice) is the one with the legal duty to notify patients and HHS, unless it delegates that duty. OCR published guidance in 2024 allowing affected covered entities to delegate notification to Change Healthcare, and UnitedHealth Group said it would handle notifications on behalf of customers that wanted it to.

The gap we still see: practices that assumed delegation happened but never confirmed it. If you have not, do two things. Confirm in writing, through your clearinghouse or billing vendor, that Change Healthcare is issuing notifications for your patients. Then keep that confirmation in your breach log with the date. If you cannot confirm it, talk to counsel about whether your own notification is required. This is a legal question, and the answer depends on your contracts and your state. State breach laws have their own deadlines and thresholds, and several states require notice to the attorney general above a certain count.

Your business associate list

Most practices could not name every vendor that touches their patient data. The Change Healthcare attack showed why that matters: many practices did not know Change was in their claims path, because their EHR or billing company routed claims through it without saying so. Build the list now, and for each vendor record what data it holds, whether a signed business associate agreement is on file, and whether the vendor has given you any written statement about its security. The proposed HIPAA Security Rule published January 6, 2025 would require exactly this inventory and an annual written verification from each business associate, and OCR already asks for it after any incident.

Vendor typeData it usually holdsWhat to have on file
ClearinghouseClaims, eligibility, remittancesBAA, payer ID list, backup submission path
EHR / practice managementFull chart and billing recordBAA, encryption statement, export procedure
Billing companyClaims, remittances, statementsBAA, user access list, offboarding procedure
Patient statement or payment vendorBalances, card dataBAA, PCI attestation
Transcription, telehealth, fax, emailClinical notes, PHI in transitBAA, encryption in transit
IT managed servicesAccess to everything aboveBAA, named technicians, MFA on remote tools

Ask your EHR and billing vendors one specific question: which clearinghouses and sub-vendors do our transactions pass through? The answer belongs on the list too, because a subcontractor breach reaches your patients the same way a direct vendor's does.

The 2024 backlog, with the timely filing math

Honestly, most practices skipped this in 2024 and are still finding claims from March that never went out. During the outage, many offices kept seeing patients and stored the encounters to submit "when it comes back". When it came back, the queue was worked from the newest date forward, and the oldest encounters were left behind. Now the clock matters. Medicare allows twelve months from the date of service, so a March 5, 2024 visit must be received by March 5, 2025. Most commercial payers allow 90 to 180 days, so most of that window is already closed, though a few payers granted extensions for the outage period and some contracts run to a year.

The reconciliation is mechanical. Pull the schedule of arrived appointments for February 21 through May 31, 2024. Pull the claims with an accepted 277 acknowledgement for the same dates of service. Match by patient and date. Every arrived appointment without an accepted claim is either a non-billable visit, a claim that was rejected and never fixed, or a claim that was never sent. A practice seeing 60 patients a day that lost even two percent of six weeks of encounters has roughly 70 visits, and at an average of $120 that is about $8,400 still recoverable from Medicare and any payer with a long limit. For the ones outside the limit, write them off with a reason code that names the outage, so the loss is visible in your reporting instead of quietly aging in accounts receivable.

The contingency plan you should already have

In March and April 2024 many practices could not submit claims, check eligibility or receive remittances for weeks. Cash stopped. The practices that came through best had one thing in common: a second path. Here is what we recommend every practice have written down, tested once, and reviewed each year.

  1. A second clearinghouse connection, or at least confirmation from your EHR vendor of how quickly one can be enabled. Know which payers you can reach through a payer portal directly if both fail.
  2. Electronic funds transfer and ERA enrollment with your top payers held in your own name, not only through the clearinghouse, so payments can continue even if the remittance feed stops.
  3. A manual eligibility procedure: the payer portal logins and phone numbers for your top ten payers, kept current, with MFA on every portal.
  4. A cash plan: how many weeks of operating expenses you hold, and a line of credit arranged before you need it.
  5. A claims backlog procedure: how you will track dates of service that were not submitted so nothing passes timely filing when the connection returns. A simple log of date of service, patient and payer, kept from day one of an outage, would have saved most of the losses described above.

What changes in the workflow

Very little day to day, which is the point. The changes are in the file cabinet: a vendor list, a BAA for each vendor, a written second path for claims and eligibility, a breach log with the delegation confirmation, and a finished reconciliation for the spring of 2024. Assign the list to one person, usually the practice manager, and review it at the same time you do your annual risk analysis. When a vendor is added, it goes on the list the same week, not at the next annual review.

Questions we hear

Our patients are asking whether they were affected. What do we tell them?

Tell them the truth: the breach happened at a company that processes claims for most of the U.S. health system, notifications are being sent by that company, and they can request credit monitoring through the number in the notice. Do not speculate about whether a specific patient's data was included, and do not promise that the practice's own systems were untouched unless your IT vendor has confirmed it in writing.

Should we move away from Change Healthcare?

That depends on your EHR, your payers and your contracts. In our experience the better question is whether you have a second path, whichever clearinghouse is primary. Single points of failure are the problem, not one vendor, and a practice that switches to a different single vendor has not solved anything.

Can a billing company help with the 2024 backlog?

Yes. The reconciliation is the same one we run in every RCM audit: arrived appointments against accepted claims for a fixed window. If the window is the spring of 2024, the list will be short but the dollars are real, and the Medicare deadline for the earliest dates is weeks away. Our billing team can run it as a one-off project.

What to do this month

  1. Confirm in writing that Change Healthcare is handling patient notification for your practice, and file the confirmation in the breach log with the date.
  2. Run the arrived-appointments-to-accepted-claims reconciliation for February 21 through May 31, 2024, and submit every Medicare claim still inside the twelve-month window first.
  3. Write the vendor list with data held, BAA date and security statement for each, and ask the EHR and billing vendors which sub-vendors your transactions pass through.
  4. Confirm EFT and ERA enrollment with your top five payers is in the practice's own name.
  5. Write the one-page contingency plan and put a test date on the calendar.
  6. Pull any 2024 advance or accelerated payment agreement and confirm the balance and repayment terms.