Change Healthcare and the $2.87 Billion Question
In February 2024, a ransomware attack took down Change Healthcare, the company that processes about one third of all U.S. healthcare claims. The attackers got in through a server that lacked multi factor authentication.
The estimated cost so far: $2.87 billion. And that doesn’t include the expected HIPAA settlement or the class action lawsuits still working through the system.
This wasn’t an isolated incident. HHS closed 22 HIPAA enforcement actions in 2024, the most in years. The Office for Civil Rights has launched a new initiative specifically targeting risk analysis failures, the most common Security Rule violation.
Recent settlements tell the story. Solara Medical Supplies paid $3 million after a phishing attack. Warby Parker faced a $1.5 million civil penalty over a hacking investigation. Multiple ransomware settlements landed in the $250,000–$950,000 range.
The pattern is consistent. Most breaches trace back to basic security gaps, missing MFA, inadequate risk assessments, delayed detection. The Change Healthcare attack wasn’t discovered until weeks after the initial compromise.
What the data shows
Healthcare remains the costliest industry for data breaches, averaging $7.42 million per incident, according to IBM’s most recent analysis. That’s about 40% higher than the global average across industries.
Average time to identify and contain a healthcare breach: 279 days. That’s the longest of any sector.
The compliance piece matters, but it’s not everything.
Class action plaintiffs can sue you. But the operational disruption may be worse than either. When Change Healthcare went down, physician practices across the country couldn’t process claims for weeks. Smaller practices took the biggest hit.
The organizations that weather these incidents aren’t necessarily the ones with the biggest IT budgets. They’re the ones that actually completed their risk assessments, tested their incident response plans, and didn’t assume their vendors had it covered.