Change Healthcare
bd_36e4f538febdd83a · schema v1 · pii pii-v1
Bioventus (reporting entity) disclosed in its 10-K Item 1C that Change Healthcare (victim/third-party vendor) experienced a cybersecurity incident where a threat actor gained access to its IT systems. Bioventus states the incident has not materially affected its financial condition, though patient billing and claims processing were disrupted. Bioventus identified an alternative intermediary and resumed some submissions. UnitedHealth Group (Change Healthcare's parent) was investigating as of March 7, 2024.
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Mar 12, 2024
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.