MalwareRansomwareStolen CredentialsCapture Stored DataData ExfiltratedData EncryptedRansom DemandedMulti-Stage ChainCustomer Data InvolvedBusiness Associate (HIPAA)Downstream VictimsPHIPIIIDENTITY_BASICLowContained
CHANGE HEALTHCARE INC.
bd_546b3d03391ed182 · schema v1 · pii pii-v1
Full breach record for CHANGE HEALTHCARE INC. →Change Healthcare Inc. (CHC), a healthcare technology business associate, disclosed a ransomware incident. On Feb 12, 2024, attackers used compromised credentials to access a Citrix portal. Ransomware was deployed on Feb 21, 2024. Data exfiltration occurred Feb 17-20. CHC notified the NH AG on Aug 2, 2024. Impacted data includes PHI and PII. CHC provided credit monitoring and engaged forensic experts.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_20fef244fbf67f71Montana State AGfiled 2024-08-02Verified
- bd_6999730badb3aebbCalifornia State AGfiled 2024-08-03(1d gap)Verified
- bd_788f5843714453cbOregon State AGfiled 2024-08-03(1d gap)Verified
- bd_dc48a09555e80a91Washington State AGfiled 2024-08-03(1d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 45d gap
- bd_1467986906075ca0Vermont State AGfiled 2024-07-29(4d gap)Verified
- bd_7573d03228639e7bHHS OCRfiled 2024-07-19(14d gap)Verified
- bd_1091c4bb67ec440aOregon State AGfiled 2024-09-16(45d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/change-healthcare-20240802.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 2, 2024
- Raw hash
- a80fa0b5e8eac1fe850ec51eec342a84fa73ccb5bb0080cc021895afbcd5a124
Reporting entity
- Name
- CHANGE HEALTHCARE INC.norm: change healthcare
- Domain
- changehealthcare.com
Victim entity
- Name
- CHANGE HEALTHCARE INC.norm: change healthcare
- Domain
- changehealthcare.com
Incident
- Discovered
- Feb 21, 2024
- Materiality determined
- Apr 22, 2024
- Notification sent
- Jul 29, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIPIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 ChannelT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 23 weeks(163 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.