CHANGE HEALTHCARE INC.
bd_6999730badb3aebb · schema v1 · pii pii-v1
Full breach record for CHANGE HEALTHCARE INC. →Change Healthcare Inc. disclosed a data breach where a cybercriminal accessed its computer system without permission between February 17 and February 20, 2024. The unauthorized access was detected on February 21, 2024. The incident involved the exfiltration of protected health information (PHI), including medical records, diagnoses, and treatments, as well as personally identifiable information (PII) such as names, addresses, Social Security numbers, and financial data including payment cards and bank account numbers. Change Healthcare contained the incident by shutting down systems, engaged law enforcement and forensic investigators, and is offering two years of credit monitoring and identity theft protection to affected individuals.
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_788f5843714453cbOregon State AGfiled 2024-08-03Verified
- bd_dc48a09555e80a91Washington State AGfiled 2024-08-03Verified
- bd_20fef244fbf67f71Montana State AGfiled 2024-08-02(1d gap)Verified
- bd_546b3d03391ed182New Hampshire State AGfiled 2024-08-02(1d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 44d gap
- bd_1467986906075ca0Vermont State AGfiled 2024-07-29(5d gap)Verified
- bd_7573d03228639e7bHHS OCRfiled 2024-07-19(15d gap)Verified
- bd_1091c4bb67ec440aOregon State AGfiled 2024-09-16(44d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-589771
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 3, 2024
- Raw hash
- 9166fe07090a5569a4a245915709fabfcd6d1733684786019634f5535dc18602
Reporting entity
- Name
- CHANGE HEALTHCARE INC.norm: change healthcare
- Domain
- changehealthcare.com
Victim entity
- Name
- CHANGE HEALTHCARE INC.norm: change healthcare
- Domain
- changehealthcare.com
Incident
- Discovered
- Feb 21, 2024
- Materiality determined
- —
- Notification sent
- Jul 29, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 23 weeks(164 days from discovery to filing)
- Compliance flags
- CA 60-day late · 159d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 21, 2024→ Notified: Jul 29, 2024159d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.