CHANGE HEALTHCARE INC.
ent_019dd1709e698f953c836e5999851afb
Disclosures
22
State AG · HHS OCR · SEC 8-K · 16 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
192,700,000
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CHANGE HEALTHCARE INC.
- Normalized
- change healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300GS1BPJEDOZHM07
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- changehealthcare.com
Disclosure history (22)newest first
- Texas State AGas victim2025-10-14
Change Healthcare Inc. based in Eden Prairie, Minnesota, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2024-03-13 and reported on 2025-10-14. 11,331,028 Texas residents were affected. 192,700,000 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via Posted at company website or special website;U.S. Mail.
- Delaware State AGas victim2025-07-31
Change Healthcare reported a data breach to the Delaware Attorney General. Notice was filed on 2025-07-31. 534,372 Delaware residents were affected. 192,700,000 individuals affected in total.
- New Hampshire State AGas victim2025-07-31
Change Healthcare, a healthcare clearinghouse and subsidiary of UnitedHealth Group, disclosed a supplemental breach notification to the New Hampshire Attorney General on July 31, 2025. The incident involved unauthorized access to computer systems between February 17-20, 2024, detected on February 21, 2024. Approximately 192.7 million individuals were potentially impacted nationwide, including 655,282 New Hampshire residents. Data accessed included PII, PHI, and financial information. Change Healthcare engaged law enforcement, isolated systems, and provided credit monitoring services.
- Rhode Island State AGas victim2025-04-22
Change Healthcare Inc. submitted a supplemental breach notification to the Rhode Island Attorney General on April 18, 2025, updating the count of mailed notices to RI residents to 264,407 as of April 8, 2025. The incident involves the compromise of Change Healthcare, a healthcare services provider, impacting patient PII and PHI. The filing notes the analysis is ongoing and the count is an interim estimate subject to change.
- Delaware State AGas victim2025-04-18
Change Healthcare reported a data breach to the Delaware Attorney General. Notice was filed on 2025-04-18. 539,916 Delaware residents were affected.
- Illinois State AGas victim2024-11-01
CHANGE HEALTHCARE, INC. filed a data-breach notice with the Illinois Attorney General in November 2024 (case 24-11-045). The register records the breach as discovered on February 17, 2024. Additional entities named: UNITED HEALTH GROUP, INC.. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Oregon State AGas victim2024-09-16
Change Healthcare reported a data breach to the Oregon Attorney General. The breach was reported on 2024-09-16. The breach occurred during 2/17/2024 - 2/20/2024. The breach was discovered on 2/21/2024. Notice was sent on 9/16/2024.
- South Carolina State AGas victim2024-08-05
Change Healthcare, Inc. disclosed a cybersecurity incident where a cybercriminal accessed its computer system between Feb 17-20, 2024. The breach exposed PHI, PII (SSN, DL), and financial data. CHC turned off systems, engaged law enforcement, and offered 2 years of credit monitoring. Notification to affected individuals began June 20, 2024.
- California State AGas victim2024-08-03
Change Healthcare Inc. disclosed a data breach where a cybercriminal accessed its computer system without permission between February 17 and February 20, 2024. The unauthorized access was detected on February 21, 2024. The incident involved the exfiltration of protected health information (PHI), including medical records, diagnoses, and treatments, as well as personally identifiable information (PII) such as names, addresses, Social Security numbers, and financial data including payment cards and bank account numbers. Change Healthcare contained the incident by shutting down systems, engaged law enforcement and forensic investigators, and is offering two years of credit monitoring and identity theft protection to affected individuals.
- Oregon State AGas victim2024-08-03
Change Healthcare Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-08-03. The breach occurred during 2/12/2024 - 2/22/2024. The breach was discovered on 3/13/2024. 250 individuals were affected. Notice was sent on 7/29/2024.
- Massachusetts State AGas victim2024-08-03
Change Healthcare Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-08-03. 2,203,808 Massachusetts residents were affected.
- Washington State AGas victim2024-08-03
Change Healthcare Inc. reports a ransomware attack occurring Feb 17-20, 2024, discovered Feb 21, 2024. Incident impacted approx. 192.7M individuals nationwide, including 3.1M in Washington. Data exposed included PHI, SSNs, DOBs, and financial data. Notices mailed starting June 20, 2024. This filing is a supplemental update dated July 31, 2025.
- Montana State AGas victim2024-08-02
Change Healthcare Inc. disclosed a cyber incident in Montana where unauthorized access occurred between Feb 17-20, 2024. The breach exposed PHI, financial data, and PII (SSN, DLs). CHC contained the incident, engaged law enforcement, and offered 2 years of credit monitoring. Notification began June 20, 2024.
- New Hampshire State AGas victim2024-08-02
Change Healthcare Inc. (CHC), a healthcare technology business associate, disclosed a ransomware incident. On Feb 12, 2024, attackers used compromised credentials to access a Citrix portal. Ransomware was deployed on Feb 21, 2024. Data exfiltration occurred Feb 17-20. CHC notified the NH AG on Aug 2, 2024. Impacted data includes PHI and PII. CHC provided credit monitoring and engaged forensic experts.
- Illinois State AGas victim2024-08-01
CHANGE HEALTHCARE, INC. filed a data-breach notice with the Illinois Attorney General in August 2024 (case 24-08-004). The register records the breach as discovered on February 17, 2024. Personal information types reported: drivers license. Additional entities named: UNITED HEALTH GROUP, INC.. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Vermont State AGas victim2024-07-29
Change Healthcare disclosed a data breach where a cybercriminal accessed its computer system between Feb 17-20, 2024. The incident involved unauthorized access and exfiltration of data including contact info, health insurance data, health data, billing/payment data, and government IDs. CHC notified law enforcement, engaged a special team, and offered 2 years of free credit monitoring.
- MINNESOTAHHS OCRas victim2024-07-19
Change Healthcare, Inc. reported to HHS on 2024-07-19 a Hacking/IT Incident affecting 192,700,000 individuals. Breached information located on Network Server. Business Associate present.
- Wisconsin State AGas victim2024-06-20
Change Healthcare (CHC) a unit of UnitedHealthcare Group (UHG) reported a data breach to the Wisconsin DATCP. The public was notified on 2024-06-20. The incident occurred on February 17-20, 2024. Data accessed: May have included contact information (such as first and last name, address, date of birth, phone number, and email) and one or more of the following:.
- FEDERALSEC 8-Kas victim2024-04-24
UnitedHealth Group filed 8-K/A Amendment No. 2 updating prior disclosures about the Change Healthcare cyberattack. The amendment incorporates an April 22, 2024 press release describing ongoing data assessment, support for impacted individuals, provider/customer notifications, and Change Healthcare service restoration progress. The underlying incident is the previously disclosed cyberattack on UnitedHealth Group subsidiary Change Healthcare.
- FEDERALSEC 8-Kas victim2024-03-08
UnitedHealth Group filed an Amendment No. 1 to its February 22, 2024 Form 8-K disclosing that cybercrime threat actors had gained access to certain Change Healthcare IT systems. The Company isolated the impacted systems, notified customers, law enforcement and government agencies, and is investigating the extent of impacted data. The Company believes the issue is specific to Change Healthcare; all other systems remain operational. As of the amendment date, no material impact on financial condition or results of operations had been determined.
- FEDERALSEC 8-Kas victim2024-02-22
On February 21, 2024, UnitedHealth Group identified a suspected nation-state cyber threat actor that had gained access to certain Change Healthcare IT systems. The Company isolated the impacted systems, retained security experts, engaged law enforcement, and notified customers and government agencies. As of the filing, UnitedHealth had not determined the incident reasonably likely to materially impact financial condition or results of operations.
- GEORGIAHHS OCRas victim2022-07-07
Change Healthcare reported to HHS on 2022-07-07 a Unauthorized Access/Disclosure affecting 1262 individuals. Breached information located on Paper/Films. The business associate, Change Healthcare Technologies, experienced a software issue that caused PHI (names, claims, financial, and treatment info) to be sent to wrong recipients. HHS and individuals were notified; additional technical safeguards were implemented.