What Happened in the Change Healthcare Data Breach?
In August 2026, a federal magistrate judge in Minnesota approved a strict new set of rules for handling the data stolen in the Change Healthcare cyberattack. Magistrate Judge Dulce J. Foster signed off on the plan on August 7, 2026. This development matters because it shows the massive litigation over this breach is still very much active, more than two years after the original attack.
The order applies to the combined lawsuit against UnitedHealth Group and several related companies. It sets out precise procedures for how attorneys, experts, and other parties can access, review, and store the stolen records during discovery. Because the stolen files include some of the most sensitive medical and financial data imaginable, the court wanted firm safeguards in place before anyone outside the original case could touch them.
The underlying breach itself dates back to February 2024, when attackers first gained unauthorized access to Change Healthcare’s network. The company, a major processor of medical claims and payments across the US healthcare system, later confirmed that a ransomware group stole a massive volume of data before the intrusion was stopped. Investigators and forensic teams have spent years since then trying to determine the full scope of what was taken.
This new court-ordered handling protocol reflects just how sensitive and voluminous the stolen dataset really is. As the litigation moves forward, courts are having to create entirely new frameworks for safely managing stolen personal data as legal evidence. That alone signals how unprecedented this breach has been for the healthcare industry.
Who was affected?
The Change Healthcare breach is widely considered one of the largest healthcare data breaches in US history. It affected patients, health plan members, and healthcare providers whose information passed through Change Healthcare’s claims processing systems. Because the company sits at the center of so much of the American healthcare billing infrastructure, the reach of this incident extends far beyond any single hospital or insurer.
Change Healthcare has previously disclosed that the breach affected a huge portion of the US population, though this specific court order does not provide an updated victim count. As a result, the precise number tied to this latest development hasn’t been publicly disclosed. However, prior estimates have placed the affected population in the hundreds of millions, making this breach relevant to a large share of American healthcare consumers.
Because the exposed data flowed through so many different providers and insurers, both adults and children could be affected. Patients across nearly every state may have had information compromised, since Change Healthcare’s systems touch claims from a wide range of healthcare organizations nationwide.
What Information Was Potentially Exposed?
The stolen data at the center of this litigation reportedly includes some of the most sensitive categories of personal information that exist. Because Change Healthcare processes medical claims, the exposed data goes well beyond basic contact details.
- Full names and dates of birth
- Social Security numbers
- Health insurance information
- Medical diagnosis and treatment records
- Prescription information
- Billing and claims data
- Financial account information
This combination of data creates serious risk for identity theft. When Social Security numbers are paired with medical and financial records, criminals can open new credit accounts, file fraudulent tax returns, or apply for loans in a victim’s name. This type of exposure is especially dangerous because the data doesn’t expire the way a credit card number can be canceled.
In addition, medical identity theft is a distinct and growing concern. Someone could use stolen health insurance details to receive medical care under another person’s identity. This can lead to incorrect information appearing in a victim’s medical records, which can affect future treatment decisions and insurance coverage.
What is the company doing?
Since the breach was first discovered, Change Healthcare and its parent company UnitedHealth Group have taken numerous steps to respond. The companies worked with forensic investigators to determine what data was accessed and have cooperated with the ongoing multidistrict litigation in Minnesota federal court. UnitedHealth Group has also offered credit monitoring and identity protection services to affected individuals in the past.
Now, as the litigation continues, the companies are complying with the court’s newly approved data-handling protocol. This means implementing specific security measures for how the stolen data can be stored, reviewed, and shared among attorneys and experts working on the case. Because the stolen dataset is so large and sensitive, this protocol is meant to prevent any further exposure while the lawsuit proceeds.
The case remains ongoing, and further updates are likely as discovery continues. Affected individuals should watch for updates from the litigation, since new information about the scope of the breach could still emerge.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Anyone who may have used a healthcare provider connected to Change Healthcare should check their credit reports regularly. You can request free reports from each of the three major credit bureaus through AnnualCreditReport.com.
Look closely for unfamiliar accounts, credit inquiries you don’t recognize, or sudden changes to your credit score. Because stolen Social Security numbers can be used months or even years after a breach, ongoing vigilance matters more than a one-time check.
Consider a Credit Freeze or Fraud Alert
Given that Social Security numbers were reportedly exposed, placing a credit freeze with each bureau is one of the strongest protective steps available. A freeze blocks lenders from accessing your credit file, which makes it much harder for identity thieves to open new accounts in your name.
Alternatively, a fraud alert requires creditors to take extra verification steps before approving new credit. This is a lighter-touch option, but it still adds a meaningful layer of protection. Either way, acting sooner rather than later reduces your window of vulnerability.
Protect Against Medical Identity Theft
Because medical and insurance information was involved, it’s important to review any Explanation of Benefits statements from your health insurer. Look for treatments, prescriptions, or provider visits you don’t recognize.
If you spot anything suspicious, contact your insurer immediately to dispute the charges. In addition, request a copy of your medical records periodically to confirm nothing has been altered or added without your knowledge.
Stay Alert for Phishing Attempts
Scammers often use breach news to craft convincing phishing emails or phone calls. As a result, be cautious of any message claiming to be from Change Healthcare, UnitedHealth Group, or your health insurer that asks for personal information.
Never click links or provide sensitive details in response to unsolicited messages. Instead, contact the organization directly using a verified phone number or website to confirm whether the communication is legitimate.
Consult a Data Breach Attorney
Given the scale and ongoing litigation surrounding this breach, affected individuals may want to speak with an attorney who focuses on data breach cases. A free case evaluation can help you understand whether you qualify to join existing litigation or file a separate claim.
Because this case remains active in federal court, deadlines and options may change as the litigation develops. Getting informed legal guidance now can help protect your rights going forward.
More Information
Official data breach notification from Iowa Attorney General
Official data breach notification from Delaware Attorney General
Official data breach notification from Oregon Department of Justice
Official data breach notification from Vermont Attorney General
