Change Healthcare Data Breach: Is There a Settlement Yet?
Last updated: July 26, 2026
There is no Change Healthcare settlement yet, so there is nothing to claim and no deadline to miss. Change Healthcare, Inc., the UnitedHealth Group subsidiary that processes a large share of American medical claims and payments, was hit by a ransomware attack in February 2024 that exposed the personal and health information of approximately 190 million people — the largest healthcare data breach in United States history. The resulting lawsuits were consolidated into a federal multidistrict litigation in Minnesota, and as of July 2026 that case is still being litigated. No settlement has been announced or approved, which means no official claim form exists.
The attack was carried out by the ALPHV/BlackCat ransomware group, which used stolen credentials to enter a Citrix remote-access portal that was not protected by multi-factor authentication. Investigators determined the attackers had access from February 17 to February 20, 2024, and the intrusion was detected on February 21, 2024. About 6 terabytes of data were stolen and systems were encrypted, disrupting pharmacy and provider payments nationwide. UnitedHealth's chief executive, Andrew Witty, confirmed the company paid a $22 million bitcoin ransom. The exposed information included names, addresses, dates of birth, Social Security numbers, government identification numbers, health insurance details, medical records and billing data — though not every affected person had every category exposed.
The consolidated case is In re: Change Healthcare, Inc., Customer Data Security Breach Litigation, MDL No. 3108, No. 0:24-md-03108-DWF-DJF, before Judge Donovan W. Frank and Magistrate Judge Dulce J. Foster in the U.S. District Court for the District of Minnesota. It was centralized in June 2024 and runs on two tracks: one for patients whose data was exposed, and one for healthcare providers who lost revenue when the payment systems went down. The court has directed the parties toward settlement discussions and mediation, and set case-management deadlines including amended pleadings on April 1, 2026 and the close of fact discovery on November 2, 2026. No trial date has been set. If and when a settlement is reached, it must be preliminarily and then finally approved by Judge Frank before any claims process opens.
Key facts
- Settlement status
- None — no settlement approved as of July 2026
- Claim form
- Does not exist yet
- Deadline
- None — nothing to file
- People affected
- About 190 million (largest US healthcare breach)
- Attack detected
- February 21, 2024 (access February 17–20, 2024)
- Attacker
- ALPHV/BlackCat ransomware group
- How they got in
- Stolen credentials on a Citrix portal without multi-factor authentication
- Data stolen
- About 6 terabytes
- Ransom paid
- $22 million in bitcoin (confirmed by UnitedHealth's CEO)
- Notification letters
- Began late July 2024
- Litigation
- MDL No. 3108, 0:24-md-03108-DWF-DJF (D. Minn.)
- Judges
- Donovan W. Frank; Magistrate Judge Dulce J. Foster
- Free credit monitoring
- Two years via IDX — enrollment closed August 26, 2025
Official settlement administrator: U.S. District Court, District of Minnesota — MDL 3108 docket
Who qualifies
- Because there is no settlement, there is no class definition yet and nobody can be 'eligible' to file. Any eligibility test you see online today is speculation.
- You were likely affected if you have received medical care, filled a prescription, or been billed for healthcare in the United States in recent years — Change Healthcare handles claims and payment processing for a very large share of American providers and pharmacies, so most affected people were never Change Healthcare customers directly.
- Notification letters started going out in late July 2024, roughly five months after the attack. Many people received one addressed from Change Healthcare rather than from their own doctor or insurer, which is why the letters were widely mistaken for junk mail.
- Not everyone had the same data exposed. Depending on the record, the stolen information could include name, address, date of birth, Social Security number, government ID number, health insurance information, diagnoses, medications, test results, and billing or payment details.
- Healthcare providers and practices are covered by a separate track of the same litigation — theirs concerns lost and delayed reimbursements during the outage, not exposed personal data.
What to do while the litigation continues
- 1
Do not file anything — and be suspicious of sites that ask you to
No settlement has been approved, so there is no official claim form, no claim number and no deadline. Websites, ads, texts or calls offering to file your Change Healthcare claim, or promising a specific payout amount, are not connected to the court. A real settlement is announced by a court-appointed administrator and reported on the court's own docket first.
- 2
Ignore the payout figures circulating online
No per-person amount exists, because no settlement terms exist. Figures being quoted for this breach are guesses extrapolated from other cases. For scale, the comparable Anthem breach of 78.8 million people settled for $115 million in 2017 — but there is no basis today for predicting what, if anything, this case will pay.
- 3
The free credit monitoring window has closed
Change Healthcare offered two years of free credit monitoring and identity-theft protection through IDX to anyone affected. The deadline to enroll was August 26, 2025 and it has passed. If you enrolled before then, your coverage should still be running; IDX support is reachable at 1-888-846-4705.
- 4
Protect yourself with the free tools you already have
Freeze your credit file at Experian, Equifax and TransUnion — it is free, reversible, and does not affect your credit score. Check your reports at annualcreditreport.com. Read every explanation of benefits from your insurer for care you did not receive, which is how medical identity theft usually shows up. Report any identity theft at identitytheft.gov.
- 5
Keep the letter you received
If a Change Healthcare notification letter arrived in 2024, keep it. Breach notices are often the cleanest proof that you were included, and if a settlement is eventually approved, the notice and any documentation of costs you incurred — credit monitoring you paid for, fraudulent charges, time spent — are exactly what a claim form asks about.
- 6
Get told the day it opens
The gap between a settlement being approved and a claim deadline is often only 60 to 180 days, and nobody mails a reminder. ClaimBee watches settlements as they are approved, scans your email for breach notices you have already received, and files claims on your behalf — so if this one opens, you will not find out after the window has shut.
Missed this one? Don't miss the next.
ClaimBee matches your profile against 2,000+ active settlements, shows payout and proof requirements up front, and tracks every deadline for you.
Frequently asked questions
Is there a Change Healthcare data breach settlement?
Not yet. As of July 2026 the lawsuits over the February 2024 Change Healthcare ransomware attack are still being litigated as MDL No. 3108 in the U.S. District Court for the District of Minnesota. No settlement has been announced or approved, so there is no claim form, no payout and no deadline.
How much will the Change Healthcare settlement pay per person?
Nobody knows, because no settlement exists. Any specific dollar figure you see for this breach is speculation, not a court-approved amount. Payouts in comparable healthcare breach cases have varied widely depending on the fund size, the number of claimants, and whether a person documented actual losses.
Is the Change Healthcare claim form I found online real?
No. There is no official Change Healthcare settlement claim form, because no settlement has been approved. Any site collecting your Social Security number, insurance details or bank information for a Change Healthcare claim today is either a lead-generation operation or a scam. Legitimate settlements are administered by a court-appointed administrator named in a court order.
How do I know if I was affected by the Change Healthcare breach?
Most affected people received a notification letter starting in late July 2024, sent by Change Healthcare rather than by their own doctor or insurer. Because Change Healthcare processes claims and payments for a very large share of US providers and pharmacies, roughly 190 million people were affected — including many who had never heard of the company.
What data was stolen in the Change Healthcare breach?
About 6 terabytes of data. Depending on the record, exposed information included names, addresses, dates of birth, Social Security numbers, government identification numbers, health insurance details, diagnoses, medications, test results, and billing and payment data. Not every affected person had every category exposed.
Can I still get the free credit monitoring from Change Healthcare?
No. Change Healthcare offered two years of free credit monitoring and identity protection through IDX, but the enrollment deadline was August 26, 2025 and it has passed. If you enrolled before the deadline your coverage should still be active — IDX can be reached at 1-888-846-4705. Freezing your credit at all three bureaus is free and available to anyone at any time.
When will the Change Healthcare lawsuit be resolved?
There is no set date. The court has directed the parties toward settlement discussions and mediation, and its case-management schedule ran through amended pleadings on April 1, 2026 and the close of fact discovery on November 2, 2026. No trial date has been set. Even after any settlement is reached, preliminary approval, notice, final approval and a claims window all take additional months.
Do I need a lawyer to be part of the Change Healthcare case?
No. The patient claims are being litigated as a class action by court-appointed lead counsel, so people whose data was exposed are represented without hiring anyone or signing anything. If a settlement is approved, class members typically participate by filing a simple claim form. Healthcare providers with revenue losses from the outage are handled on a separate track of the same MDL.
Related settlements
Closed · Data breach
Anthem $115 Million Data Breach Settlement
Monitoring or up to $50 cash · Closed Jan 29, 2018
Closed · Data breach
Premera Blue Cross $74 Million Data Breach Settlement
~$13 cash; up to $10,000 losses · Closed Mar 30, 2020
Closed · Privacy
Kaiser Permanente $46 Million Privacy Breach Class Action Settlement
$20 – $40 · Closed March 12, 2026
Closed · Data breach
Blackbaud Data Breach Settlement
None — no consumer claim · No consumer claim
Closed · Data breach
National Public Data Breach — No Settlement Exists
$0 · No settlement — nothing to claim
More settlements people are checking
Payout status for other settlements we track, updated as administrators publish new information.