RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · 21 February 2024 event · prepared 16 September 2026

A Citrix portal without MFA halted claims across US health care

UnitedHealth's Senate testimony traces the Change Healthcare breach to one login without multi-factor authentication.

Visual for this record: A Citrix portal without MFA halted claims across US health care
Visual published by dehayf5mhw1h7.cloudfront.net, shown for identification of the record. Credit: dehayf5mhw1h7.cloudfront.net · source page ↗ Rights: owner-review-pending.

What happened

According to testimony given by UnitedHealth Group chief executive Andrew Witty to the Senate Finance Committee, criminals used compromised credentials on 12 February 2024 to remotely access a Citrix portal used by Change Healthcare, a claims-processing subsidiary of Optum. Witty's written testimony states plainly that the portal did not have multi-factor authentication enabled. Once inside, the intruders moved laterally through Change Healthcare's systems and exfiltrated data. Nine days later, on 21 February, a group identifying itself as ALPHV or BlackCat deployed ransomware that encrypted the company's technology environment.

The company severed connectivity to contain the intrusion, an action that itself halted claims processing, pharmacy transactions and payments across a large share of the American health system. Witty told the committee that pharmacy claims processing returned to 99 percent of pre-incident volume by 7 March, while payment processing, representing about six percent of the country's total payment volume, was still below full recovery by the time of the hearing on 1 May.

Confidence and limits

This account rests on sworn testimony from the company that owns the affected systems, delivered in an official congressional hearing rather than an independent forensic report. It is corroborated by the fact that the hearing itself occurred and by the committee's own published record, which gives it official-corroboration rather than primary-confirmed standing. Witty acknowledged that the full scope of compromised patient and provider data remained under review months after the attack, and he did not identify the specific individuals who carried out the intrusion. The testimony does not establish who within the ALPHV affiliate structure was responsible, only the technical entry point and its consequence.

Why it mattered

Change Healthcare processes a very large share of US medical claims and prescriptions, so one company's unpatched authentication gap became a systemic dependency for hospitals, pharmacies and independent practices nationwide. The event demonstrated that consolidation in health care technology creates concentration risk: a single control failure at one clearinghouse can propagate further than a comparable failure at a single hospital. UnitedHealth Group's own emergency funding programs, which the testimony says advanced more than six billion dollars to providers, illustrate the scale of disruption an unavailable intermediary can cause.

Defensive takeaway

If your organization depends on a third-party clearinghouse, payment processor or similarly central intermediary, ask that vendor directly whether every remote-access point into its environment requires phishing-resistant multi-factor authentication, and build a documented fallback process for the day that intermediary goes dark.

  • Do we know every remote-access application exposed to the internet across our full technology estate, including recently acquired subsidiaries?
  • Would our organization be able to continue essential operations for several weeks if a single upstream vendor became unavailable?
  • Who is responsible for verifying that acquired systems meet our authentication standards before, not after, they are connected to production data?

The Change Healthcare case is a reminder that a single missing control, not a novel technique, can produce a national-scale disruption when the affected system sits at a chokepoint the rest of an industry depends on.

Defensive takeaway

Check whether every remote-access portal in your environment, including ones acquired through mergers, enforces phishing-resistant multi-factor authentication before treating it as a trusted entry point.

UnitedHealth Group's CEO gave this account under oath to the Senate Finance Committee, corroborated by the committee's own hearing record; the company's testimony is the primary source for the technical sequence, and independent verification of the full scope of affected records was still ongoing at the time of testimony.

Sources & reading trail

Hacking America's Health Care: Assessing the Change Healthcare Cyber Attack and What's Next ↗

Establishes that the Senate Finance Committee held a hearing on 1 May 2024 examining the Change Healthcare cyberattack, with Andrew Witty as the sole witness.

government-primary · Source published: 1 May 2024 · Retrieved: 16 September 2026

Testimony of Andrew Witty, Chief Executive Officer, UnitedHealth Group, Before the Senate Finance Committee ↗

States that criminals used compromised credentials to access a Citrix portal without multi-factor authentication on 12 February 2024 and deployed ransomware nine days later.

company-primary · Source published: 1 May 2024 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.