On 12 February 2024, attackers used stolen credentials to log into a Citrix remote access portal operated by Change Healthcare, a UnitedHealth Group subsidiary that processes approximately one third of all healthcare transactions in the United States. The portal did not have multi-factor authentication enabled.
That was the only thing standing between the attackers and one of the most sensitive healthcare datasets in existence. There was no MFA. The credentials worked. They were in.
Over the following nine days, the attackers - an affiliate of the BlackCat/ALPHV ransomware group - moved laterally through Change Healthcare's network and exfiltrated an estimated 4 terabytes of data. On 21 February they deployed ransomware, encrypting systems across the organisation. Change Healthcare severed connectivity with its data centres to stop the spread. Prescription processing, insurance claims, and healthcare provider payments stopped functioning across the country. Hospitals and medical practices were left unable to verify patient insurance, process prescriptions, or receive payments, with smaller practices forced to use personal funds to remain operational.
UnitedHealth paid a $22 million ransom in Bitcoin to ALPHV. ALPHV then exit-scammed their own affiliate, disappeared with the money, and left the affiliate - known as "notchy" — still holding the data. Notchy took it to a second ransomware group, RansomHub, which launched a separate extortion campaign. UnitedHealth refused to pay again. The data was exposed regardless.
The final count of affected individuals reached 190 million - the largest healthcare data breach in US history, covering roughly two thirds of the American population. UnitedHealth's total response costs exceeded $2.9 billion.
UnitedHealth CEO Andrew Witty testified before the US Senate Finance Committee in May 2024, confirming that the entry point was a Citrix portal without MFA. A single missing security control on a remote access portal opened the door to the largest healthcare breach in history.
The Citrix portal without MFA is the perimeter failure. But the nine days of lateral movement, the 4TB data exfiltration, and the ransomware deployment that followed are execution boundary failures. Each of those actions - accessing sensitive patient records at scale, moving across systems, deploying encryption across production infrastructure - executed without a confirmed human authority decision at any point.
GoFirm Deep Guard, configured at the data access and infrastructure layer, gates exactly these actions. Bulk access to patient records, lateral movement into sensitive environments, and infrastructure-level changes each require a named authority to confirm on their registered device before they execute. An attacker who has successfully authenticated via a Citrix portal, with or without MFA, still cannot produce that confirmation.
The missing MFA let them in. The missing execution control is what allowed $2.9 billion worth of damage to follow.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.
References
1. Kaspersky, The Complete Story of the 2024 Ransomware Attack on UnitedHealth, February 2025
2. Censinet, Lessons from Change Healthcare Breach: What to Know, April 2026
3. Safeguard.sh, Change Healthcare Ransomware 2024: Deep Dive Post-Mortem, March 2026
4. The HIPAA Guide, Change Healthcare Data Breach: 192.7 Million Affected, August 2025
