Change Healthcare (Feb 2024): A Citrix Portal Without MFA and a Health System Outage
Facts in this article were checked against the sources listed below as of Oct 5, 2026.
Retrospective: this article looks back at events from February 2024, written in 2026 with the benefit of hindsight.
On February 21, 2024, ransomware hit Change Healthcare, a UnitedHealth Group subsidiary that processes a large share of US medical claims. Pharmacies struggled to fill prescriptions, providers couldn't get paid, and the disruption rippled across the healthcare system for weeks.
- Stolen credentialsFebruary 12, 2024: ALPHV/BlackCat affiliates log in to a Change Healthcare Citrix remote access portal using compromised credentials.
- No MFAThe portal does not require multi-factor authentication.
- Movement and theftOver nine days the attackers move through the environment and exfiltrate data.
- RansomwareFebruary 21, 2024: ransomware encrypts Change Healthcare systems, disrupting claims and pharmacy processing nationwide.
- AftermathUnitedHealth pays a $22 million ransom; about 192.7 million individuals are reported affected.
When UnitedHealth's CEO, Andrew Witty, testified before Congress, he explained how it started. The answer was not a sophisticated exploit.
What happened
According to Witty's testimony:
- On February 12, 2024, attackers from the ALPHV/BlackCat ransomware operation used compromised credentials to log in to a Citrix remote access portal at Change Healthcare.
- The portal did not use multi-factor authentication.
- Nine days later, on February 21, the attackers deployed ransomware that encrypted Change Healthcare's systems.
UnitedHealth confirmed it paid a $22 million ransom in bitcoin. Witty said the company still did not get its data back; another group later attempted further extortion. Change Healthcare ultimately notified the US Department of Health and Human Services that approximately 192.7 million individuals were affected — one of the largest healthcare data breaches in US history.
Change Healthcare had been acquired by UnitedHealth in 2022, prompting questions in Congress about how quickly acquired systems were brought up to the parent company's security standards.
Why it mattered
One missing control, systemic impact. Change Healthcare sat in the middle of US healthcare payments. A remote access portal without MFA became a national disruption.
The Colonial Pipeline lesson, repeated. In 2021, Colonial Pipeline was breached through a legacy VPN account protected only by a password. Three years later, a remote access portal without MFA led to an even larger crisis.
Acquisitions inherit risk. Systems that arrive through an acquisition often run under the old owner's standards until someone deliberately changes them.
Paying didn't end it. The ransom payment didn't guarantee data deletion and didn't prevent further extortion attempts.
What to do now
- Inventory every remote access entry point. VPNs, Citrix and other virtual desktop gateways, RD Gateways, remote support tools, network appliance admin interfaces and SaaS admin consoles. Confirm with external scans, firewall rules and acquisition records.
- Put authentication through Entra ID wherever possible. Use SAML or OIDC single sign-on for modern gateways, the NPS extension for Entra multifactor authentication for RADIUS-based VPNs and RD Gateways, or Entra Private Access and application proxy to publish internal apps without a VPN. Then Conditional Access — and MFA — applies.
- Require phishing-resistant MFA and compliant devices for remote access, starting with administrators.
- Remove local accounts on gateways except a documented, separately protected break-glass account.
- Verify continuously. Review Entra sign-in logs for single-factor access to remote access applications, and rescan externally every month for new endpoints.
- Segment critical systems so a single remote access session can't reach everything.
- Make remote access MFA an acquisition day-one requirement.
- Plan for long outages. Identify critical suppliers and processes and test how you'd operate for weeks without them.
How to detect single-factor remote access
You can find this exposure before attackers do:
- Entra ID sign-in logs. For remote access applications integrated with Entra ID, filter successful sign-ins where
AuthenticationRequirementissingleFactorAuthentication. Every result is either a documented exception or a gap. - Gateway logs. Forward Citrix, VPN and RD Gateway logs to Microsoft Sentinel. Look for logins by accounts without an MFA claim, logins from new countries or hosting providers, and dormant accounts suddenly active.
- Post-login behavior. Ransomware operators typically run reconnaissance soon after entry: domain trust enumeration, queries for Domain Admins, AD enumeration tools and RDP to many hosts. Defender for Endpoint and Defender for Identity detect many of these patterns.
- External scanning. Monthly scans of your public IP ranges catch new or forgotten remote access endpoints.
Common mistakes
- Exceptions that never expire. A gateway excluded from MFA "temporarily" during a migration can stay that way for years.
- Local accounts on appliances that bypass central identity entirely.
- Assuming acquired companies match your standards. They usually don't until someone checks.
- No plan for prolonged outages. Change Healthcare's customers needed contingency processes for weeks, not hours.
What changed afterward
The attack prompted congressional hearings in which UnitedHealth's CEO testified about the missing MFA and the decision to pay the ransom. It intensified regulatory focus on healthcare cybersecurity and on the concentration risk created when a single company sits in the middle of an industry's payments.
For other organizations, the most practical change is in how MFA is verified. Many companies believed they had "MFA everywhere" because their main email and cloud apps required it. Change Healthcare showed that the exceptions — an older remote access portal, a system from an acquisition, a vendor login — are where attackers go. Verification has to be continuous and evidence-based: sign-in logs and external scans, reviewed regularly, rather than a statement in a policy document.
MFA strength matters too. By 2026, phishing kits that steal sessions or trick users into approving device-code sign-ins were sold as subscription services. Requiring MFA on every remote access path is the minimum; phishing-resistant methods for administrators and remote access are the next step.
Questions for leadership
- Does every remote access path into our environment require MFA — with no exceptions?
- How do we verify that acquired companies meet our security baseline?
- Which suppliers would cause a business crisis if they were offline for a month, and what is our plan?
Key takeaways
- Change Healthcare was breached through a Citrix portal without MFA using stolen credentials.
- Ransomware followed nine days later, disrupting US healthcare and affecting about 192.7 million people.
- A $22 million ransom did not guarantee data recovery.
- MFA on every remote access path, verified continuously, is the control that matters most.
Sources
- How to Enforce MFA on Every Remote Access Portal How-To & Hardening
- Detecting Remote Access Without MFA: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: Change Healthcare and the Systemic Risk of One Missing Control CIO Briefings