The Change Healthcare data breach lawsuit is a consolidated federal class action pending in the U.S. District Court for the District of Minnesota before Judge Donovan W. Frank, formally captioned In Re: Change Healthcare, Inc. Customer Data Security Breach Litigation, MDL No. 3108. As of mid-2026, the case is in fact discovery. No class has been certified, no settlement has been proposed, and there is no claims process open for the roughly 192.7 million people whose data was exposed in the February 2024 ransomware attack.
Where the Case Stands Right Now
The Judicial Panel on Multidistrict Litigation consolidated dozens of suits filed around the country and transferred them to Minnesota on June 7, 2024. The defendants are Change Healthcare, Optum, and UnitedHealth Group. The complaints allege negligence, negligence per se, unjust enrichment, and violations of state consumer protection laws, all built around the claim that the defendants failed to adequately secure the sensitive data flowing through Change Healthcare’s clearinghouse.
The litigation is split into two tracks. The patient track covers individuals whose personal, medical, or financial information was exposed. The provider track covers hospitals, pharmacies, physician practices, and other healthcare entities that lost revenue when the claims-processing system went down.
On December 19, 2025, Judge Frank ruled on the defendants’ motions to dismiss in both tracks, granting them in part and denying them in part. The core negligence and consumer-protection claims survived. Contract, nuisance, and other peripheral allegations that the court found did not fit the facts were dismissed. That ruling cleared the central legal theories to move into discovery.
The pretrial schedule sets these deadlines:
- Amended pleadings were due April 1, 2026.
- Fact discovery closes November 2, 2026.
- Non-dispositive motions are due November 6, 2026.
Status conferences have been running regularly, with the most recent on May 19, 2026, and the next scheduled for June 18, 2026. Magistrate Judge Dulce J. Foster has been facilitating early settlement discussions. In a March 2026 order, Judge Foster directed the parties to exchange names of private mediators, noting that while “formal settlement discussions are likely premature,” the court wanted to begin building a framework. A confidential settlement-related conference between lead counsel and the magistrate judge was set for June 18, 2026.
Class certification briefing has not been scheduled. No bellwether trial date has been set. The litigation is expected to continue well into 2027 at a minimum.
Who the Lawsuit Covers
The patient track is meant for individuals whose information passed through Change Healthcare and was compromised in the breach. Change Healthcare reported to the Department of Health and Human Services that approximately 192.7 million individuals were affected, making this the largest healthcare data breach in U.S. history. The exposed data varies by person but falls into four broad categories:
- Personal identifiers, including names, addresses, dates of birth, Social Security numbers, driver’s license and state ID numbers, and passport numbers.
- Health insurance information, including plan and policy details, member and group ID numbers, and Medicare or Medicaid IDs.
- Medical information, including medical record numbers, provider names, diagnoses, medications, test results, imaging records, and treatment details.
- Billing and payment data, including claim numbers, account numbers, billing codes, payment card information, banking details, and balances due.
Change Healthcare has said some of the exposed data belonged to “guarantors” who paid bills on behalf of patients rather than the patients themselves. The company also said it had not seen evidence that full medical histories were among the stolen records.
The provider track is separate. It is for healthcare entities that suffered financial harm when Change Healthcare’s clearinghouse went offline and they could not submit claims or verify insurance for weeks. Individuals do not participate in that track.
Can You File a Claim Yet
No. There is currently no way to file a claim or formally join the class action. Claims processes only open after a class is certified and a settlement is approved or a judgment entered, and none of those has happened. If and when a claims process is established, it will come with defined eligibility rules and filing deadlines that will be publicized at that time.
What you can do now is confirm whether you were notified. Change Healthcare began mailing individual breach notification letters in mid-2024 and reported to HHS that approximately 130 million notices had been sent by January 2025. Notifications for many affected individuals still had not gone out as of the most recent HHS updates, in part because the responsibility to notify patients is shared between Change Healthcare and the individual providers whose data passed through its systems. A letter may still be coming even if you have not received one.
UnitedHealth Group has set up a support website and a dedicated phone line at 1-866-262-5342 offering credit monitoring and identity-theft protection to affected individuals. Enrolling in those services does not waive any right to participate in the class action later.
Government Actions Running Alongside the MDL
Two other proceedings could affect what eventually happens.
Nebraska Attorney General Mike Hilgers filed a state-court lawsuit against Change Healthcare, UnitedHealth Group, and Optum on December 16, 2024, in Lancaster County District Court. The complaint alleges violations of Nebraska’s Consumer Protection Act, its Financial Data Protection and Consumer Notification of Data Security Breach Act, and its Uniform Deceptive Trade Practices Act, each carrying penalties of $2,000 per infraction. The state focuses on the lack of multi-factor authentication and a delay of nearly five months in notifying Nebraska consumers. The complaint estimated 575,000 Nebraskans were affected; the court later cited a figure closer to 900,000. On November 10, 2025, Judge Strong denied the defendants’ motion to dismiss, ruling the state had “sufficiently alleged all” of its claimed violations. Hilgers has said his office is “aggressively trying to get the case to a jury trial.”
The HHS Office for Civil Rights opened a HIPAA investigation into both Change Healthcare and UnitedHealth Group on March 13, 2024. OCR Director Melanie Fontes Rainer cited the “unprecedented magnitude” of the attack. The investigation, which is examining compliance with HIPAA privacy, security, and breach notification requirements, remains open. A coalition of 22 state attorneys general also sent a joint letter to UnitedHealth Group in April 2024 demanding stronger data security and reserving their rights to pursue enforcement actions. Beyond Nebraska, no other state has filed its own suit as of mid-2026 based on available reporting.
How the Breach Happened
Change Healthcare is the largest medical claims clearinghouse in the United States, processing roughly 15 billion health insurance claims each year. UnitedHealth Group acquired the company in October 2022 for $13.8 billion and folded it into its Optum business unit.
On February 12, 2024, hackers affiliated with the ALPHV/BlackCat ransomware group broke into Change Healthcare’s network through a Citrix remote-access portal that did not have multi-factor authentication enabled. The intruders spent nine days moving through the company’s systems and extracting data before launching ransomware on February 21, 2024. Change Healthcare took more than 100 systems offline, freezing insurance verification, claims submission, and payment processing for hospitals, pharmacies, and physician offices across the country.
UnitedHealth Group CEO Andrew Witty confirmed during Senate Finance Committee testimony on May 1, 2024, that the company paid approximately $22 million in bitcoin to the attackers on March 3, 2024. Witty acknowledged the compromised server lacked multi-factor authentication and estimated that roughly one-third of Americans may have had their health information exposed. He said all of UnitedHealth’s external-facing systems had since been equipped with multi-factor authentication.
The picture grew more complicated in April 2024 when a separate group called RansomHub, reportedly made up of former ALPHV affiliates, began a second extortion campaign, claiming the original ransom never reached the affiliates who actually stole the data and posting screenshots of stolen records on the dark web. There is no public reporting that a second ransom was paid. These facts, and the security failures behind them, are the foundation of the plaintiffs’ negligence claims moving forward in Minnesota.