Criterica Intelligence — production models trained on real court records, not synthetic data
Data Breach — MDL No. 3108

Change Healthcare, Inc.

U.S. District Court for the District of Minnesota

The Change Healthcare, Inc., Customer Data Security Breach litigation was centralized before Judge Donovan W. Frank in the District of Minnesota in June 2024, consolidating claims arising from a ransomware attack against Change Healthcare, a UnitedHealth Group subsidiary that operates critical claims-processing and payment infrastructure used across a very large share of the U.S. healthcare system. The attack both disrupted healthcare operations nationally — delaying claims processing and prescription fulfillment for providers and patients — and exposed personal and health information for a substantial patient population whose data flowed through Change Healthcare's systems.

With 152 pending actions, this is one of the larger and most structurally significant dockets in the healthcare data-breach category, reflecting Change Healthcare's role as shared infrastructure across an unusually broad swath of the healthcare industry. Resolution risk in this docket is shaped by both the scale of the affected population and the operational-disruption dimension of the incident, which is distinct from a typical data-exposure breach and may generate additional claim theories tied to delayed care or payment disruption alongside the core data-privacy claims.

Given Change Healthcare's central, infrastructure-like position in the healthcare payment ecosystem, this docket is a significant test case for how litigation addresses breaches of shared critical infrastructure that combine both data-exposure and operational-disruption harms, a combination not present in most conventional data-breach MDLs. Criterica Intelligence's platform tracks this kind of critical-infrastructure breach pattern distinctly from standard data-exposure litigation, since the dual nature of the harm can meaningfully affect both the damages theories available and the docket's overall resolution timeline. A companion capital brief on this docket is available through Criterica Capital.

Frequently Asked Questions
Why was the Change Healthcare breach so disruptive nationally?

Because Change Healthcare operates critical claims-processing and payment infrastructure used across a very large share of the U.S. healthcare system, the ransomware attack delayed claims processing and prescription fulfillment broadly, in addition to exposing patient data.

How is this docket different from a typical data-breach MDL?

It combines both data-exposure harm and operational-disruption harm — delayed care and payment processing — which is not present in most conventional data-breach litigation and may support additional claim theories.

What drives the scale of this docket?

Change Healthcare's central, infrastructure-like role in the healthcare payment ecosystem, which means the affected population spans an unusually broad cross-section of providers, pharmacies, payers, and patients.

What does this docket represent for critical-infrastructure breach litigation?

A significant test case for how courts address breaches of shared healthcare infrastructure combining data-exposure and operational-disruption harms, a pattern Criterica Intelligence tracks distinctly from standard data-breach litigation.

Statistics shown reflect historical or illustrative model outputs derived from real case data. They are not predictions or guarantees of any individual outcome. Litigation results depend on facts, jurisdiction, judge, and counsel, and vary case by case. Model accuracy is subject to selection effects and changing legal dynamics.

← All Pending MDLsFunding brief on Criterica Capital →