Skip to content
Back to Blog
low severity September 16, 2024 · 4 min read

Change Healthcare Data Breach Notice (Oregon Attorney General)

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

Change Healthcare notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on September 16, 2024. The filing puts the incident itself on February 17, 2024.

Change Healthcare Data Breach Notice (Oregon Attorney General)

The February 17, 2024 breach at Change Healthcare placed personal information belonging to an unknown number of Oregon residents into the hands of unauthorised parties. The organisation filed its formal notification with the Oregon Department of Justice on September 16, 2024 — 212 days later.

That seven-month gap is the single most striking fact in the record. While notification deadlines vary by the complexity of the investigation and by state requirements, the interval is long enough that many affected individuals first learned of the incident through this filing rather than a direct letter.

The Information That Was Exposed

The filing lists only one broad category: personal information. No passwords, no financial account numbers, no medical records, and no government identifiers such as Social Security numbers are named in the exposed categories for this specific Oregon notice. This is genuinely good news. The absence of those high-risk fields removes several of the most damaging long-term consequences that usually follow a healthcare-related breach.

Because the record names only personal information, the people whose records were included face lower immediate risk than many assume when they see the words “Change Healthcare” and “breach” together. The organisation is required to notify affected Oregon residents directly, usually by mail. If you have not received such a letter at your address on file as of February 17, 2024, your information was likely not part of this incident. Anyone who has moved since that date should contact Change Healthcare directly to confirm their status.

What This Exposure Actually Enables

Personal information alone can still be used to craft convincing phishing messages, impersonation attempts, or fraudulent customer-service calls. Attackers who already hold other pieces of your data from previous breaches can combine them with whatever was taken here to build a more complete profile. The risk is real but narrower than the panic headlines suggest.

Because no permanent identifiers were exposed, you do not face the lifetime monitoring burden that comes with a stolen Social Security number or passport. The exposure does not require you to freeze credit reports or place fraud alerts solely because of this incident. That distinction matters. Many people in your position waste hours and money on protective steps that this specific filing does not justify.

The Related UnitedHealth Group Incident

This Oregon filing is part of the wider UnitedHealth Group/Change Healthcare events that began in early 2024. The uncertainties around exact initial access and whether the compromise occurred at Change Healthcare or a vendor remain unresolved in public records. The filing itself does not disclose those details, and speculation does not help you protect yourself.

What is clear is that healthcare payment and records processors hold data that retains value far longer than passwords or credit cards. Even limited personal information can support identity-related fraud months or years later when combined with data from other sources.

Concrete Steps That Match This Specific Exposure

  • Watch for phishing and impersonation attempts. Treat every unexpected call, email, or text claiming to be from Change Healthcare, Optum, or your insurer with suspicion. Verify requests through official channels you initiate yourself.
  • Review your Explanation of Benefits statements. Continue monitoring insurance statements for any claims you do not recognise, even though medical details were not listed in this filing. Early detection remains your best defense.
  • Place a fraud alert if you have received a notification letter. A 90-day fraud alert with one of the three major credit bureaus is sufficient given the limited categories exposed; a full credit freeze is unnecessary unless you have other reasons for concern.
  • Contact Change Healthcare directly if you moved after February 17, 2024. Ask them to confirm whether your records were included. Their customer service can access the precise list that the public filing does not provide.
  • Keep records of any communication. Save copies of the notification letter, dates you contact the company, and names of representatives. Documentation protects you if issues arise later.

The exposure of personal information in this incident is serious but contained. No passwords were exposed, so there is no need to change credentials for Change Healthcare or related services. No biographic identifiers that cannot be reissued were listed. Your primary ongoing task is vigilance against social engineering rather than emergency credit repair or password resets.

The seven-month delay between the February 17 incident and the September 16 filing means many people are only now learning their data may have been involved. If you have not received a letter, that absence is the most reliable indicator available. Where doubt remains, reaching out to the organisation is the only step that can resolve it.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed September 16, 2024
Last reviewed July 22, 2026
Affected Unconfirmed
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email