Change Healthcare Inc. Data Breach Notice (Oregon Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Change Healthcare Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on August 03, 2024. The filing puts the incident itself on February 12, 2024.
The February 12, 2024 breach at Change Healthcare exposed personal information belonging to 250 Oregon residents. The company filed its formal notification with the Oregon Department of Justice on August 03, 2024 — 173 days later.
That five-and-a-half-month gap is the single most striking fact in the record. While notification deadlines vary by state and depend on when an investigation concludes, the interval is long enough to matter to anyone whose records were included.
No Passwords or Credentials Were Exposed
The filing lists only personal information. No passwords, no login details, and no financial account credentials appear in the exposed categories. This is genuinely good news. It means the breach does not put any of your Change Healthcare accounts at direct risk of takeover. You do not need to change any passwords because of this incident.
What the Exposed Personal Information Actually Enables
Personal information in this context typically includes details that can support identity theft or fraud attempts. With enough of it, someone could try to open accounts, file fraudulent tax returns, or impersonate you in medical or insurance settings. Because no permanent government identifiers such as Social Security numbers were exposed, the risk profile is lower than many healthcare breaches, but the data still retains value to fraudsters.
The people whose records were included cannot change the fact that this information now exists outside Change Healthcare’s systems. What they can control is how closely they monitor for misuse.
The Letter Is the Only Reliable Way to Know If You Are Affected
Change Healthcare is required to notify affected individuals directly, usually by mail. If you have not received a letter, your information was most likely not part of the 250 records included in this filing. However, if you have moved since February 12, 2024, the letter may have gone to an old address. In that case, contact Change Healthcare directly to confirm whether your records were involved.
Why the Delay Matters to You
A 173-day interval between the incident and the filing means the organization spent nearly six months investigating, containing, and preparing notifications. During that period the exposed personal information was outside their direct control. While the record does not disclose whether the data was exfiltrated or the exact initial access vector, the length of time before public notice leaves affected individuals with a longer window of unknown risk.
This is not a judgement about the company’s conduct. It is simply what the dates on the filing show. For the 250 people named, those dates shift the practical timeline for vigilance.
What You Can Still Control
Even without passwords or Social Security numbers in the exposed data, basic protective steps remain valuable. The goal is to make it harder for anyone who may have obtained the personal information to turn it into usable fraud.
- Place a fraud alert with the three major credit bureaus. This forces lenders to verify your identity before opening new accounts and lasts 90 days, after which you can renew it.
- Review every Explanation of Benefits statement from your health insurer. Look for claims you do not recognize. Medical identity theft can lead to incorrect information in your permanent health record.
- Monitor your credit reports weekly for the next six months. Free weekly reports are available from AnnualCreditReport.com. Look for accounts or inquiries you did not authorize.
- Be wary of unsolicited calls, texts, or emails that appear to come from insurers, pharmacies, or government agencies asking for personal details. Use known official contact numbers instead of replying directly.
- File your taxes early next year and consider using an IRS Identity Protection PIN if you have not already. This adds an extra verification layer even when full Social Security numbers are not exposed.
The exposure of personal information from a healthcare provider carries lifelong implications because medical and insurance records are difficult to correct once contaminated. Yet the absence of credentials and certain high-value identifiers in this specific filing limits what attackers can do immediately.
Stay alert, use the letter as your personal confirmation, and treat the next twelve months as a period that requires tighter monitoring than usual. The record gives you the dates, the number of people affected, and the categories. Everything else is what you choose to do with that information.
Report details & sourcing
Related breaches
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…
Castle Management, LLC Data Breach Notice (Vermont Attorney General)
Castle Management, LLC notified Vermont residents of a data breach in a filing reported to the Vermo…
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…