The Thread · Privacy & The Provider Squeeze
The Change Healthcare Breach
UnitedHealth owns the artery that carries roughly a third of all U.S. medical claims — and it owns a bank. In 2024 the artery went down. Providers bled out at zero revenue for weeks. Then the bank showed up with a loan — and came back to collect like a loan shark.
I. The Artery Goes Down
February 21, 2024
Change Healthcare is a UnitedHealth subsidiary, folded into Optum Insight. It is not a small piece of plumbing — it processes roughly 15 billion healthcare transactions a year, touches about one-third of all U.S. patient records, and clears on the order of $2 trillion in payments. When UnitedHealth acquired it, the company placed itself at the center of the nation's medical billing system.
On February 21, 2024, a ransomware attack took it down. Twenty-one parts of Change's business were affected. Hospitals and practices could no longer submit claims, get reimbursed, or even verify a patient's insurance eligibility. Pharmacies couldn't fill prescriptions. Patients couldn't get their medications. The country's billing backbone simply stopped.
One physician reported their practice went "5 weeks with $0 in revenue" because of the outage. They were not unusual.
The breach also exposed an extraordinary amount of personal data. By later court filings, the exposure reached an estimated 192.7 million people — and state attorneys general, including Nebraska's, sued over the failure to protect it.
II. The "Help"
A Loan From the Company That Broke You
UnitedHealth doesn't just own the artery. It owns a bank — Optum Bank, the second-largest provider of health savings accounts in the country, with roughly $20 billion in assets — and a lending arm, Optum Financial. So when the providers it had cut off from revenue began to drown, UnitedHealth offered them a lifeline: emergency loans.
How did it decide whom to lend to? UnitedHealth has been accused of using its own proprietary insurance claims data — the data it sees because it processes everyone's claims — to flag prospective borrowers for Optum Bank, a practice that may run afoul of privacy and lending law. It is not the first time: the Department of Justice previously sued UnitedHealth over the misuse of claims data in 2022.
Read plainly: the company broke the payment system, watched the providers it serves go insolvent, used its monopoly view of their finances to identify who was desperate, and offered them debt.
III. The Collection
"Repay in Five Days — or We Garnish Your Claims"
By 2025, with many practices still recovering, UnitedHealth turned to collection — and the reporting describes tactics that earned the company a blunt label from one outlet: loan shark.
Providers received threatening communications demanding repayment in full — or risk having their insurance reimbursements withheld. The most documented case is Dr. Christine Meyer, a Pennsylvania internist who said her independent primary-care practice lost more than $1 million in revenue as a direct result of the cyberattack. She wrote publicly that Optum Financial demanded she repay a loan of more than $750,000 — and threatened to garnish her practice's claim reimbursements if she did not repay within five business days.
The mechanism closes a loop: UnitedHealth controls the reimbursements the provider is owed and the loan the provider was given. It can simply take the first to satisfy the second — leverage no ordinary lender has.
The Wall Street Journal and CNBC both reported UnitedHealth sending demands for repayment of the cyberattack loans in the spring of 2025.
IV. The Scrutiny
The Senate Is Asking
Senators Ron Wyden and Elizabeth Warren pressed UnitedHealth for answers on what they characterized as abusive tactics to recoup the loans it made to doctors after the mass cyberattack. The probe into the predatory loan collections has been covered across the trade and health-policy press — Becker's Hospital Review, the HIPAA Journal, and Medical Economics among them.
Alongside the Senate inquiry, the breach itself has produced a consolidated provider class action over the disruption to claims and payments, and state attorney-general action over the exposed data.
This thread isn't only a privacy story. It is the clearest single illustration of why vertical integration is dangerous: a company that owns the payment system, the insurer, the provider network, and the bank can turn its own failure into a profit center, and turn the people it serves into debtors it can collect from at will. It rhymes with every other entry in this room — the same move, run on a national scale: starve the independent provider, then absorb what's left.
Sources