Change Healthcare Data Breach Settlement: No Settlement Yet
Is there a Change Healthcare data breach settlement?
No. As of July 2026, there is no Change Healthcare data breach settlement, no settlement fund, and no claim form anywhere for consumers or providers to file. If you searched for this because you got a breach notice, or because you saw a site offering to submit a "Change Healthcare settlement claim," the honest answer is that nothing exists yet to claim.
What happened
Change Healthcare, a UnitedHealth Group subsidiary that processes medical claims, billing, and prescriptions for a large share of the U.S. health care system, was the subject of a major cybersecurity incident. Change Healthcare notified the U.S. Department of Health and Human Services' Office for Civil Rights (OCR) on July 31, 2025 that approximately 192.7 million individuals were impacted, making it one of the largest health data breaches ever reported to federal regulators.
Because Change Healthcare sits behind so many hospitals, pharmacies, and insurers, the affected population includes both patients whose health information passed through its systems and the providers and practices that rely on it to get paid. That split is why the lawsuits against Change Healthcare and UnitedHealth Group are organized into two separate tracks rather than one.
The HIPAA breach notification rule is why a company like Change Healthcare has to tell HHS's Office for Civil Rights about an incident like this at all. Covered entities and their business associates are required to notify OCR when unsecured protected health information is exposed, and OCR publishes and updates that notification through its own channels, including the FAQ page cited on this page. That reporting obligation is a regulatory requirement, separate from the civil lawsuits described below; it does not create a payout for anyone on its own.
Where the litigation stands right now, and why
The lawsuits filed around the country over this breach have been consolidated into a single federal proceeding, MDL No. 3108, case 0:24-md-03108 (DWF/DJF), in the U.S. District Court for the District of Minnesota, before Judge Donovan W. Frank and Magistrate Judge Dulce J. Foster. Consolidating related cases into one court under one judge is standard practice for large breach litigation. It does not mean a settlement is close; it only means the cases are being managed together.
The litigation runs on two tracks. The Provider Actions track covers health care providers and practices that used Change Healthcare's systems. The Patient Actions track covers individual patients and health plan members whose information was exposed. Consolidated master complaints were filed in both tracks in July 2025. As of July 2026 the court has directed the parties into private mediation, while noting in the same order that formal settlement discussions are likely premature at this stage of the case. That is a normal step in litigation this size and is not an indication that a settlement has been reached.
No class has been certified in either track, and no settlement has been reached. That sequence matters: a case typically has to clear class certification, and often survive motions to dismiss, before settlement talks can produce anything a claims administrator could actually pay out. Nothing on the public docket points to a settlement being imminent, and this page will not guess at a date.
How a case like this typically resolves
Large data breach MDLs generally end one of three ways. Most commonly, the parties reach a negotiated settlement that a judge has to preliminarily and then finally approve, which is what eventually creates a fund and a claim form. Less commonly, a case goes to trial and produces a jury verdict, which is a different legal event from a settlement and does not come with a consumer claims process by default. A case can also be narrowed or dismissed in whole or in part on a motion, which changes who remains in the litigation without any payout at all. As of July 2026, MDL No. 3108 has not reached any of those three endpoints; it is still in the earlier stage of pleadings and case management described above.
Who is part of the lawsuits
If you are a patient or health plan member whose data may have passed through Change Healthcare's systems, you would fall under the Patient Actions track. If you are a health care provider, practice, or billing entity that used Change Healthcare to process claims, you would fall under the Provider Actions track.
Being a potential class member in an MDL does not require you to do anything right now. There is no form to sign up for, no deadline to meet, and no fee to pay to "join" the case. If a settlement is reached and a class is certified later, notice and a claims process would follow at that point, not before.
Why there is no payout figure to give you
Some settlement pages on this site can tell you a realistic payout range, because a fund exists and a court has approved a claims process for it. This is not one of those pages. There is no settlement fund, no payout structure, and no documented-loss cap for the Change Healthcare litigation, because there is no settlement.
Any number you see elsewhere describing what claimants will supposedly "get" from a Change Healthcare settlement is not based on anything that has actually happened in this case yet.
The scam risk here is the real story
Because this breach affected roughly 192.7 million people and made national news, it is a magnet for search ads and social posts pushing a fake "Change Healthcare settlement claim" page. Since no claims process exists, any site asking you to submit a claim, verify your identity, or enter a Social Security number, insurance ID, or payment details to "receive your Change Healthcare settlement payout" is not a legitimate source. This isn't a generic warning; it describes exactly what a scam aimed at this breach looks like, because the real thing it would need to imitate does not exist.
If a real settlement is ever reached, notice will come from a court-appointed settlement administrator through an official case website tied to the docket above, never from an unsolicited text message, email, or search ad promising a fast payout.
What to do right now
You do not need to wait for a settlement to protect yourself; the exposure already happened. Place a free security freeze with all three major credit bureaus, Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and does not cost anything or hurt your credit score.
A credit freeze does not catch medical identity theft, which is the specific risk in a health data breach like this one. Someone using your stolen health information will not show up on a credit report; they show up on your insurance claims instead. Review the explanation of benefits (EOB) statements your health plan sends for care, prescriptions, or equipment you did not receive, and call your insurer if anything looks unfamiliar.
If you find signs of fraud, financial or medical, report it at IdentityTheft.gov, the Federal Trade Commission's official recovery site. It walks you through a personalized recovery plan and helps generate the letters and affidavits many insurers and creditors require.
Keep your own records as you go. Save any breach notice letter you received, note the date you placed each credit freeze, and keep copies of any EOB statement you flag as unfamiliar. If a settlement or a claims process is ever created for this litigation, having your own timeline and documentation ready will make it easier to act quickly, whatever the eventual proof requirements turn out to be.
What to watch for next
Case-management activity in MDL No. 3108 continues in the District of Minnesota. The milestones worth watching are a ruling on class certification in either track and any motion seeking preliminary approval of a settlement, since preliminary approval is the step that would, for the first time, create a real claim form and deadline. A jury verdict, if the case ever reached trial instead of settling, would be a different milestone entirely and would not by itself create a consumer claims process.
Until one of those events happens, there is nothing to file and no fund to claim from. This page reflects the docket as of the last-verified date shown above and will be updated if the litigation's posture changes.
Frequently Asked Questions
Is there a Change Healthcare data breach settlement I can file a claim for?
No. As of July 2026, there is no Change Healthcare data breach settlement, no settlement fund, and no claim form. The litigation is still in the pretrial stage in federal court.
Why hasn't the Change Healthcare lawsuit settled yet?
The case, MDL No. 3108, only reached consolidated master complaints in July 2025, and no class has been certified in either litigation track. Settlements in large data breach MDLs typically follow class certification, they don't precede it.
I received a breach notice from Change Healthcare. Do I need to sign up for the lawsuit?
No. There is nothing to sign up for right now. If you fall within the Patient Actions or Provider Actions track and a settlement is later reached, notice and a claims process would go out to the class automatically.
A website is asking me to enter my Social Security number to claim my Change Healthcare settlement payout. Is that legitimate?
No. Since no Change Healthcare settlement or claims process exists as of July 2026, any site collecting personal, insurance, or payment information under that name is a scam vector, not an official claims portal.
What is MDL No. 3108?
MDL No. 3108 is the federal multidistrict litigation number assigned to the consolidated Change Healthcare data breach lawsuits, case 0:24-md-03108 (DWF/DJF), overseen by Judge Donovan W. Frank and Magistrate Judge Dulce J. Foster in the U.S. District Court for the District of Minnesota.
What is the difference between the Provider Actions and Patient Actions tracks?
The Provider Actions track covers health care providers and practices that used Change Healthcare's systems to process claims. The Patient Actions track covers individual patients and health plan members whose personal or health information was exposed.
Will a credit freeze protect me after the Change Healthcare breach?
A credit freeze protects against new accounts being opened in your name, but it does not catch medical identity theft. Review your health plan's explanation of benefits statements for care you did not receive, since that is usually where medical identity theft surfaces first.
When will there be a Change Healthcare settlement?
There is no announced timeline. This page tracks the docket in MDL No. 3108 and will be updated if a settlement or claims process is announced; no date can be predicted from the current case posture.
How can I check for updates on the Change Healthcare litigation myself?
The U.S. District Court for the District of Minnesota maintains a public case page for MDL No. 3108 with filed orders and scheduling notices, which is the most reliable way to track the case's progress.
How to tell a settlement notice is real
Check the case name, case number, and court against the official settlement site. Go to that site directly instead of clicking a link in an email or text. Nobody legitimate will call, text, or email out of the blue asking for your Social Security number, bank account, or card details, and nobody will charge you to file. Report anyone who does at ReportFraud.ftc.gov.
Informational only. Not legal, tax, or financial advice, and not affiliated with any settlement.
RecordingLaw.com is an independent legal-information publisher. We are not a law firm, not a settlement administrator, and not affiliated with, endorsed by, or acting on behalf of any court, government agency, defendant, or claims administrator described on this page. Reading this page does not create an attorney-client relationship.
We do not process claims and we never collect your claim information. You cannot file a claim on RecordingLaw.com. To file, opt out, object, or check your status, use only the official settlement administrator identified above. We link to it for your convenience.
Filing a legitimate claim is free. No legitimate settlement or administrator will charge you a fee to file, or ask for your Social Security number, bank, or card details by unsolicited call, text, or email. If someone does, it is likely a scam. Report it at ReportFraud.ftc.gov.
Deadlines, amounts, and approval status change and are set by the court. We verify against the official administrator and court records, but confirm the current details on the official site before acting. Nothing here guarantees eligibility, a payment, or any amount. Settlement payments may be taxable. See IRS Publication 4345. and consult a tax professional. For advice about your specific situation, consult a licensed attorney in your state. Affiliate disclosure.
Sources and References
- HHS Office for Civil Rights - Change Healthcare Cybersecurity Incident FAQ(hhs.gov).gov
- U.S. District Court, District of Minnesota - MDL No. 3108 case page(mnd.uscourts.gov).gov
- HHS Office for Civil Rights - Breach Portal (HIPAA breach notification database)(hhs.gov).gov
- IdentityTheft.gov - Federal Trade Commission identity theft recovery(identitytheft.gov).gov
- Federal Trade Commission - Credit Freezes and Fraud Alerts(consumer.ftc.gov).gov