Court Rules
All enforcement actions
Enforcement ActionLow RiskMultistate

CT AG Demands Action from Change Healthcare Over Massive Health Data Breach

Change HealthcareJuly 9, 2024Connecticut Attorney General

Summary

Connecticut Attorney General William Tong urged residents to enroll in free credit monitoring and identity theft protection following the Change Healthcare cyberattack in February 2024, which exposed sensitive health data. The breach potentially impacted up to one-third of Americans, but Change Healthcare has failed to provide individual notice to affected consumers. The AG joined other attorneys general in April 2024 to demand that UnitedHealth Group take more meaningful action to protect those harmed.

Contract Impact

In-house legal teams should immediately review all Business Associate Agreements (BAAs) under HIPAA and vendor contracts with Change Healthcare (or its parent UnitedHealth Group) where health data is processed, stored, or transmitted. Specific clauses to scrutinize include: data breach notification timelines and methods (given the failure to provide individual notice), indemnification provisions for breach-related liabilities, mandatory cybersecurity standards and incident response obligations, audit and oversight rights, and termination clauses for non-compliance. Contracts may need amendments to enforce stricter notification deadlines (e.g., within 72 hours), require provision of free credit monitoring for affected individuals, mandate enhanced security controls like encryption and multi-factor authentication, and clarify liability allocation for breaches involving protected health information.

Contract Search Terms

HIPAA business associate agreementdata breach notification clauseincident response planthird-party risk managementdata processing addendumconsumer notification requirementsindemnification clausecybersecurity requirementsaudit rightsdata retention schedule

Laws Cited

HIPAA

Violation Types

Entity Details

Entity

Change Healthcare

Industry

Healthcare

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"Change Healthcare, a unit of UnitedHealth, is the nation’s biggest electronic data clearinghouse."
Laws Cited
"Data breaches involving PHI are required to be reported to the U.S. Department of Health & Human Services - Office for Civil Rights (hhs.gov) by HIPAA-covered entities."
Violation Types
"The February cyberattack interrupted operations for thousands of doctors’ offices, hospitals, and pharmacies. It also resulted in Americans’ sensitive health and personal data being leaked onto the dark web - a hidden portion of the Internet where cyber criminals buy, sell, and track personal information."
Violation Types
"However, Change Healthcare has not yet provided individual notice to consumers."
Is Multistate
"In April, Attorney General Tong joined other attorneys general in sending a letter to UnitedHealth Group, Inc. — the nation's largest health insurer and the parent company of Change Healthcare — urging the corporation to take more meaningful action to better protect providers, pharmacies, and patients harmed by the recent breach."

Related Enforcement Actions

CT

MediaLab.AI Inc.

Connecticut Attorney General William Tong announced a civil investigative demand into MediaLab.AI Inc., owner of the Kik Messenger app, over lax age assurance practices, content moderation, and child safety failures that advocates have dubbed a "predator's paradise." The action follows a July 2025 notice of violation under the Connecticut Data Privacy Act for privacy notice deficiencies and processing sensitive data — including health, biometric, and precise geolocation data — without proper consent, which the company has only partially addressed. The new investigation seeks records related to practices that may constitute unfair or deceptive acts or practices under the CTDPA and the Connecticut Unfair Trade Practices Act. No fine has been imposed to date.

CT

Hyperliquid

Attorney General William Tong issued a consumer alert warning Connecticut residents about unregulated, offshore decentralized finance (DeFi) cryptocurrency exchanges, naming GMX, Gains Network, dYdX, Aevo, Drift Protocol, Vertex Protocol, and Hyperliquid. The alert highlights risks including bypassing U.S. law via VPNs, predatory leverage up to 250x, misleading synthetic asset products, and lack of KYC protections. No enforcement action or penalty was imposed; at least one Connecticut consumer reportedly lost $200,000 deposited with an unregulated DeFi exchange.

CT

Zillow Group, Inc. and Redfin Corporation

$2.0M

Attorney General Tong and a coalition of four other states and the FTC sued Zillow and Redfin after Zillow paid Redfin $100 million to shut down its multifamily rental advertising business and transfer clients to Zillow. The settlement requires the companies to restore competition, with Redfin rebuilding its apartment advertising business, and pay $2 million to the coalition.

CT

Anthem, ConnectiCare, and UnitedHealthcare

Attorney General William Tong sent a letter to the Connecticut Insurance Department urging rejection of double-digit rate increases sought by Anthem, ConnectiCare, and UnitedHealthcare for individual and small group health insurance plans covering about 220,000 people. The letter argues the rates exceed inflationary measures and criticizes the carriers for failing to control costs and for poor claims system management, particularly ConnectiCare's transition to Molina Healthcare.

CT

TaxAct

$275K

Connecticut Attorney General William Tong announced a $275,000 settlement with TaxAct, an online tax preparation company, over allegations that between January 2018 and December 2022, TaxAct improperly disclosed detailed customer financial information to Meta and Google through third-party tracking technologies without notifying taxpayers. The settlement requires TaxAct to pay $275,000 and implement new third-party tracking compliance measures, including a review committee, written policies, a tag monitoring system, and two independent third-party audits.

CT

Manchester City Nissan

$4.0M

Connecticut Attorney General William Tong and the Federal Trade Commission announced a $4 million settlement with Manchester City Nissan (Chase Nissan LLC) resolving allegations that the dealership double-charged for 'certified pre-owned' vehicles and collected unauthorized junk fees. The settlement requires payment for consumer redress, prohibits misrepresentations, mandates clear disclosure of the maximum total price, and requires express informed consent for all charges.