On Wednesday, May 1, Andrew Witty, the chief executive of UnitedHealth Group, sat in front of the Senate Finance Committee in the morning and the House Energy and Commerce oversight subcommittee in the afternoon to answer for the Change Healthcare attack. If your practice submits claims through Change, or through a clearinghouse that routes to Change, you have been living with the consequences since February 21. The hearings did not fix anything. They did tell us a few things worth knowing, and they put some numbers on the record that had been rumors.
A practice manager we spoke with this week put it plainly: her claims are flowing again, her deposits still look strange, and nobody has told her what happens to the advance she took from the payer. That is where most independent practices are right now. The plumbing is mostly repaired. The paperwork is not. So let's cover what was said, and then what to actually do with the rest of May.
Key takeaways
- Witty confirmed the entry point was a Citrix remote access portal without multifactor authentication, that a ransom of about $22 million was paid, and that the stolen data may cover roughly a third of Americans.
- Any payer that used Change to receive claims or send remittances was affected, not only UnitedHealthcare, so the reconciliation covers every payer in your mix.
- The cleanup is four jobs: encounter-to-acknowledgment reconciliation from February 21, unapplied deposits matched to remittances, CO-18 duplicates reviewed, and advance repayment terms put in the cash forecast.
- Breach notification is not your job yet. Record when you learned your data may be involved and wait for OCR's guidance on delegation.
- The one security lesson that applies to a small practice is the one the senators kept repeating: a second factor on every remote login.
What the testimony confirmed
Four points came out of the hearings that matter for billing operations. First, the attackers used compromised credentials on February 12 to log into a Citrix remote access portal that did not have multifactor authentication turned on, moved through the network for nine days, and deployed ransomware on February 21. Witty acknowledged the missing second factor directly under questioning, and he said the Change systems were older technology that had not yet been brought up to UnitedHealth's standards since the 2022 acquisition. Second, UnitedHealth paid a ransom, which Witty confirmed as roughly $22 million, and he said the decision was his. Third, the company's current estimate is that the stolen data could cover about a third of people in the United States. The exact scope is not known yet, the file review will take months, and notification letters have not gone out. Fourth, UnitedHealth said its temporary funding assistance program and related advances had put more than $6.5 billion into providers' hands.
Witty also described the recovery. Pharmacy processing came back in early March, the main claims network in mid to late March, and payment and remittance functions in stages after that. Senators from both parties asked why a company of that size had a front door with no second lock, and nobody had a good answer. We think the honest summary for a practice is this: the network you depend on is back, the organization that runs it is going to be under scrutiny for a long time, and neither of those facts closes a single open claim in your system.
Who this affects
Not only UnitedHealthcare claims. Change Healthcare is a clearinghouse and payment network, so any payer that used Change to receive claims or send remittances was affected, regardless of who your contract is with. Practices that never heard of Change before February discovered that their practice management vendor routed everything through it. Medicare claims that went through a clearinghouse connected to Change were held up alongside commercial claims, and some Medicaid managed care plans received nothing for weeks.
If you switched to a different clearinghouse in March, you now have two channels to reconcile, and the second channel has its own enrollment records for electronic remittance advice (ERA) and electronic funds transfer (EFT). In our experience the practices in the worst shape today are the ones that switched in a hurry, got claims moving, and never went back to see what happened to the ones sent through Change in the last week before the outage.
Four cleanup jobs to finish this month
1. Reconcile every date of service from February 21 forward
Pull a report of all encounters from February 21 through the date your submissions resumed, and check each one for a payer acknowledgment (a 277CA accepted status) and an adjudication (an 835 remittance or a portal record). Claims that were sent into Change in the last days before the outage may show as "submitted" in your system and never arrived anywhere. Those need to be resubmitted, and for some payers they are already close to a 90-day timely filing limit. Many payers announced timely filing relief, but the terms differ, so record the payer's written policy next to each resubmission. A claim filed late without the relief documented is a CO-29 denial that will not be overturned.
2. Find the missing remittances
Some payers paid during the outage but could not deliver the 835 file. Money arrived in the bank and sits unapplied, while the claim continues to age. Compare bank deposits from March and April with posted payments. For every deposit without a remittance, request the ERA or a paper remit from the payer, or pull it from the payer portal. Do not let staff post from the bank statement without line detail; that creates credit balances you will chase for a year.
3. Watch for duplicates
If you resubmitted claims through a new clearinghouse in March, some of the originals eventually made it through Change when it came back. The result is duplicate denials (CO-18) that look alarming and mean nothing, and, less often, duplicate payments that you will need to refund. Sort the CO-18 denials by date of service and confirm the original was paid before closing them. A duplicate payment from Medicare has a 60-day refund clock once you have identified it, so do not leave those in a pile.
4. Know the terms of any advance you took
The UnitedHealth temporary funding program and the CMS accelerated and advance payments for providers and suppliers affected by the outage both have repayment terms, and they are not the same. Get the written terms, put the expected recoupment start date in your cash forecast, and make sure whoever reconciles deposits knows that a smaller check in a future month may be a recoupment rather than an underpayment. This is the part everyone skips, and it produces a panic in the fall when Medicare remittances suddenly show large offsets.
A worked example: one payer, one week
Here is how the reconciliation looks in practice for a fictional three-provider internal medicine group and one commercial payer. The group pulls every encounter for that payer with dates of service February 19 through March 22, the day claims resumed through the new clearinghouse: 312 encounters, $58,400 in charges. It then matches each encounter to three things: a 277CA acknowledgment, an 835 line, and a posted payment.
| Bucket | Encounters | Charges | Action |
|---|---|---|---|
| Acknowledged, adjudicated, posted | 219 | $41,100 | None |
| Submitted to Change Feb 19 to 21, no acknowledgment | 41 | $7,700 | Resubmit with the payer's relief policy on file |
| Paid per portal, no 835 received, deposit unapplied | 28 | $5,200 | Request ERA, post from line detail |
| Denied CO-18 after resubmission | 19 | $3,600 | Confirm original paid; close |
| Denied CO-29, filed after limit, relief not cited | 5 | $800 | Appeal with the payer's published relief notice |
The point of the table is the second row. Forty-one encounters, about 13% of the period, simply vanished, and no report in the practice management system flagged them because the system believed they had been sent. Multiply that across every payer and you understand why practices are still finding money in May. In our experience the vanished bucket is the largest recoverable dollar figure in the whole cleanup and the one least likely to be worked, because it never appears on a denial report.
What the hearing means for your own security
The missing multifactor authentication was the detail that senators kept coming back to. It is also the detail most relevant to a small practice. Every remote access path into your EHR, practice management system, clearinghouse portal and email should require a second factor. If your billing company or IT vendor logs in remotely, ask them, in writing, how. Ask the same about the remote desktop tool your EHR vendor uses for support. A practice cannot control a national clearinghouse, but it can control its own front door, and the HIPAA security risk analysis you are already required to keep is the place to write down that you checked.
The other lesson is about dependency. Most practices learned in February that they had one path to every payer and no idea what it was. Write down, this month, which clearinghouse each payer connection uses, whether your practice management vendor could route through a second one, and how long enrollment for a backup would take. That inventory is a one-page document and it is worth more than any vendor's assurance.
| Item | Owner | Done by |
|---|---|---|
| Encounter-to-acknowledgment reconciliation, Feb 21 to resumption date | Billing lead | May 15 |
| Unapplied deposits matched to remittances | Payment poster | May 20 |
| CO-18 duplicate denials reviewed and closed | Denials staff | May 24 |
| Timely filing relief policies documented per payer | Billing lead | May 10 |
| Advance repayment terms in the cash forecast | Practice manager | May 10 |
| Multifactor authentication confirmed on every remote login | IT vendor | May 31 |
| Clearinghouse dependency inventory written | Practice manager | May 31 |
Questions we hear
Should we go back to Change now that it is restored?
If your new clearinghouse is working, we would not rush. Switching twice in one year doubles the enrollment paperwork for ERAs and EFTs, and every switch produces a month of unapplied cash. Decide in the third quarter with two months of clean data from the new connection in hand. If the new connection is dropping claims or missing payers, that is a different conversation, and it should happen now.
Do we have to notify our patients about the breach?
Not yet, and possibly not you. UnitedHealth has said it will offer to handle notifications on behalf of affected providers, and the Office for Civil Rights has been asked to clarify how that works under HIPAA. Watch for that guidance before you send anything, and keep a record of the date you first learned your data may have been involved, because HIPAA timelines run from discovery.
Our AR over 90 days jumped in March. Will payers hold that against us?
No payer tracks your aging. What matters is whether the claims were filed on time under the relief each payer offered. Document the relief and file the claims. If the volume is more than your team can work, our denial management team handles exactly this kind of backlog, and an RCM audit of the February to April window will show you what is still recoverable and what is gone.
What to do this month
- Run the encounter report for February 19 through your resumption date and sort every line into the five buckets in the table above, payer by payer.
- Collect each payer's written timely filing relief notice and attach it to the resubmission batch it covers.
- Match every March and April deposit to an 835 or a portal remittance; post nothing from a bank statement alone.
- Get the repayment terms for any advance in writing and put the recoupment dates in the cash forecast.
- Confirm multifactor authentication on every remote login, including vendors, and note the check in your security risk analysis.
- Write the one-page clearinghouse dependency inventory and put the decision about staying or switching on the September agenda.
