Every federal MDL from the Judicial Panel's own reports · updated September 1, 2026Find your lawsuit →
Settlement Record

HomeLawsuitsChange Healthcare data breach lawsuit

Change Healthcare data breach lawsuit

Active MDLStatus as of September 3, 2026 · MDL No. 3108

Active MDL in pretrial discovery in the District of Minnesota; the court has ruled in part on motions to dismiss and ordered settlement talks, but no settlement has been announced as of September 2026. Lawsuits over the February 2024 ransomware attack on Change Healthcare, which UnitedHealth Group has said affected roughly 190 million people, are consolidated in an active federal MDL with no settlement reached as of September 2026.

The docket record

Actions pending
152+5(+3.4%)
Total actions, historical
167
Change, 3 months
+17(+12.6%)
Change, 12 months
+72(+90.0%)
Docket
MDL No. 3108
Court
District of Minnesota
Transferee judge
Donovan W. FrankSr. District Judge

Source: JPML “Pending MDL Dockets by Actions Pending,” report dated September 1, 2026 · first in our series Jul 2024

Actions pending in MDL 3108, by monthly JPML report050100150200Jan 2024Jul 2024Feb 2025Aug 2025Feb 2026Aug 2026Sep 2026
Actions pending on each monthly JPML report, Jan 2024 to Sep 2026. Gaps are months the report omitted the figure.

Month-by-month figures, Jan 2024 to Sep 2026

Report dateActions pendingChangeTotal, historicalReport
September 1, 2026152+5167PDF
August 3, 2026147+1162PDF
July 1, 2026146+11161PDF
June 1, 2026135+15149PDF
May 1, 2026120+18134PDF
April 1, 2026102+7114PDF
March 2, 202695+5107PDF
February 2, 2026900102PDF
January 5, 202690+4102PDF
December 2, 202586+198PDF
November 3, 202585+297PDF
October 1, 202583+395PDF
September 2, 202580+292PDF
August 1, 202578−189PDF
July 1, 202579+689PDF
June 2, 202573+183PDF
May 1, 202572+382PDF
April 1, 202569+479PDF
March 3, 202565−373PDF
February 3, 202568+370PDF
January 2, 202565+167PDF
December 2, 202464+466PDF
October 1, 202460+462PDF
September 3, 202456−258PDF
August 1, 202458+958PDF
July 1, 20244949PDF
June 3, 2024not listedPDF
May 1, 2024not listedPDF
April 1, 2024not listedPDF
March 1, 2024not listedPDF
February 1, 2024not listedPDF
January 2, 2024not listedPDF

Full docket title: IN RE: Change Healthcare, Inc., Customer Data Security Breach Litigation. Programmatic record page: MDL 3108.

Where it stands

The litigation over the February 2024 Change Healthcare ransomware attack is proceeding on two tracks, one for patients whose data was exposed and one for healthcare providers who allege the platform outage disrupted their claims and payments. Both tracks filed master (consolidated) complaints on July 7, 2025. On December 19, 2025, Judge Donovan W. Frank granted defendants' motions to dismiss in part and denied them in part as to both the patient and provider master complaints, meaning some claims were dismissed and others were allowed to proceed; the court's own case page does not detail which specific claims survived, so that should be confirmed against the order itself before citing specifics. A February 4, 2026 case management order (Pretrial Order No. 24) set an April 1, 2026 deadline for amended pleadings and a November 2, 2026 fact-discovery deadline. Magistrate Judge Dulce J. Foster has directed the parties to exchange mediator names and hold informal settlement conferences, but as of the court's most recent published update (August 26, 2026) no settlement agreement has been reached. The JPML's September 1, 2026 pending-MDL report lists 152 actions currently pending (167 total, including terminated actions) in MDL 3108.

Sources: MDL 3108 - Change Healthcare, Inc. Data Breach (case page) · MDL Cases · Pending MDL Dockets by District, September 1, 2026 · Breach Portal: Notice to the Secretary of HHS Breach of U…; full list at the end of this page.

What the lawsuits are about

Change Healthcare, a UnitedHealth Group company (operated through its Optum division) that processes medical claims and payments for a large share of U.S. healthcare providers, suffered a ransomware attack beginning February 21, 2024. The attack, attributed to a cybercrime group operating as ALPHV/BlackCat, forced Change Healthcare to take its systems offline, disrupting prescription processing, medical claims, and provider payments nationwide for weeks. UnitedHealth Group has said the incident compromised personal, financial, and protected health information; as reported by HHS's breach-notification process, the number of individuals notified has been put at roughly 190 million, among the largest healthcare data breaches on record. Plaintiffs, both patients whose information was exposed and healthcare providers who say the outage cost them revenue and drove up costs, allege the defendants failed to adequately secure their systems and data. These are allegations from plaintiffs' complaints, not proven facts.

As lawsuits were filed around the country, the Judicial Panel on Multidistrict Litigation centralized the federal cases into MDL No. 3108, IN RE: Change Healthcare, Inc., Customer Data Security Breach Litigation, assigning it to Judge Donovan W. Frank in the U.S. District Court for the District of Minnesota, with Magistrate Judge Dulce J. Foster handling pretrial discovery matters. The court organized the cases into a Patient Track and a Provider Track, each proceeding under its own master complaint, with Pretrial Order No. 1 (August 14, 2024) setting up preliminary procedures and temporary leadership counsel.

Both tracks' master complaints were filed July 7, 2025 (case numbers CV 25-179 for the provider track and CV 25-183 for the patient track). Defendants moved to dismiss; the court held a hearing on June 12, 2025, and ruled on December 19, 2025, granting the motions in part and denying them in part for both tracks. The case is now in fact discovery, due to close November 2, 2026, alongside informal settlement conferences ordered by the magistrate judge. As of the JPML's September 1, 2026 report, 152 actions remain pending. A separate insurance track was described as 'under consideration' as of an August 2026 status conference but had not been formally established as of this writing.

Injuries named in the filings

  • Exposure of protected health information and personal financial information in the ransomware attack, alleged by patient-track plaintiffs
  • Increased risk of identity theft and fraud, and costs of credit monitoring or identity-protection services, alleged by patient-track plaintiffs
  • Lost revenue, delayed claims payments, and increased operating costs from the platform outage, alleged by provider-track plaintiffs (healthcare providers)

Principal defendants: UnitedHealth Group Incorporated; Optum, Inc.; Change Healthcare, Inc..

Sources: MDL 3108 - Change Healthcare, Inc. Data Breach (case page) · MDL Cases · Pending MDL Dockets by District, September 1, 2026 · Breach Portal: Notice to the Secretary of HHS Breach of U…; full list at the end of this page.

Who the filings say qualifies

Illustration of a person seen from behind holding a phone showing a starburst ad, with a ruled checklist document on the table in front of them
Compare the ad to the filings' own criteria before you fill in anyone's form.

The court has organized MDL 3108 into two separate master complaints rather than a single certified class, so 'who qualifies' here describes who the litigation covers, not a settlement class definition (no settlement class has been defined as of September 2026). This is drawn from the District of Minnesota's own MDL case page describing the Patient Track and Provider Track structure.

  • Patient Track: individuals whose personal, financial, or health information was compromised in the February 2024 Change Healthcare data breach and who received (or should have received) a breach notification
  • Provider Track: healthcare providers or healthcare organizations that allege financial or operational harm from the disruption to Change Healthcare's claims-processing and payment systems
  • A pending case must be part of, or transferred into, MDL No. 3108 in the District of Minnesota to be covered by the master complaints and case management orders described here

Source: MDL 3108 case page, U.S. District Court, District of Minnesota.

These are the criteria in the public record, not a promise about any individual case. A law firm evaluates each case on its own facts, and limitations periods vary by state.

Want a case review for the Change Healthcare data breach?

Case reviews for this litigation are not open through this site yet. Leave your details and we will pass them to a participating firm or intake partner only if one accepts this litigation, and only with the consent below.

Key dates

  1. A ransomware attack, attributed to the ALPHV/BlackCat group, takes Change Healthcare's systems offline, disrupting medical claims and payment processing nationwide. source
  2. The JPML centralizes federal Change Healthcare data breach cases into MDL No. 3108, assigning the litigation to Judge Donovan W. Frank in the District of Minnesota. source
  3. Pretrial Order No. 1 is entered, establishing preliminary procedures and appointing temporary leadership counsel. source
  4. The Patient Track and Provider Track each file a master (consolidated) complaint. source
  5. Judge Frank rules on defendants' motions to dismiss, granting them in part and denying them in part as to both the patient and provider master complaints. source
  6. Pretrial Order No. 24 (case management order) sets an April 1, 2026 deadline for amended pleadings and a November 2, 2026 fact-discovery deadline. source
  7. The JPML's pending-MDL report lists 152 actions pending (167 total) in MDL 3108 before Judge Frank in the District of Minnesota. source

Questions people ask

Is the Change Healthcare data breach lawsuit still active?

Yes. As of September 2026, MDL No. 3108 is an active, consolidated federal litigation in the District of Minnesota, in fact discovery with a November 2, 2026 deadline. No settlement has been reached, though the court has ordered informal settlement conferences between the parties.

Was my data affected in the Change Healthcare breach?

UnitedHealth Group has said, and HHS's breach-notification process reflects, that roughly 190 million individuals were notified as part of this breach. If you received a written breach notification from Change Healthcare, UnitedHealth Group, or Optum, your information was likely part of the incident; the exact scope has not been independently verified for this page beyond that public reporting.

Has there been a settlement in the Change Healthcare data breach litigation?

No settlement had been announced as of the court's most recent published update (August 26, 2026). The magistrate judge has directed the parties to exchange mediator names and hold informal settlement discussions, but no settlement fund, class definition, or claims process exists yet. This page will be updated if that changes.

Who is suing UnitedHealth Group and Change Healthcare?

Two groups of plaintiffs are involved, consolidated into separate master complaints: patients whose personal and health information was exposed in the breach, and healthcare providers who allege the platform outage disrupted their claims processing and payments. Both tracks are part of MDL No. 3108 before Judge Donovan W. Frank in the District of Minnesota.

What did the court decide on the motion to dismiss?

On December 19, 2025, Judge Frank granted the defendants' motions to dismiss in part and denied them in part for both the patient-track and provider-track master complaints. That means some claims were dismissed and others were allowed to proceed to discovery; the published case summary this page relies on does not break out which specific claims survived, so anyone relying on that detail should check the underlying order.

What caused the Change Healthcare data breach?

A ransomware attack that began February 21, 2024, attributed to a cybercrime group operating under the name ALPHV/BlackCat, compromised Change Healthcare's systems and, according to public reporting, involved a multimillion-dollar ransom payment. Change Healthcare is a claims-processing subsidiary of UnitedHealth Group's Optum division.

Sources: MDL 3108 - Change Healthcare, Inc. Data Breach (case page) · MDL Cases · Pending MDL Dockets by District, September 1, 2026 · Breach Portal: Notice to the Secretary of HHS Breach of U…; full list at the end of this page.

Track this docket

We re-read the JPML report on the first business day of each month. Get an email when this record changes: case count, status, or a settlement development.

Sources

  1. U.S. Judicial Panel on Multidistrict Litigation, “Pending MDL Dockets by Actions Pending,” monthly reports July 1, 2024 to September 1, 2026. Transferee court: District of Minnesota, Donovan W. Frank.
  2. MDL 3108 - Change Healthcare, Inc. Data Breach (case page), U.S. District Court, District of Minnesota. Accessed September 3, 2026.
  3. MDL Cases, U.S. District Court, District of Minnesota. Accessed September 3, 2026.
  4. Pending MDL Dockets by District, September 1, 2026, Judicial Panel on Multidistrict Litigation. Accessed September 3, 2026.
  5. Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information, U.S. Department of Health and Human Services, Office for Civil Rights. Accessed September 3, 2026.
  6. Change Healthcare, Wikipedia. Accessed September 3, 2026.

Settlement Record is not a law firm and does not give legal advice. We may be compensated if you request a case review and are referred to a law firm or intake partner. Settlement Record is not affiliated with any court, agency, defendant or law firm named on this page.

Before you fill out anyone's form

Read the record before you read the ad.

Every lawsuit on this site is a docket the Judicial Panel publishes. Check the count, the status and who the filings cover, then decide who to talk to.

Free · public court data · no account.

Three things to check first

  1. Is the lawsuit real? Every federal MDL is on the Judicial Panel's monthly report. If a docket number is on our register, the litigation exists; if it settled or was dismissed, the record says so.

  2. Who do the filings say qualifies? The master complaint and the court's plaintiff fact sheet define the injuries and exposures at issue. We quote those, not an ad.

  3. Where is the official form? For settled class actions, the court-appointed administrator runs the claims. We link to it and never host a claim form ourselves.

Public court data, dated and sourced. Not a law firm, not legal advice.