Qilin ransomware group posted 2.8 million UnitedHealth Group patient records on July 20 2026 and demanded 50 million dollars in Bitcoin. The stolen data includes names Social Security numbers and medical diagnoses. UnitedHealth stated the breach originated from a compromised VPN account on July 12.
The company isolated affected systems within 48 hours and notified the Department of Health and Human Services. Qilin previously targeted Change Healthcare in 2024. UnitedHealth has offered two years of credit monitoring to impacted individuals.
Federal investigators from CISA and FBI joined the response on July 18. The incident marks the largest healthcare breach since the 2024 Change Healthcare attack. UnitedHealth stock fell 7 percent on July 21.
Healthcare organizations increased cybersecurity spending by 45 percent in 2025 yet remain prime targets. Qilin uses double extortion tactics combining encryption with data leaks.
Why this matters
The breach highlights persistent vulnerabilities in legacy VPN infrastructure across critical infrastructure sectors. Regulators may impose new mandatory breach notification timelines within 24 hours. Insurance premiums for healthcare cyber coverage rose 60 percent in the past year.
UnitedHealth faces potential HIPAA fines exceeding 100 million dollars. The event accelerates adoption of zero-trust architectures in the sector.
CISA plans to release updated healthcare cybersecurity guidelines by September 2026.