If this impacted their software development, it could include source for current and older but still in use products, which could potentially be analyzed looking for potential exploits. It may include internal bug trackers that may include information on unpatched exploits or on exploits quietly patched only as part of updates and so potentially still in the wild. Heck, it may include some of their internal product security testing information and whatever might be in that.
An awful lot of large companies and healthcare systems now have Citrix portals available to the world rather than having annoying-to-manage-and-support VPN connections - are there undisclosed vulnerabilities in any of those?
Even going outside the technical side, if there's sensitive HR information they may have materials that can be leveraged for blackmail purposes to attempt to maintain long-term access.
And all of that is just talking about the Citrix remote access piece that I still think of when I hear the name. There's also XenApp/XenDesktop for virtualization, the ShareFile sharing site that others have mentioned, their endpoint management product, etc. There might even be holdover stuff - what would a copy of out-of-date source code to GoToMyPC be worth?
A lot will depend on the ability of whoever got it to capitalize on it, but assuming this was indeed a nation expect that they'll be able to spend at least some resources.