FEDERALItem 1.05 · mandatoryHackingHealthcareHealthcareLowActive
CHANGE HEALTHCARE INC.
bd_60972bcbcf823790 · schema v1 · pii pii-v1
Full breach record for CHANGE HEALTHCARE INC. →UnitedHealth Group filed an Amendment No. 1 to its February 22, 2024 Form 8-K disclosing that cybercrime threat actors had gained access to certain Change Healthcare IT systems. The Company isolated the impacted systems, notified customers, law enforcement and government agencies, and is investigating the extent of impacted data. The Company believes the issue is specific to Change Healthcare; all other systems remain operational. As of the amendment date, no material impact on financial condition or results of operations had been determined.
SEC clockMateriality determined Feb 21, 2024 → Filed Mar 8, 202416d ✗ SEC 4-day late
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_36e4f538febdd83aSEC 10-K Item 1Cfiled 2024-03-12(4d gap)Verified
- bd_ceefcf273bc5de75SEC 8-Kfiled 2024-03-14(6d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/731766/000073176624000085/unh-20240221.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 8, 2024
- Raw hash
- ea8c27e3c5472a541bfa6118346b342fabaf569dc0750ee44472a0417990ae01
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- UnitedHealth Group Incorporatednorm: unitedhealth group
- SEC CIK
- 0000731766
- Domain
- unitedhealthgroup.com
Victim entity
- Name
- CHANGE HEALTHCARE INC.norm: change healthcare
- Domain
- changehealthcare.com
- Industry
- Healthcarellm
Incident
- Discovered
- —
- Materiality determined
- Feb 21, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- —
- Attack vector
- Unauthorized Access
- Threat actor
- External
- Regulator citations
- Notified law enforcement and government agencies
Compliance
- Compliance flags
- SEC 4-day late · 16d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Feb 21, 2024→ Filed: Mar 8, 202416d cal. 4 business days SEC 4-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.