FEDERALItem 7.01 · voluntary (Reg FD)HackingSupply Chain (3P Vendor)Data ExfiltratedPIIFINANCIAL_ACCOUNTLowActive
CHANGE HEALTHCARE INC.
bd_ceefcf273bc5de75 · schema v1 · pii pii-v1
Full breach record for CHANGE HEALTHCARE INC. →Option Care Health, Inc. filed an 8-K disclosing that Change Healthcare, a subsidiary of UnitedHealth Group, experienced a cybersecurity incident on February 21, 2024. Option Care Health disconnected from Change Healthcare's systems on that date and has not identified any compromise of its own systems. The incident caused operational disruptions, preventing the processing of over half of the Company's claims, impacting cash flow and patient care operations.
SEC clockMateriality determined Mar 14, 2024 → Filed Mar 14, 20240d ✓ SEC 4-day OK
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_36e4f538febdd83aSEC 10-K Item 1Cfiled 2024-03-12(2d gap)Verified
- bd_60972bcbcf823790SEC 8-Kfiled 2024-03-08(6d gap)Candidate
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1014739/000101473924000013/bios-20240314.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 14, 2024
- Raw hash
- 797991bd944ebc1bb5d5f66da93bbd24cdc31dbe4684ef6180240d3afd3017ca
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- OPTION CARE HEALTH, INC.norm: option care health
- SEC CIK
- 0001014739
- Domain
- optioncare.com
Victim entity
- Name
- CHANGE HEALTHCARE INC.norm: change healthcare
- Domain
- changehealthcare.com
Incident
- Discovered
- —
- Materiality determined
- Mar 14, 2024
- Notification sent
- Mar 14, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Change Healthcare
- Initial access
- supply_chain
Compliance
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Mar 14, 2024→ Filed: Mar 14, 20240d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.