UNITEDHEALTH GROUP INCORPORATED
ent_019dd1709e698ffb3a415fbbe3d531be
Disclosures
25+
SEC 8-K · Leak Site · SEC 10-K Item 1C · State AG · HHS OCR · 6 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
20,536
nationwide · HHS OCR MN
Leak-site claims
4
unverified actor claims
Identity resolution
- Canonical name
- UNITEDHEALTH GROUP INCORPORATED
- Normalized
- unitedhealth group— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300GHBMY8T5GXDE41
- SEC EDGAR CIK
- 0000731766
- Domain
- unitedhealthgroup.com
Disclosure history (newest 25)newest first
- FEDERALSEC 8-Kas reporting2024-04-24
UnitedHealth Group filed 8-K/A Amendment No. 2 updating prior disclosures about the Change Healthcare cyberattack. The amendment incorporates an April 22, 2024 press release describing ongoing data assessment, support for impacted individuals, provider/customer notifications, and Change Healthcare service restoration progress. The underlying incident is the previously disclosed cyberattack on UnitedHealth Group subsidiary Change Healthcare.
- GLOBALLeak Siteas victim2024-04-16
Visits: 9992 Data Size: 4TB Published: False
- GLOBALLeak Siteas victim2024-04-08
Visits: 38 Data Size: 4TB Published: False
- FEDERALSEC 8-Kas reporting2024-03-08
UnitedHealth Group filed an Amendment No. 1 to its February 22, 2024 Form 8-K disclosing that cybercrime threat actors had gained access to certain Change Healthcare IT systems. The Company isolated the impacted systems, notified customers, law enforcement and government agencies, and is investigating the extent of impacted data. The Company believes the issue is specific to Change Healthcare; all other systems remain operational. As of the amendment date, no material impact on financial condition or results of operations had been determined.
- GLOBALLeak Siteas victim2024-02-28
- FEDERALSEC 10-K Item 1Cas victim2024-02-28
UnitedHealth Group's FY2023 10-K Item 1C briefly notes a cybersecurity incident disclosed on February 22, 2024, believed to have been committed by cybercrime threat actors. The company states the investigation is ongoing and that, as of the report date, it has not determined the incident is reasonably likely to materially impact its financial condition or results of operations. No technical details, affected individual count, data types, or attack vector are disclosed in this filing.
- FEDERALSEC 8-Kas reporting2024-02-22
On February 21, 2024, UnitedHealth Group identified a suspected nation-state cyber threat actor that had gained access to certain Change Healthcare IT systems. The Company isolated the impacted systems, retained security experts, engaged law enforcement, and notified customers and government agencies. As of the filing, UnitedHealth had not determined the incident reasonably likely to materially impact financial condition or results of operations.
- GLOBALLeak Siteas victim2023-06-14
- Illinois State AGas reporting2022-01-01
UNITED HEALTH GROUP filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-087). The register records the breach as discovered on May 5, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas reporting2022-01-01
UNITED HEALTH GROUP filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-088). The register records the breach as discovered on August 16, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- MINNESOTAHHS OCRas victim2021-07-30
UnitedHealth Group Single Affiliated Covered Entity reported to HHS on 2021-07-30 a Unauthorized Access/Disclosure affecting 774 individuals. Breached information located on Network Server. A coding error caused PHI, including names and Social Security numbers, to appear on the patient portal. The entity provided complimentary credit monitoring and implemented additional safeguards.
- MINNESOTAHHS OCRas victim2020-02-04
UnitedHealth Group Health Plan Single Affiliated Covered Entity reported to HHS on 2020-02-04 a Hacking/IT Incident at a business associate affecting 3335 individuals. The compromised protected health information included names, treatment information, and claims and financial information from a network server. In response, the entity offered complimentary credit monitoring and implemented additional safeguards.
- MINNESOTAHHS OCRas victim2020-01-22
UnitedHealth Group Health Plan Single Affiliated Covered Entity reported to HHS on 2020-01-22 an Unauthorized Access/Disclosure affecting 934 individuals. Breached information located on Paper/Films. An employee inadvertently sent mail containing PHI (names, DOBs) to a plan member. CE provided credit monitoring and implemented administrative safeguards.
- MINNESOTAHHS OCRas victim2019-05-08
UnitedHealth Group Health Plan Single Affiliated Covered Entity reported to HHS on 2019-05-08 a Unauthorized Access/Disclosure affecting 20536 individuals. Breached information located on Network Server. The entity mistakenly filed the report regarding an incident at another CE; the case was closed without investigation.
- MINNESOTAHHS OCRas victim2018-04-10
UnitedHealth Group reported to HHS on 2018-04-10 a Unauthorized Access/Disclosure affecting 896 individuals. Breached information located on Paper/Films. An employee of a business associate mistakenly mailed PHI to wrong recipients.
- MINNESOTAHHS OCRas victim2018-03-15
UnitedHealth Group reported to HHS on 2018-03-15 a Unauthorized Access/Disclosure affecting 1755 individuals. Breached information located on Paper/Films. Enrollment packages containing PHI were incorrectly mailed to wrong recipients.
- MINNESOTAHHS OCRas reporting2016-11-22
United Health Group Single Affiliated Covered Entity reported to HHS on 2016-11-22 a Hacking/IT Incident affecting 1408 individuals. Breached information located on Network Server. The ePHI involved included names, addresses, and claims and health insurance information. The CE implemented additional administrative, technical, and security safeguards.
- MINNESOTAHHS OCRas victim2016-05-04
United Health Group reported that members of its Louisiana Medicaid Plan had their names incorrectly matched with the wrong addresses, which resulted in letters containing protected health information being mailed to incorrect recipients. This breach affected approximately 5,330 individuals and involved their names, treatment information, and claims information.
- Massachusetts State AGas victim2012-09-26
UnitedHealth Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-09-26. 5 Massachusetts residents were affected. The report records the breach type as paper.
- MINNESOTAHHS OCRas victim2012-05-18
UnitedHealth Group health plan single affiliated covered entity (MN) reported to HHS OCR on 2012-05-18 an Unauthorized Access/Disclosure incident affecting 19,100 individuals. Breached information was located on Other media. No business associate was present. No further description was provided.
- Massachusetts State AGas victim2012-04-01
UnitedHealth Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-04-01. 34 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2012-03-30
UnitedHealthcare discovered unauthorized employee access to a database containing personal information, including names, SSNs, and Medicare numbers, for the period June 28 to December 12, 2011. The incident was detected on January 30, 2012. Law enforcement was notified, and affected individuals were offered one year of credit monitoring. The company is reinforcing employee policies and evaluating additional safeguards.
- MINNESOTAHHS OCRas victim2012-02-01
UnitedHealth Group health plan single affiliated covered entity reported to HHS on 2012-02-01 a breach of type 'Other' affecting 6678 individuals. Breached information located on Paper/Films.
- MINNESOTAHHS OCRas victim2010-06-04
UnitedHealth Group (Health Plan, MN) reported to HHS OCR on 2010-06-04 a breach of type 'Other' affecting 16,291 individuals. Paper correspondence for members in UnitedHealth's prescription drug plans was inadvertently sent to incorrect temporary addresses due to a database administration error involving a third-party vendor (PDI) proprietary address database. Exposed data included member name, plan number, and in some cases date of birth and/or limited medical information. Breached information located on Paper/Films. UnitedHealth stopped using PDI's database and revised its address update process.
- MINNESOTAHHS OCRas victim2010-04-27
UnitedHealth Group reported to HHS on 2010-04-27 a Theft affecting 735 individuals. Breached information located on Other, Paper/Films. Remittance forms containing PHI were stolen.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of UNITEDHEALTH GROUP INCORPORATED — not by UNITEDHEALTH GROUP INCORPORATED itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Massachusetts State AGvia UNITEDHEALTHCARE INSURANCE COMPANY2026-08-01
United Language Group, LLC, a third-party vendor for UnitedHealthcare, detected unauthorized access to its network on July 9, 2025. An attacker accessed data between July 8-9, 2025. Affected data included PHI, PII, government IDs, and limited financial account info. One Rhode Island resident was notified. ULC engaged forensic investigators and is offering 24 months of credit monitoring.
- CONNECTICUTHHS OCRvia United HealthCare Services, Inc.2026-06-19
UnitedHealth Care Services, Inc. Single Affiliated Covered Entity reported to HHS on 2026-06-19 a Hacking/IT Incident affecting 37384 individuals. Breached information located on Email. Business associate was present.
- CONNECTICUTHHS OCRvia United HealthCare Services, Inc.2026-06-05
UnitedHealth Care Services, Inc. Single Affiliated Covered Entity reported to HHS on 2026-06-05 a Hacking/IT Incident affecting 34574 individuals. Breached information located on Network Server.
- CONNECTICUTHHS OCRvia UNITEDHEALTHCARE INSURANCE COMPANY2025-08-12
UnitedHealthcare reported to HHS on 2025-08-12 a Unauthorized Access/Disclosure affecting 3215 individuals. Breached information located on Paper/Films.
- Washington State AGvia United HealthCare Services, Inc.2025-06-27
MedicareCompareUSA notified the Washington AG of a phishing incident affecting United Healthcare policyholders. Unauthorized access to email accounts occurred Nov 5-21, 2024. Data exposed: names, SSNs, Medicare numbers, DOBs. 1,258 WA residents notified on June 27, 2025. Credit monitoring offered.
- Massachusetts State AGvia United HealthCare Services, Inc.2025-06-27
MedicareCompareUSA filing on behalf of United Healthcare reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-06-27. 1 Massachusetts residents were affected.
- Indiana State AGvia United HealthCare Services, Inc.2025-06-27
MedicareCompareUSA filing on behalf of United Healthcare reported a data breach to the Indiana Attorney General. The breach occurred on 2024-11-05 and was reported on 2025-06-27. 1 Indiana residents were affected. 2,537 individuals affected in total.
- Nebraska State AGvia United HealthCare Services, Inc.2025-06-27
MedicareCompareUSA reported a phishing incident affecting United Healthcare data. Unauthorized access occurred Nov 5-21, 2024, exposing names, SSNs, and health policy numbers. One Nebraska resident was notified on June 27, 2025. MCUSA provided credit monitoring and notified HHS.
- Massachusetts State AGvia UNITEDHEALTHCARE INSURANCE COMPANY2025-04-25
Unitedhealthcare ("UHC") reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-04-25. 220 Massachusetts residents were affected.
- Illinois State AGvia UNITEDHEALTHCARE INSURANCE COMPANY2025-02-01
UNITED HEALTHCARE INSURANCE COMPANY filed a data-breach notice with the Illinois Attorney General in February 2025 (case 25-02-125). The register records the breach as discovered on November 6, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.