UnitedHealth Group Incorporated
ent_019dd1709e698ffb3a415fbbe3d531be
Disclosures
15
SEC 10-K Item 1C · SEC 8-K · Leak Site · HHS OCR · State AG · 4 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
20,536
nationwide · HHS OCR MN
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- UnitedHealth Group Incorporated
- Normalized
- unitedhealth group— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300GHBMY8T5GXDE41
- SEC EDGAR CIK
- 0000731766
- Domain
- unitedhealthgroup.com
Disclosure history (15)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-03-02
UnitedHealth Group (UNH) filed its 10-K Item 1C disclosing no material cybersecurity risks as of Dec 31, 2025. The filing details a comprehensive cybersecurity program aligned with NIST, including risk assessments, incident response, third-party risk management, and board oversight by the Audit and Finance Committee. No specific breaches or incidents were reported.
- FEDERALSEC 8-Kas reporting2024-04-24
UnitedHealth Group filed 8-K/A Amendment No. 2 updating prior disclosures about the Change Healthcare cyberattack. The amendment incorporates an April 22, 2024 press release describing ongoing data assessment, support for impacted individuals, provider/customer notifications, and Change Healthcare service restoration progress. The underlying incident is the previously disclosed cyberattack on UnitedHealth Group subsidiary Change Healthcare.
- FEDERALSEC 8-Kas reporting2024-03-08
UnitedHealth Group filed an Amendment No. 1 to its February 22, 2024 Form 8-K disclosing that cybercrime threat actors had gained access to certain Change Healthcare IT systems. The Company isolated the impacted systems, notified customers, law enforcement and government agencies, and is investigating the extent of impacted data. The Company believes the issue is specific to Change Healthcare; all other systems remain operational. As of the amendment date, no material impact on financial condition or results of operations had been determined.
- FEDERALSEC 10-K Item 1Cas victim2024-02-28
UnitedHealth Group's FY2023 10-K Item 1C briefly notes a cybersecurity incident disclosed on February 22, 2024, believed to have been committed by cybercrime threat actors. The company states the investigation is ongoing and that, as of the report date, it has not determined the incident is reasonably likely to materially impact its financial condition or results of operations. No technical details, affected individual count, data types, or attack vector are disclosed in this filing.
- FEDERALSEC 8-Kas reporting2024-02-22
On February 21, 2024, UnitedHealth Group identified a suspected nation-state cyber threat actor that had gained access to certain Change Healthcare IT systems. The Company isolated the impacted systems, retained security experts, engaged law enforcement, and notified customers and government agencies. As of the filing, UnitedHealth had not determined the incident reasonably likely to materially impact financial condition or results of operations.
- GLOBALLeak Siteas victim2023-06-14
- MNHHS OCRas victim2021-07-30
UnitedHealth Group Single Affiliated Covered Entity reported to HHS on 2021-07-30 a Unauthorized Access/Disclosure affecting 774 individuals. Breached information located on Network Server. A coding error caused PHI, including names and Social Security numbers, to appear on the patient portal. The entity provided complimentary credit monitoring and implemented additional safeguards.
- FEDERALHHS OCRas victim2020-02-04
UnitedHealth Group Health Plan Single Affiliated Covered Entity reported to HHS on 2020-02-04 a Hacking/IT Incident at a business associate affecting 3335 individuals. The compromised protected health information included names, treatment information, and claims and financial information from a network server. In response, the entity offered complimentary credit monitoring and implemented additional safeguards.
- MNHHS OCRas victim2019-05-08
UnitedHealth Group Health Plan Single Affiliated Covered Entity reported to HHS on 2019-05-08 a Unauthorized Access/Disclosure affecting 20536 individuals. Breached information located on Network Server. The entity mistakenly filed the report regarding an incident at another CE; the case was closed without investigation.
- MNHHS OCRas victim2016-11-22
United Health Group Single Affiliated Covered Entity reported to HHS on 2016-11-22 a Hacking/IT Incident affecting 1408 individuals. Breached information located on Network Server. The ePHI involved included names, addresses, and claims and health insurance information. The CE implemented additional administrative, technical, and security safeguards.
- FEDERALHHS OCRas victim2016-05-04
United Health Group reported that members of its Louisiana Medicaid Plan had their names incorrectly matched with the wrong addresses, which resulted in letters containing protected health information being mailed to incorrect recipients. This breach affected approximately 5,330 individuals and involved their names, treatment information, and claims information.
- MNHHS OCRas victim2012-05-18
UnitedHealth Group health plan single affiliated covered entity (MN) reported to HHS OCR on 2012-05-18 an Unauthorized Access/Disclosure incident affecting 19,100 individuals. Breached information was located on Other media. No business associate was present. No further description was provided.
- 🐻California State AGas victim2012-03-30
UnitedHealth Group health plan single affiliated covered entity experienced unauthorized internal access to a database between June 28 and December 12, 2011. Discovered on January 30, 2012, the incident exposed member PII (name, SSN, DOB, address, Medicare ID). The company investigated, reported to law enforcement, and offered one year of Equifax credit monitoring. Remediation included reinforcing employee policies and evaluating additional safeguards.
- MNHHS OCRas victim2012-02-01
UnitedHealth Group health plan single affiliated covered entity reported to HHS on 2012-02-01 a breach of type 'Other' affecting 6678 individuals. Breached information located on Paper/Films.
- MNHHS OCRas victim2010-06-04
UnitedHealth Group (Health Plan, MN) reported to HHS OCR on 2010-06-04 a breach of type 'Other' affecting 16,291 individuals. Paper correspondence for members in UnitedHealth's prescription drug plans was inadvertently sent to incorrect temporary addresses due to a database administration error involving a third-party vendor (PDI) proprietary address database. Exposed data included member name, plan number, and in some cases date of birth and/or limited medical information. Breached information located on Paper/Films. UnitedHealth stopped using PDI's database and revised its address update process.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of UnitedHealth Group Incorporated — not by UnitedHealth Group Incorporated itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- CTHHS OCRvia UNITEDHEALTHCARE INSURANCE COMPANY2025-08-12
UnitedHealthcare reported to HHS on 2025-08-12 a Unauthorized Access/Disclosure affecting 3215 individuals. Breached information located on Paper/Films.
- 🏎️Indiana State AGvia UNITEDHEALTHCARE INSURANCE COMPANY2024-08-07
UnitedHealthcare reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-14 and was reported on 2024-08-07. 2 Indiana residents were affected. 1,178 individuals affected in total.
- CTHHS OCRvia UNITEDHEALTHCARE INSURANCE COMPANY2024-05-01
UnitedHealthcare Insurance Company reported to HHS on 2024-05-01 an Unauthorized Access/Disclosure affecting 16,665 individuals. An employee of the covered entity's business associate mailed PHI of 16,665 individuals to the wrong recipients. Breached information was located in Paper/Films. The CE notified HHS, affected individuals, and media. The CE and BA implemented additional administrative, technical, and security safeguards, and staff were retrained.
- 💎Delaware State AGvia UNITEDHEALTHCARE INSURANCE COMPANY2023-12-22
Welltok, Inc. notified UnitedHealthcare members in Delaware of a data breach involving the exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer tool. The incident occurred between May 30-31, 2023, resulting in the exfiltration of member data including names, addresses, Member IDs, DOBs, and Medicaid IDs. Welltok engaged third-party forensic specialists and is offering 24 months of credit monitoring via Experian.
- 🦬Montana State AGvia UNITEDHEALTHCARE INSURANCE COMPANY2023-12-08
UnitedHealthcare reported a data breach to the Montana Attorney General. The breach was reported on 2023-12-08. The breach occurred from 4/11/2023 to 4/12/2023. 3 Montana residents were affected.
- 🐻California State AGvia UNITEDHEALTHCARE INSURANCE COMPANY2023-08-31
UnitedHealthcare discovered unauthorized access to its broker portal on December 29, 2022. The incident occurred between December 1, 2022, and January 25, 2023. An unauthorized party accessed member health information, including names, member IDs, and plan details, while attempting to divert funds. Social Security numbers and financial account information were not involved. UnitedHealthcare disabled affected accounts and implemented additional security controls.
- 🦫Oregon State AGvia UNITEDHEALTHCARE INSURANCE COMPANY2023-08-31
UnitedHealthcare reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-31. The breach occurred during 1/1/0001. The breach was discovered on 12/29/2022. 315,915 individuals were affected. Notice was sent on 1/1/0001.
- 🦫Oregon State AGvia UNITEDHEALTHCARE INSURANCE COMPANY2023-06-09
UnitedHealthcare reported a data breach to the Oregon Attorney General. The breach was reported on 2023-06-09. The breach occurred during 2/19/2023 - 2/20/2023. The breach was discovered on 2/20/2023. 16,844 individuals were affected. Notice was sent on 6/9/2023.
- 🦬Montana State AGvia UNITEDHEALTHCARE INSURANCE COMPANY2023-04-28
UnitedHealthcare reported a data breach to the Montana Attorney General. The breach was reported on 2023-04-28. The breach occurred from 2/19/2023 to 2/25/2023. 14 Montana residents were affected.
- 🦞Maine State AGvia UNITEDHEALTHCARE INSURANCE COMPANY2022-10-10
UnitedHealthcare (UHC) reported a data breach affecting 32,064 individuals, including 116 Maine residents. The breach, described as an external system breach (hacking), occurred on May 7, 2022, and was discovered on August 4, 2022. The compromised information includes names and Social Security numbers. UHC notified affected individuals on October 7, 2022, and offered a two-year membership to Experian IdentityWorks for identity theft protection.