Skip to content
UnitedHealth Group · SEC 8-K Item 1.05Filed Feb 22, 2024

UnitedHealth Group discloses a material cybersecurity incident

Material cybersecurity incidentSecurityUpdated 38h ago
Disclosed
Feb 22, 2024
Records
Not stated
Industry
Financial services
Filings
3
Data involved
Not listed by the filing.
SEC filing

What the filing says

On February 21, 2024, UnitedHealth Group (the "Company") identified a suspected nation-state associated cyber security threat actor had gained access to some of the Change Healthcare information technology systems. Immediately upon detection of this outside threat, the Company proactively isolated the impacted systems from other connecting systems in the interest of protecting our partners and patients, to contain, assess and remediate the incident. The Company is working diligently to restore those systems and resume normal operations as soon as possible, but cannot estimate the duration or extent of the disruption at this time.

Timeline

  1. Amended filing · Apr 24, 00:00 UTC
    Amended filing: https://www.sec.gov/Archives/edgar/data/731766/000073176624000150/pressreleasedatedapril2220.htm
  2. Amended filing · Mar 8, 00:00 UTC
    8-K/A: As an update to the Original Report, the Company identified that cybercrime threat actors had gained access to certain Change Healthcare information technology systems. Immediately upon detection of this outside threat, the Company isolated the impacted systems from other connected systems in order to protect the Company's partners and customers. The Company promptly notified customers, law enforcement and government agencies.

Sources: vendors' own status pages, published postmortems and SEC 8-K Item 1.05 filings, read daily. Times as reported. Logos via logo.dev; trademarks belong to their owners.

Outages by email

Saturday mornings: the week's major outages, new postmortems and disclosed breaches, only in weeks that had some.

Double opt-in. Unsubscribe any time.