Skip to content
UnitedHealth Group · SEC 8-K Item 1.05Filed Feb 22, 2024

UnitedHealth Group discloses a material cybersecurity incident

Material cybersecurity incidentSecurityUpdated 16h ago
Disclosed
Feb 22, 2024
Records
Not stated
Industry
Financial services
Filings
3
Data involved
Not listed by the filing.
SEC filing

What the filing says

On February 21, 2024, UnitedHealth Group (the "Company") identified a suspected nation-state associated cyber security threat actor had gained access to some of the Change Healthcare information technology systems. Immediately upon detection of this outside threat, the Company proactively isolated the impacted systems from other connecting systems in the interest of protecting our partners and patients, to contain, assess and remediate the incident. The Company is working diligently to restore those systems and resume normal operations as soon as possible, but cannot estimate the duration or extent of the disruption at this time.

Timeline

  1. Amended filing · Apr 24, 00:00 UTC
    Amended filing: https://www.sec.gov/Archives/edgar/data/731766/000073176624000150/pressreleasedatedapril2220.htm
  2. Amended filing · Mar 8, 00:00 UTC
    8-K/A: As an update to the Original Report, the Company identified that cybercrime threat actors had gained access to certain Change Healthcare information technology systems. Immediately upon detection of this outside threat, the Company isolated the impacted systems from other connected systems in order to protect the Company's partners and customers. The Company promptly notified customers, law enforcement and government agencies.

From vendors' own status pages and disclosures. Times as reported. Logos via logo.dev; trademarks belong to their owners.

Weekly: the week's major outages, postmortems and breaches, Saturday mornings.