UnitedHealth Investor Suit Alleges Security, Governance Lapses

By and | August 13, 2026

UnitedHealth Group Inc. board members ignored a raft of governance and oversight risks for years before catastrophic failures triggered billions in losses for investors, a shareholder lawsuit alleges.

An amended complaint filed Aug. 7 in a Minnesota federal court reveals new information from former insiders about how UnitedHealth handled cybersecurity after an acquisition of a company that would later suffer the largest US healthcare data breach on record.

It also alleged that UnitedHealth, which owns the largest US health insurer, shut down an internal audit program that showed problems in its Medicare billing. UnitedHealth has previously faced allegations from whistleblowers and government watchdogs that it inflated Medicare payments, and the US Department of Justice has opened criminal and civil investigations into its Medicare practices.

A UnitedHealth representative declined to comment on the allegations. Attorneys for the defendants didn’t respond to a request for comment.

The healthcare conglomerate, based in Eden Prairie, Minn., and Washington, D.C., is fending off multiple lawsuits from shareholders who incurred losses as the company’s stock price cratered from a record high in 2024. A separate securities fraud lawsuit led by the California Public Employees’ Retirement System is awaiting a judge’s decision on whether to dismiss the claim.

The cases broadly allege that UnitedHealth misled investors about the strength of its business and ignored risks from regulators, even as negative press reports mounted. They center on allegations that it improperly gamed payments from Medicare, neglected cybersecurity risks, inappropriately denied care, and used opaque deals to meet earnings targets and mask the underlying weakness in its operations.

Much of the conduct described in the lawsuits has been reported in media, including the Wall Street Journal, Stat News, and Bloomberg News. UnitedHealth has defended itself and refuted negative claims. Still, the company has said it’s taken about two dozen actions in response to company-sponsored reviews that found problems, including repeated regulatory violations.

The latest filing comes from shareholders including Rhode Island’s public employee retirement system and the Swedish asset manager Länsförsäkringar Fondförvaltning AB, which owns more than $123 million in UnitedHealth stock, according to the complaint. They’re suing board members on behalf of the company, claiming directors and officers missed red flags of “misconduct and serious regulatory concerns, yet took no action to ensure compliance.” Before filing the latest complaint, shareholders reviewed company books and records, but the revised complaint redacted many of those details from the public version.

History of Allegations

The amended complaint expands on allegations first made in a lawsuit filed in 2024.

Some of the claims draw on the accounts of former Change Healthcare employees identified as confidential witnesses. Two people spoke about lax cybersecurity practices following UnitedHealth’s $7.8 billion acquisition of health data and payments company Change Healthcare.

Change was targeted by a cyberattack in 2024 that snarled payments across the healthcare system, cost the company billions and exposed private data of 190 million Americans in the largest US health data breach.

The accounts of insiders cited in the revised complaint suggest that was avoidable.

The company wanted to integrate Change Healthcare swiftly after its 2022 victory in an antitrust lawsuit brought by the US so that it would be tough to unwind the deal if the company lost on appeal, according to one witness. The person was identified in the complaint as Change Healthcare’s director of risk management before and after the deal. That rush left the company blind to the risks involved and unable to address the cyber defenses it needed, the witness said, according to the complaint.

Another executive, identified as Change Healthcare’s director of information services for a dozen years, said UnitedHealth leaders were aware of impaired security systems at Change that led to the data breach.

The company dropped protection from cybersecurity firm CrowdStrike in favor of a service from Microsoft Corp. that the witness considered inferior, the complaint says. This witness also described legacy businesses acquired in the Change deal that had security risks, including lack of multi-factor authentication, and said that management wouldn’t provide significant funding to fix these problems, according to the complaint.

The hack was ultimately attributed to an account that was left unprotected by multi-factor authentication, a basic cybersecurity precaution. “We’re trying to dig through exactly why that server had not been protected,” Andrew Witty, UnitedHealth’s chief executive officer at the time, told Congress in 2024.

Witty, who left the CEO role and the board last year following a collapse in the company’s profits, is among 12 former and current directors and officers named in the lawsuit. It also names current CEO and board chair Stephen Hemsley, who chaired the board for the period covered by the litigation.

Medicare Payment Issues

The complaint also alleges that UnitedHealth shut down an internal audit program that showed it submitted claims for $200 million in Medicare payments that weren’t supported by patients’ diagnoses. The lawsuit blames Hemsley for the decision.

“Rather than remediate this damning finding and demand compliance, Defendant Hemsley supported the decision to eliminate an audit program entirely, ensuring that the fraud could continue undetected,” according to the complaint. The complaint doesn’t offer additional details on the Medicare claims or the audit program.

UnitedHealth has faced extensive criticism over its payments from Medicare. Reports from a federal inspector general, whistle blower lawsuits and congressional inquiries have alleged that the company overstated how sick members were to inflate reimbursements from the government.

The company has disputed these claims and defended its practices. In one pending civil case, a court-appointed expert found the US Department of Justice lacked evidence to support its case and recommended ruling in favor of the company. The Justice Department has separate civil and criminal inquiries into UnitedHealth’s Medicare practices, the company has disclosed.

The lawsuit also alleges that the board knew a federal policy change meant to rein in payments to insurers would cost the company billions of dollars years before it disclosed the size of the financial hit.

The change was a new version of the federal “risk model” that determines how much Medicare pays insurers for patients based on their illnesses.

In 2025, after UnitedHealth’s profit collapsed, the company disclosed that those changes would cost about $11 billion over three years. That figure, according to the lawsuit, was “an impact the Board had been quantifying internally since 2023.”

The lawsuit, known as a derivative complaint, accuses board members of ignoring warning signs for years, damaging the company and wiping out billions in market value. It asks a judge to order the company to improve its corporate governance, implement compliance programs on its Medicare Advantage programs, establish cybersecurity controls that meet industry standards and bar the defendants from serving as officers or directors.

“The Board received specific internal warnings, government reports, and extensive media coverage — all of which created actual knowledge or constituted red flags putting the Board on notice of the Company’s systematic violation of law,” the plaintiffs wrote.

Photo: Photographer: Gabby Jones/Bloomberg

Topics Lawsuits

Was this article valuable?

Here are more articles you may enjoy.