Incident · 8-K Item 1.05
UnitedHealth Group discloses the Change Healthcare cyberattack
Compiled 2026-09-27 from public records. By the cisonews.net Desk.
UnitedHealth Group disclosed on February 22, 2024 that a threat actor had gained access to some information technology systems of its Change Healthcare unit, which processes pharmacy, medical claims and payment transactions. The company identified the intrusion on February 21 and filed under Item 1.05 the next day.
The first filing
In the original report UnitedHealth described the actor as a suspected nation-state associated threat. It isolated the affected systems from other connected systems and said the disruption was specific to Change Healthcare.
Amendments
The March 8, 2024 amendment changed the description of the attackers to cybercrime threat actors. It said the company's work centred on restoring pharmacy, medical claims and payment services, and it attached a press release with an expected restoration timeline.
The April 24, 2024 amendment incorporated an April 22 press release on the company's data review and support for affected individuals. Across all three filings, UnitedHealth stated it had not determined that the incident was reasonably likely to materially affect its financial condition.
What the Item 1.05 text leaves out
The filings' own text does not give a count of affected individuals; that material sits in the attached press releases, which this entry does not summarize.
Sources
- 2024-02-22 · AUnitedHealth Group, Form 8-K (SEC EDGAR), published February 22, 2024
- 2024-03-08 · AUnitedHealth Group, Form 8-K/A (SEC EDGAR), published March 8, 2024
- 2024-04-24 · AUnitedHealth Group, Form 8-K/A (SEC EDGAR), published April 24, 2024
Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.
See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.