Zhitong Finance App learned that a key shareholder lawsuit alleges that members of the board of directors of the US health insurance supergiant UnitedHealth Group (UNHUS) ignored a series of corporate governance and supervision risks for many years until catastrophic mistakes broke out, which ultimately caused investors billions of dollars in losses.
A revised lawsuit filed in a federal court in Minnesota on August 7 revealed new information from people familiar with the company's former insider on how UnitedHealth handled cybersecurity issues after acquiring a company that was later affected by the largest healthcare data breach recorded in the US.
The lawsuit also alleges that UnitedHealth, which owns America's largest health insurance provider, closed an internal audit program that previously discovered that the company had problems with Medicare (US Medicare) billing. UnitedHealth has previously faced accusations from whistleblowers and government regulators that it inflated Medicare payments; the US Department of Justice has also launched criminal and civil investigations into its Medicare business practices.
A representative for UnitedHealth declined to comment on the allegations. Defense attorneys did not respond to requests for comment.
Shareholders such as the Rhode Island Public Employee Retirement System accuse current and former directors and executives of ignoring major regulatory and compliance “red lines” for a long time in the form of derivative lawsuits, covering Change Healthcare cybersecurity flaws, Medicare risk adjustments and internal audit issues, and policy shocks that the board of directors allegedly knew about in advance but were not fully disclosed.
Change Healthcare's 2024 cyber attack ultimately affected about 190 million people, making it one of the largest disclosed data breaches in the history of the US healthcare industry; at the same time, government investigations and congressional reviews surrounding UnitedHealth Medicare Advantage risk adjustment practices still form an important regulatory background.
The healthcare group, headquartered in Eden Prairie, Minnesota and Washington, D.C., is currently dealing with multiple shareholder lawsuits. These investors suffered severe losses after the company's stock price plummeted from an all-time high in 2024. Another securities fraud lawsuit led by the California Civil Service Retirement System is currently awaiting a judge's decision on whether to dismiss the lawsuit.
These cases generally accuse UnitedHealth of misleading investors on issues relating to the overall strength and prospects of its business, and that the company is ignoring risks from regulators even as negative media reports continue to increase. These lawsuits mainly revolve around allegations that Allied Health improperly manipulated Medicare payments, ignored cybersecurity risks, improperly denied patients access to health services, and used opaque deals to achieve profit goals and mask the true weakness of its underlying operations.
Many of the acts described in these lawsuits have previously been covered by the media, including The Wall Street Journal, Stat News, and Bloomberg News. UnitedHealth, on the other hand, has always defended itself and denied the negative accusations. Despite this, the company has stated that after the internal review initiated by the company discovered the problem, it has taken about 20 or more corrective actions, including rectification of numerous violations of regulatory regulations.
As shown in the chart above, UnitedHealth's stock price collapsed after a high in 2024 — investors suffered significant losses after the company withdrew its performance outlook.
The latest lawsuit was filed by shareholders including the Rhode Island Public Employee Retirement System and Swedish asset management company Länsförsäkringar Fondförvaltning AB. According to the lawsuit, the latter holds more than $123 million worth of UnitedHealth shares. On behalf of the company, these shareholders sued the board members, claiming that the directors and most executives ignored the red flags of “illegal acts and serious regulatory concerns” and did nothing to ensure that the company complied with the relevant regulations. Shareholders had already checked the company's books and records before filing the latest lawsuit, but the revised public version of the lawsuit omitted many of these details.
According to information, according to the lawsuit, the board of directors had already internally quantified the huge financial impact of the new Medicare risk model as early as 2023, and the company later revealed that the three-year cumulative impact of related changes may have caused an impact of about 11 billion US dollars; since then, United Health has publicly acknowledged that Optum Health was affected by regulatory and cost issues, causing a three-year financial pressure of about 11 billion US dollars. As a result, shareholder claims have further escalated from damages to requests to strengthen Medicare compliance mechanisms, cybersecurity controls, and corporate governance, and even to restrict some defendants from continuing to serve as directors or executives in the future. What this litigation really points to is not a profit reduction, but rather whether the “high-quality medical compound asset” valuation framework previously enjoyed by UnitedHealth needs to be permanently added to the governance discount.
From cyber breaches to Medicare's “compliance black box”: regulatory risks directly hit UnitedHealth's core profit machine
According to information, this latest revised lawsuit further expands on the charges initially raised in a lawsuit filed in 2024.
Some of the charges stem from statements from former Change Healthcare employees who were listed as anonymous witnesses in the lawsuit. Two of them spoke about UnitedHealth's lax cybersecurity practices after UnitedHealth bought the healthcare data and payment company Change Healthcare for $7.8 billion.
Change Healthcare was hit by a cyber attack in 2024, causing the payment process of the entire healthcare system to be disrupted, causing the company to lose billions of dollars, and leaking the private data of 190 million Americans, making it the largest healthcare data breach in the US.
According to insiders quoted in the revised lawsuit, this incident could have been avoided.
According to a witness statement, UnitedHealth hopes to quickly complete the integration of Change Healthcare after winning an antitrust lawsuit filed by the US government in 2022, so even if the company later loses the appeal, it will be difficult to split the deal because the business is already deeply integrated. According to the lawsuit, the witness acted as Change Healthcare's risk management director before and after the deal. According to the lawsuit, the witness said that this hasty push made it impossible for the company to clearly see the risks involved and to resolve the cyber defense issues that it really needed to reinforce.
Another executive is described in the lawsuit as having been the information services director for Change Healthcare for 12 consecutive years. The person said UnitedHealth's leadership was aware of flaws in Change Healthcare's security system, and these flaws eventually led to the data breach.
According to the lawsuit, the company abandoned the protective services provided by the cybersecurity company CrowdStrike and used a Microsoft service instead, and the witness believed that the latter's security capabilities were weak. The witness also described the security risks of some historic legacy businesses acquired in the Change deal, including a lack of multi-factor authentication, and stated that management was unwilling to provide large-scale funding to address these issues.
The hack was ultimately attributed to an account not protected by multi-factor authentication, which is the most basic cybersecurity measure. UnitedHealth's then-CEO Andrew Witty told the US Congress in 2024: “We are working to thoroughly find out why that server wasn't protected at the time.”
Witty stepped down as CEO and director last year after the company's profits collapsed. He is one of 12 current and former directors and executives listed in this lawsuit. The lawsuit also listed Stephen Hemsley, the current CEO and chairman of the board, who was the chairman of the company's board during the period covered by the lawsuit.
The lawsuit also alleges that UnitedHealth closed an internal audit program that found that the company had submitted claims involving $200 million in Medicare payments, but these payments were not supported by patient diagnosis results. The lawsuit blamed Hemsley for the decision.
The lawsuit stated: “Instead of rectifying this extremely damaging audit finding and requiring the company to achieve compliance, defendant Hemsley supported the decision to completely cancel this audit project to ensure that related fraud could continue undetected.” The complaint did not disclose further details about these Medicare claims or the audit program.
Governance risk is beginning to become shareholder value risk
The lawsuit alleges that the company shut down an internal audit program, and the project allegedly found about $200 million in Medicare payment claims lacking patient diagnostic support; the broader context is that regulators, whistleblowers, and Congress have long questioned whether UnitedHealth exaggerates patients' conditions through risk adjustment codes, thereby increasing government compensation. Related Senate investigations once again put UnitedHealth's risk adjustment practices in the spotlight in 2026, and the company has always denied misconduct and defended its own business practices. What really affects the valuation here is not a potential fine, but whether the market starts adding a higher regulatory risk premium to UnitedHealth's long-term most important profit engine.
The lawsuit also stated that the board of directors had already quantified the huge financial impact of the new Medicare risk model internally as early as 2023, and the company later disclosed that the relevant changes may have caused an impact of about 11 billion US dollars over three years; since then, UnitedHealth did publicly acknowledge that Optum Health was affected by regulatory and cost issues, causing a three-year financial pressure of about 11 billion US dollars. As a result, shareholder claims have further escalated from damages to requests to strengthen Medicare compliance mechanisms, cybersecurity controls, and corporate governance, and even to restrict some defendants from continuing to serve as directors or executives in the future. What this litigation really points to is not a profit reduction, but rather whether the “high-quality medical compound asset” valuation framework previously enjoyed by UnitedHealth needs to be permanently added to the governance discount.
UnitedHealth has long been widely criticized for the payments it received from Medicare. The federal inspector general's report, whistleblower lawsuits, and congressional investigations have all alleged that the company exaggerated the seriousness of the member's condition to increase the amount of reimbursement it received from the government.
The company has always contested these allegations and defended its own business practices. In a civil case still pending, an expert appointed by the court found that the US Department of Justice lacked sufficient evidence to support its case claims and recommended that the court decide in favor of the company. UnitedHealth has disclosed that the Department of Justice is also currently conducting separate civil and criminal investigations into the company's Medicare business practices.
The lawsuit also alleges that the board of directors knew years before the company officially disclosed its financial impact that a federal policy adjustment aimed at limiting payments to insurance companies would cost the company billions of dollars.
This change involves a new version of the federal “risk model,” which determines how much Medicare should pay insurers based on a patient's illness.
In 2025, following the collapse of UnitedHealth's profits, the company disclosed that these policy changes would have an impact of about $11 billion over three years. According to the lawsuit, the “scale of impact” represented by this figure has been carried out by the board of directors internally since 2023.
This lawsuit is a so-called derivative lawsuit. It alleges that board members have ignored warning signals for years, harmed the company's interests, and evaporated the company's multi-billion dollar market value. The plaintiff asked the judge to order UnitedHealth to improve corporate governance, establish compliance programs for its Medicare Advantage business, establish a cybersecurity control system that meets industry standards, and prohibit the relevant defendants from continuing to serve as company executives or directors.
According to reports, the plaintiff wrote, “The board has received specific internal warnings, government reports, and numerous media reports — all of this information already constitutes actual knowledge, or at least a danger signal sufficient to alert the board of the company to systemic misconduct.”