TechNewsReel
Live

UnitedHealth Board Sued Over Cybersecurity Lapses and Alleged Audit Suppression

Shareholders allege the healthcare giant ignored systemic security risks during the Change Healthcare acquisition and hid Medicare billing fraud.

TechNewsReel Newsroom · August 17, 2026

An amended shareholder lawsuit filed August 7, 2026, in a Minnesota federal court alleges that UnitedHealth Group board members ignored systemic governance and cybersecurity risks for years. The suit claims the company's leadership neglected critical security gaps to prioritize rapid growth and suppressed internal oversight to maintain fraudulent government reimbursements.

According to the complaint, UnitedHealth rushed the integration of Change Healthcare—acquired for $7.8 billion—to prevent the deal from being unwound on appeal, intentionally overlooking security vulnerabilities in the process. Former insiders cited in the suit claim the company replaced CrowdStrike cybersecurity protection with an inferior Microsoft service and failed to fund necessary fixes for legacy systems. These failures culminated in the 2024 Change Healthcare breach, which exposed the private data of 190 million Americans; the breach was attributed to a single account lacking multi-factor authentication (MFA).

Governance and Financial Allegations

Beyond cybersecurity, the lawsuit targets the company's internal governance and its relationship with federal Medicare programs. The complaint alleges that CEO Stephen Hemsley supported the elimination of an internal audit program after it identified $200 million in unsupported Medicare payments. The plaintiffs' complaint asserts that rather than demanding compliance, Hemsley supported the decision to end the program to ensure the fraud could continue undetected.

Additionally, the suit claims the board had internally quantified the impact of federal "risk model" changes as early as 2023. However, UnitedHealth did not disclose that these changes would cost the company $11 billion over three years until 2025. The plaintiffs, which include Länsförsäkringar Fondförvaltning AB and Rhode Island's public employee retirement system, are now seeking the removal of certain directors and comprehensive corporate governance reforms.

Industry Implications

This case highlights a critical tension between the speed of mergers and acquisitions and the necessity of cybersecurity due diligence. The allegations suggest that when strategic integration is prioritized over security audits, the resulting vulnerabilities can create catastrophic risks for the entire healthcare infrastructure. For the broader industry, the suit serves as a warning that rushing the onboarding of massive data sets without verifying MFA and legacy system security can lead to unprecedented exposure.

What's Next

UnitedHealth has previously admitted to taking two dozen corrective actions following internal reviews that found regulatory violations, though it has defended its general practices. The court will now determine if the allegations of systemic governance failure and the intentional suppression of audits warrant the removal of board members. Observers will be watching for whether the company can prove its current security posture is sufficient to prevent a recurrence of the Change Healthcare disaster.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.