Lead
UnitedHealth Knew About Cybersecurity Gaps, Investors Allege. Then a Breach Hit 190 Million People
Shareholders say board decisions helped pave the way for a breach affecting millions of people. Now they’re suing the healthcare giant
Aug 21, 2026
Photo: Adobe Stock
Listen to this ArticleMore info
0:00 / 0:00
UnitedHealth is being sued by two investment groups over allegations that the company ignored known cybersecurity gaps
A complaint filed by the Rhode Island State Employees’ Retirement System and Länsförsäkringar Fondförvaltning, which holds over $123 million in stock in UnitedHealth, alleges that several current and former executives and board members of the healthcare company are responsible for “corporate governance failures on a historic scale.”
According to the lawsuit, the plaintiffs allege that board members deceived investors, repurchased approximately $29 billion of their own shares, and concealed knowledge of cybersecurity gaps within the company system, which ultimately led to a massive data breach
“On their watch, the company built its industry-leading earnings on a foundation of systemic wrongdoing and illegality,” reads the suit. “It defrauded the federal Medicare program, denied medically necessary care to its most vulnerable members, deceived a federal court, violated patient privacy laws, unlawfully suppressed competition, and manipulated earnings.”
Refreshed leadership advice from CEO Stephanie Mehta
Featured Video
An Inc.com Featured Presentation
An amended filing on August 7 in a Minnesota federal court expands on the original complaint by naming a data breach the company underwent in 2024. The investors claim the company had a lack of safeguards in place to prevent such an event from occurring
UnitedHealth did not immediately respond to Inc.’s request for comment.
Board accountability
The initial complaint filed in 2024 raised concerns over the “firewall” between UnitedHealthcare and Optum, a subsidiary, alleging a breach of fiduciary duties

