Dive Brief:
- Two groups of shareholders are suing UnitedHealth, alleging the company defrauded Medicare, manipulated earnings and ignored cybersecurity gaps for years.
- The plaintiffs, two institutional investors, allege that UnitedHealth rushed its acquisition of claims processing subsidiary Change Healthcare, leading to cybersecurity gaps that resulted in the largest healthcare data breach in U.S. history in 2024. The suit also claims the company shut down an internal audit program that showed issues with its Medicare billing.
- The amended complaint, filed Aug. 7, expands on the initial lawsuit filed by the shareholders in 2024, relying on confidential witnesses who used to work for Change Healthcare in leadership roles, as well as a review of UnitedHealth’s records.
Dive Insight:
UnitedHealth and several current and former executives and board members are responsible for “corporate governance failures on a historic scale,” the lawsuit says.
The plaintiffs — a public pension fund for Rhode Island state employees and Länsförsäkringar Fondförvaltning AB, a Swedish asset manager — allege that board members deceived investors, repurchased approximately $29 billion of their own shares and concealed their misconduct.
In the initial suit, shareholders alleged that UnitedHealth’s “firewall” protocol with Optum — a strategy the company employed to block sensitive data from flowing freely between the two companies, in an attempt to appease antitrust allegations — was a misrepresentation of its practices. The amended suit shifts focus to UnitedHealth’s handling of Change from a cybersecurity standpoint, as well as allegations of Medicare billing issues.
One of the confidential witnesses, who served as Change’s director of risk management from 2017 to 2023, said in the suit that UnitedHealth’s post-acquisition transition period was deliberately rushed because the Department of Justice had filed an appeal in 2022 in an attempt to block the deal. The DOJ argued that UnitedHealth’s acquisition of Change would result in less competition and higher health insurance costs.
UnitedHealth wanted the companies to be “so fully combined” that separation would be “nearly impossible” if the deal was ultimately blocked, the suit said. It wasn’t, and UnitedHealth finalized its acquisition of Change in 2022.
That alleged lack of due diligence meant that UnitedHealth didn’t have all the information it needed to understand Change’s risk profile, because, “when you rush, you miss things,” the witness said. The suit claims that UnitedHealth was aware of its security shortcomings, including a deficient firewall and improper access controls, like multifactor authentication.
It was this rush that led to the 2024 ransomware attack that exposed the data of 190 million people, compromised claims processing nationwide and cost UnitedHealth over $2 billion, according to the witness. The lack of MFA for Change enabled hackers to compromise its systems.
The Minnesota-based company’s net income and stock price plummeted in the aftermath of the data breach.
Among the other claims in the amended complaint are several allegations around UnitedHealth’s Medicare billing practices, which have faced scrutiny in other lawsuits and federal investigations in recent years.
The lawsuit called out Stephen Hemsley, UnitedHealth’s chief executive and board chairman, alleging that he supported the decision to eliminate an internal audit program that revealed that UnitedHealth had submitted at least $200 million in unsupportable diagnosis codes to the federal government.
“On their watch, the Company built its industry-leading earnings on a foundation of systemic wrongdoing and illegality,” the suit stated.
“It defrauded the federal Medicare program, denied medically necessary care to its most vulnerable members, deceived a federal court, violated patient privacy laws, unlawfully suppressed competition, and manipulated earnings.”
UnitedHealth declined to answer questions about ongoing litigation.