NE Times
Business

UnitedHealth Shareholders Allege Governance Failures on a Historic Scale Over Medicare Billing and the Change Healthcare Breach

An amended complaint in Minnesota draws on former insiders to allege a rushed acquisition and a discontinued billing audit.

Aisha Verma

Commentary & Analysis ·

4 min read
An empty corporate boardroom at dusk with a city skyline beyond

Verified key facts

  • Two groups of shareholders have sued UnitedHealth, with an amended complaint filed on 7 August in a Minnesota federal court, per Healthcare Dive and Modern Healthcare.
  • The complaint alleges the company rushed its acquisition of Change Healthcare, leaving cybersecurity gaps that contributed to the largest healthcare data breach in US history in 2024.
  • It alleges UnitedHealth shut down an internal audit programme that had identified problems in its Medicare billing.
  • Plaintiffs say at least $200 million of claims were submitted to the federal government backed by erroneous diagnosis codes.
  • The filing describes 'corporate governance failures on a historic scale' and cites more than $277 billion in shareholder value lost between December 2024 and August 2025.

A complaint built on insider accounts

Two groups of UnitedHealth shareholders have brought suit against the company, its executives and board members, with an amended complaint filed on 7 August in a Minnesota federal court. Healthcare Dive and Modern Healthcare both reported that the amended filing draws on new information from former insiders.

That detail is what separates this from the ordinary post-collapse securities suit. Shareholder litigation usually reasons backwards from a share price: something fell, therefore something must have been concealed. A complaint sourced to people who were in the building makes a narrower and more testable claim about what was known internally and when.

The acquisition at the centre of it

The allegation concerning Change Healthcare is that UnitedHealth rushed the acquisition of the claims-processing business, and that the integration left cybersecurity gaps. In 2024 Change Healthcare suffered what became the largest healthcare data breach recorded in the United States.

The complaint's specific contention is that Optum and Change Healthcare became so intertwined that separating them was, in the plaintiffs' phrasing, nearly impossible. That matters because it converts a security failure into a governance one: the claim is not merely that a breach happened, but that the structure which made it possible was chosen and then not corrected.

The audit that was reportedly stopped

The second strand concerns Medicare. Plaintiffs allege that UnitedHealth shut down an internal audit programme that had surfaced problems in its Medicare billing, and that the company submitted at least $200 million in claims to the federal government supported by erroneous diagnosis codes.

Diagnosis coding is where Medicare Advantage economics live. Plans are paid according to how sick their enrolled members are assessed to be, so the codes attached to a patient translate directly into revenue. An allegation that an audit function identifying coding problems was discontinued is, if established, an allegation about the deliberate removal of a control.

The number attached to the fallout

The complaint puts more than $277 billion of shareholder value as lost between December 2024 and August 2025. Figures of that size in litigation are advocacy as much as accounting, and they measure market capitalisation rather than anything paid out.

Still, the scale is not in dispute in the way the causation is. UnitedHealth is among the largest companies in American healthcare, and the period in question covered the breach, the Medicare scrutiny and a broader repricing of the managed-care sector.

It is also worth separating the two allegations, because they carry different kinds of risk. A cybersecurity failure is largely a historical event with a quantifiable remediation cost. A contention that Medicare claims were submitted on erroneous diagnosis codes reaches into how revenue was recognised, and questions of that sort tend to attract regulators as well as plaintiffs. The two strands appear in one complaint, but they would not resolve on the same timetable or in the same forum.

What the company has and has not said

These are allegations in a civil complaint that has not been tested. UnitedHealth has contested claims of this kind previously, and the amended filing marks the start of a contested phase rather than any finding. Nothing here has been established in court.

That caveat is not a formality. Securities complaints are written to survive a motion to dismiss, which rewards the strongest available characterisation of every fact. The insider sourcing raises the evidentiary floor, but a filing remains one side's account.

Why governance is the frame investors chose

It is notable that the plaintiffs anchored the case on governance rather than on any single operational failure. Suing over a breach alone runs into the defence that no security is perfect. Suing over the pattern — an acquisition integrated at speed, a control function discontinued, board oversight described as absent — asks a different question, about whether the mechanisms that were meant to catch these things were functioning at all.

It also broadens the exposure beyond the company to individual directors and officers, which is why board-level defendants are named.

There is a practical reason for the choice as well as a legal one. Directors and officers are generally covered by insurance policies written specifically for claims of this type, and those policies respond to allegations of oversight failure in a way that they may not to purely operational losses. Framing the case around governance therefore aims the claim at a pool of money that exists to satisfy it. That is ordinary litigation strategy rather than anything improper, but it explains why the complaint reads as it does.

The motion to dismiss, and what discovery would open

The near-term procedural marker is UnitedHealth's response and any motion to dismiss, which will test whether the insider accounts are specific enough to clear the pleading standard for securities fraud.

If the case survives that stage, discovery is where the audit-programme allegation gets decided, because it turns on internal documents about who ended it and why. That is the point at which this stops being a filing and becomes a record.

Sources

  • Healthcare Dive - Investor suit says UnitedHealth ignored governance, cybersecurity gaps for years
  • Modern Healthcare - Investor lawsuit alleges UnitedHealth ignored Medicare, cyber risks
  • Bloomberg - UnitedHealth Investor Suit Alleges Security, Governance Lapses
  • Insurance Journal - UnitedHealth Investor Suit Alleges Security, Governance Lapses
Share

You may also like to read