UnitedHealth Group combines two platforms, UnitedHealthcare and Optum, to provide health insurance and health services. UnitedHealthcare offers medical, dental, and vision plans for individuals, employers, and government programs, including Medicare and Medicaid. Optum uses data, technology, and analytics to deliver pharmacy care, care management, and consulting to providers, payers, and government entities. The company earns revenue from insurance premiums and service fees, and aims to help people live healthier lives by expanding access to affordable, high-quality care and improving health outcomes through data-driven solutions.
Company Size
10,001+
Company Stage
IPO
Headquarters
Eden Prairie, Minnesota
Founded
1980
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Flexible Work Hours
UnitedHealth's LHC Group hit by vishing. LHC Group, a home health and hospice provider owned by UnitedHealth Group's Optum, has disclosed a data breach tied to a vishing attack that exposed patient information, confirming the LHC Group Optum vishing breach as the latest cybersecurity incident affecting a major UnitedHealth subsidiary. How the LHC Group Optum vishing breach actually unfolded. LHC Group said it became aware April 7 that an employee may have fallen victim to a voice phishing scheme, according to the September notice. The company's third-party technology vendor, which supports referral management, care coordination, and clinical workflow functions, subsequently flagged suspicious activity tied to an LHC user account. The scope and timeline of unauthorized access. An investigation determined a threat actor stole credentials and accessed a large volume of files containing patient protected health information on the vendor's platform. The unauthorized access occurred from April 7 to April 15, and LHC Group began confirming the identities of affected individuals July 9, a roughly three-month gap between the initial incident and identity confirmation that reflects the often lengthy forensic process required to fully characterize a breach's scope. What data was exposed within this LHC Group Optum vishing breach. Exposed data may have included patient names, addresses, dates of birth, clinical summaries, treatment plans, diagnosis codes, dates of service, provider information, health insurance details, and Medicare or Medicaid ID numbers. Social Security numbers and financial information were involved in limited instances, according to the notice. Why this range of exposed data matters. The breadth of clinical and identifying information potentially exposed, spanning treatment plans and diagnosis codes alongside identity documents like Social Security numbers, illustrates the significant privacy stakes for affected patients even though the most sensitive financial data was limited to only a subset of cases. The regulatory disclosure behind this LHC Group Optum vishing breach. The breach was reported to HHS' Office for Civil Rights on Sept. 4 with an initial figure of 500 affected individuals, a placeholder count that companies commonly file while a review is ongoing and that may rise as LHC Group's investigation continues. OCR posted the figure later in the month. Why this placeholder figure doesn't reflect the full scope. Using a placeholder figure while an investigation remains active is standard breach reporting practice, meaning the true number of affected individuals will likely become clearer only as LHC Group completes its review, a pattern consistent with how the company's earlier 2026 breach involving vendor Doctor Alliance also affected more than 28,000 individuals once fully tallied. LHC Group's response to this Optum vishing breach. LHC Group disabled the compromised account, notified the FBI, engaged third-party forensic experts, and is offering two years of free credit monitoring and identity protection through IDX. The company said it has no evidence the information has been misused. Why this response reflects standard breach protocol. Disabling the compromised account and engaging both law enforcement and independent forensic experts represents the standard sequence of containment and investigation steps healthcare organizations typically follow after confirming unauthorized access, though the company's assurance that no misuse has been detected does not rule out the possibility of future harm to affected individuals. How this LHC Group Optum vishing breach fits its corporate ownership. LHC Group, with about 30,000 employees across dozens of states, became part of UnitedHealth Group's Optum in 2023 as part of a $5.4 billion acquisition. This ownership places the breach within the broader portfolio of UnitedHealth Group companies already facing significant public and regulatory scrutiny over cybersecurity, following the massive Change Healthcare cyberattack that affected the industry broadly in 2024. Why this adds to UnitedHealth's ongoing scrutiny. Given the heightened attention already directed at UnitedHealth Group's cybersecurity practices and broader corporate structure, this breach at a subsidiary acquired for $5.4 billion adds another data point to the sustained public and regulatory focus the company has faced across multiple fronts throughout 2026. What this LHC Group Optum vishing breach means going forward. With LHC Group's investigation still ongoing and the initial 500-person figure likely to rise, affected patients should expect updated notifications as the company completes its review of exactly whose information was compromised. Given that this marks at least the second vendor-related breach LHC Group has experienced in 2026, following an earlier incident involving vendor Doctor Alliance, the company and its parent Optum may face pressure to strengthen vendor risk management and employee training specifically around voice phishing recognition. What to watch going forward. As LHC Group's investigation continues, industry observers will likely watch how much the affected individual count grows beyond the initial 500-person placeholder figure, and whether additional details emerge about the specific vendor platform involved. Given the recurring pattern of vishing and third-party vendor compromise affecting LHC Group specifically this year, this LHC Group Optum vishing breach may prompt renewed scrutiny of how UnitedHealth Group's Optum subsidiaries manage vendor access controls and employee security training across their home health and hospice operations nationally.
UnitedHealth Group creates new chief administrative officer position. September 24, 2026 UnitedHealth Group has named Jodee Kozlak to the newly-created role of chief administrative officer, the healthcare giant announced Thursday morning.
UnitedHealth, Cigna team with CertifyOS on provider credentialing - Modern Healthcare. UnitedHealth, Cigna, Centene join forces on provider credentialing. September 23, 2026 05:00 AM CDT Health insurance companies are joining forces to simplify the arduous provider credentialing process.
UnitedHealth Group's Optum has sold a stake in its Florida WellMed clinics to private equity firm TPG and formed a strategic partnership. The clinics will remain in Optum's network and continue serving patients. TPG's involvement aims to accelerate growth through local focus and investment capacity whilst Optum works to improve clinic performance. UnitedHealth opens approximately 15 clinics in Florida annually. The partnership supports both profitability repair and expansion without slowing the company's broader turnaround. Optum Health is recovering from a challenging 2025, when it generated $102 billion revenue, down 3% year over year, with operating margins below zero. Management expects margins of roughly 2% in 2026, 4% in 2027, and 6% in 2028.
Do no harm: UnitedHealth's buyup of ASCs had little impact on facilities. After UnitedHealth Group (NYSE: UNH) acquired SCA Health and its network of 300 ambulatory surgery centers (ASCs), very little changed about the way those facilities operate, according to new research. The study, published in the September issue of Health Affairs, builds upon prior research into the effects of UnitedHealth buying major ASC operator SCA, the company formerly known as Surgical Care Affiliates, in 2017. In an analysis published in February, researchers examined commercial claims from 2015 to 2018 and found that UnitedHealth's acquisition of 24 ASCs was associated with an 11% price increase for competing insurers. It also found that referral patterns did not meaningfully change after the purchase. But the more recent study, conducted by different researchers, examined five aspects of the impact of UnitedHealth's ownership of both SCA and non-SCA surgery centers. It also covered a longer period than the previous study, from 2013-2021. The findings echo what SCA Health CEO Winborne Macphail told ASC News in a recent interview, which is that UnitedHealth's Optum division mainly acts as a "capital infusion" partner for SCA while leaving it to handle its own operations. The researchers - who hailed from Columbia University, Brown University and the RAND Corporation - found that UnitedHealthcare's investment in ASCs was not associated with any significant near-term changes in procedure volume, ASC size and mix of patients. However, the ownership changes carried a small but notable reduction in the probability of post-colonoscopy complications in the second year after the change in ownership. That, coupled with the fact that average risk score of patients did not change in that time, "suggests that no quality deterioration was observed in the short run," the study authors wrote. For their analysis of procedure volume, ASC size, patient mix and care quality, researchers examined data from the Medicare fee-for-service population. A better facility-fee negotiator? The researchers then examined how UnitedHealth's ownership of ASCs impacted negotiated commercial prices for two procedures - arthroscopy and colonoscopy - across UnitedHealthcare, Blue Cross Blue Shield, Aetna and Cigna. They found that compared with other insurers, UnitedHealthcare paid lower facility fees to non-UnitedHealth-owned ASCs, particularly in less concentrated insurer markets. UnitedHealth's ownership of an ASC also was negatively associated with negotiated facility fees, although the pattern differed by procedure, the researchers wrote. "Specifically, for arthroscopy, UnitedHealthcare ASCs had lower facility fees for all insurers, which might reflect lower facility operating costs," the study asserted. "For colonoscopy, there was not a statistically significant difference between facility fees that UnitedHealthcare ASCs received from UnitedHealthcare compared with those received from other nationwide insurance companies." All eyes on consolidation. This latest research on the impact of the vertical integration between health insurance companies and healthcare providers comes at a time of heightened scrutiny of industry consolidation, health insurers' business practices and UnitedHealth's sprawling enterprise. UnitedHealth leaders have long maintained that the company has a "firewall" between its health insurance arm, UnitedHealthcare; and its Optum division, which includes Optum Health (healthcare delivery assets), Optum Rx (a pharmacy benefit manager) and Optum Insight (data and analytics). The Biden-era Dept. of Justice directly challenged the firewall concept when it sued to block Optum's acquisition of the major claims-data clearinghouse Change Healthcare and argued that the company would use that data to disadvantage competing insurers - but it was unsuccessful. Meanwhile, consolidation in the ASC space has accelerated. While UnitedHealth is unique among payer-providers it its ownership of significant ASC assets, health systems have been racing to buy up surgery centers to diversify their own portfolios. The Catholic health system Ascension's purchase of major ASC operator AMSURG is perhaps the most notable recent example. In the September Health Affairs study, researchers acknowledged those dynamics and said they hope their findings help bring some clarity to the debate over the value of healthcare consolidation. "As consolidation among insurers and ASCs increases in scope and attracts regulatory scrutiny, our study provides evidence to inform antitrust policy and enforcement activity," they wrote. "Policy makers should continue to monitor insurer-provider integration, particularly its relationship with negotiated prices and market competition over longer time horizons."