1 unchanged sentence
CYBERSECURITY
−Removed: UnitedHealth Group manages cybersecurity and data protection through a continuously evolving framework.
−Removed: The framework allows us to identify, assess and mitigate the risks we face, and assists us in establishing policies and safeguards to protect our systems and the information of those we serve.
−Removed: Our cybersecurity program is managed by our Chief Digital and Technology Officer and our Chief Security Officer .
−Removed: The Audit and Finance Committee of the Board of Directors has oversight of our cybersecurity program and is responsible for reviewing and assessing the effectiveness of the Company’s cybersecurity and data protection policies, procedures and resource commitment, including key risk areas and mitigation strategies.
−Removed: As part of this process, the Audit and Finance Committee receives regular updates from the Chief Digital and Technology Officer and the Chief Security Officer on critical issues related to our information security risks, cybersecurity strategy, supplier risk and business continuity capabilities.
−Removed: The Audit and Finance Committee has also added a leading cybersecurity incident and response firm to serve as its advisor on cybersecurity matters.
−Removed: The Company’s framework includes an incident management and response program that continuously monitors the Company’s information systems for vulnerabilities, threats and incidents;
−Removed: manages and takes action to contain incidents that occur;
−Removed: remediates vulnerabilities;
−Removed: and communicates the details of significant threats and incidents to management, including the Chief Digital and Technology Officer and the Chief Security Officer, as deemed necessary or appropriate.
−Removed: Pursuant to the Company’s incident response plan, incidents are reported to the Audit and Finance Committee and appropriate government agencies and other authorities, as deemed necessary or appropriate, considering the actual or potential impact, significance and scope.
−Removed: We require our third-party partners and contractors to handle data in accordance with our data privacy and information security requirements and applicable laws.
−Removed: We regularly engage with our suppliers, partners, contractors, service providers and internal development teams to identify and remediate vulnerabilities in a timely manner and monitor system upgrades to mitigate future risk, and evaluate whether they employ appropriate and effective controls and continuity plans for their systems and operations.
−Removed: To ensure that our program is designed and operating effectively, our infrastructure and information systems are audited periodically by internal and external auditors.
−Removed: We have obtained various certifications from industry-recognized certifying organizations as a result of certain external audits.
−Removed: We also perform regular vulnerability assessments and penetration tests to improve system security and address emerging security threats.
−Removed: Our internal audit team independently assesses security controls against our enterprise policies to evaluate compliance and leverages a combination of auditing and security frameworks to evaluate how leading practices are applied throughout our enterprise.
+Added: Overview of Cybersecurity Program
+Added: UnitedHealth Group assesses its cybersecurity and data protection initiatives through the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
+Added: This framework provides guidelines for maintaining a mature and comprehensive cybersecurity program, outlining the essential components and responsibilities required to safeguard sensitive information.
+Added: Risk Assessment and Management Practices
+Added: The Company employs processes to assess, identify, and manage cybersecurity risks.
+Added: These processes include conducting tabletop exercises to test and reinforce incident response controls, performing control gap analyses, executing penetration tests, and implementing data recovery testing.
+Added: Internal and external security assessments, along with ongoing threat intelligence monitoring, are used to further strengthen the program.
+Added: Employees participate in annual cybersecurity and data privacy training to enhance awareness and preparedness across the enterprise.
+Added: Incident Management and Response
+Added: The Company has established an incident management and response program that continuously monitors information systems for vulnerabilities, threats, and incidents.
+Added: This program is designed to respond to and manage incidents as they arise, remediate vulnerabilities, and communicate significant threats or incidents to management, including the Chief Security Officer (CSO), the Chief Digital and Technology Officer (CDTO) , and executive leadership.
+Added: Under the incident response plan, incidents are reported to the Audit and Finance Committee and, when necessary, to appropriate government agencies, based on their impact, significance, and scope.
+Added: Third-Party Risk Management
+Added: We require third-party partners and contractors to handle data in accordance with the Company’s data privacy and cybersecurity requirements, as well as applicable laws.
+Added: The Company maintains ongoing engagement with suppliers, partners, contractors, and service providers to identify and remediate vulnerabilities, and monitors system upgrades to mitigate future risks.
+Added: Through our third-party risk management program, we evaluate whether third parties use effective controls and business continuity plans, and drive the remediation of any identified issues or risks.
+Added: Auditing, Certifications, and Continuous Improvement
+Added: We engage both internal and external advisors and auditors to review and audit our infrastructure and information systems to enhance the program’s design and operational effectiveness.
+Added: The Company maintains various certifications from industry-recognized organizations.
+Added: We conduct regular vulnerability assessments and penetration tests to improve system security and address emerging security threats.
+Added: The internal audit team independently assesses cybersecurity controls against enterprise policies, using a combination of auditing and cybersecurity frameworks to evaluate the application of leading practices.
Audit results and remediation progress are reported to, and monitored by, senior management and the Audit and Finance Committee.
−Removed: We also periodically partner with industry-leading cybersecurity firms to assess our cybersecurity program.
−Removed: These assessments complement our other assessment work by evaluating our cybersecurity program as a whole.
−Removed: We complete an enterprise information risk assessment as part of our overall enterprise information security risk management assessment, which is overseen by our Chief Security Officer.
−Removed: This risk assessment is a review of internal and external threats that evaluates changes to the information risk landscape to inform the investments and program enhancements to be made in the future to rapidly respond and recover from potential attacks, including rebuild and recovery protocols for key systems.
−Removed: We evaluate our enterprise information security risk to address unexpected or unforeseen changes in the risk environment or our systems and the resulting impacts are communicated to the Company’s overall enterprise risk management program.
−Removed: We believe our Chief Digital and Technology Officer and our Chief Security Officer have the appropriate knowledge and expertise to effectively manage our cybersecurity program.
−Removed: The Chief Digital and Technology Officer has experience leading enterprise digital transformation efforts for a large multinational corporation and held several leadership and growth positions at a global technology consulting and services firm before joining UnitedHealth Group.
−Removed: Our Chief Security Officer has more than 30 years of experience as a security professional in both the private and public sectors, including in law enforcement.
−Removed: Prior to joining UnitedHealth Group, he served in security leadership roles at several large multinational corporations and has additionally served on cybersecurity advisory boards for some of the largest corporations in the country.
+Added: We also engage external cybersecurity and audit firms to provide an evaluation of the program’s maturity.
+Added: Enterprise Risk Assessment
+Added: As part of the overall enterprise cybersecurity risk management program, we complete regular enterprise information risk assessments.
+Added: Overseen by the CSO, these assessments address unexpected or unforeseen changes in the risk environment by reviewing internal and external threats and evaluating changes to the cybersecurity risk landscape.
+Added: The results of these assessments inform future investments and program enhancements and are communicated as part of the Company’s broader enterprise risk management program.
+Added: Engagement with Third-Party Experts
+Added: In addition to in-house cybersecurity capabilities, the Company engages assessors, consultants, and other third parties to assist with a range of cybersecurity matters, including red team testing, auditing, and strategic advisory services.
+Added: Leadership and Governance
+Added: Management of UnitedHealth Group’s cybersecurity risks is overseen by the CSO and CDTO .
+Added: Our CSO brings more than 30 years of experience in security roles across private and public sectors, including law enforcement and leadership positions at major multinational corporations.
+Added: Our CDTO has been with the Company for more than two decades, holding leadership roles in finance, operations and technology, and has previously served as chief information officer for UnitedHealthcare and several of our Optum businesses.
+Added: Together, the CSO and CDTO co-chair UnitedHealth Group’s Enterprise Security Council, which oversees the security team’s work and includes the Chief Compliance Officer, the Chief Legal Officer, the Chief Audit Executive, the Chief Privacy Officer, and senior business executives.
+Added: Board Oversight
+Added: The Board of Directors has delegated to the Audit and Finance Committee primary responsibility for overseeing the Company’s risk management and compliance programs related to cybersecurity, data protection, and privacy.
+Added: The Audit and Finance Committee receives regular updates from the CSO and CDTO on critical cybersecurity risks, strategy, supplier risk, and business continuity.
+Added: The Audit and Finance Committee has also engaged a leading cybersecurity incident and response firm to advise on and strengthen oversight of these matters.
As of December 31, 2025, the Company has not identified any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect the Company, including our business strategy, results of operations or financial condition, but there can be no assurance that any such risk will not materially affect the Company in the future.
−Removed: For further information about the cybersecurity risks we face, and potential impacts, see Part I, Item 1A, “Risk Factors.”
+Added: For further information about the cybersecurity risks we face, and potential impacts of such risks, see Part I, Item 1A, “Risk Factors.”
We own and lease real properties to support our business operations in the United States and other countries.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.