Court Mandates Strict Security for Change Healthcare's Stolen Data in Litigation
A federal judge has imposed stringent security protocols on how plaintiffs' attorneys and experts must handle data stolen from Change Healthcare during a 2024 cyberattack that impacted 193 million individuals.

A federal judge has mandated rigorous security measures for the handling of sensitive data stolen from Change Healthcare during a massive cyberattack in February 2024. The order, approved by U.S. Magistrate Judge Dulce Foster, dictates the strict protocols that plaintiffs' attorneys and their designated experts must follow when examining a copy of the compromised data as part of ongoing class action litigation.
The multidistrict litigation consolidates over 150 lawsuits filed by patients and healthcare providers alleging negligence and consumer protection violations following the ransomware attack attributed to the BlackCat gang (also known as Alphv). This attack significantly disrupted Change Healthcare, a unit of UnitedHealth Group, for months, impacting approximately 193 million individuals.
The court's stipulated protective order classifies the "impacted data files" as "designated discovery material," requiring "heightened security precautions" due to the presence of personally identifiable information (PII) and protected health information (PHI). The order aims to prevent further compromise of this highly sensitive data.
Under the new security requirements, the data can only be examined in a tightly controlled, largely offline forensic environment. Change Healthcare and its parent companies are permitted to produce only a single copy of the complete stolen dataset. This data must be transferred on an encrypted external hard drive compliant with FIPS 140-2 or 140-3 standards. The plaintiffs' expert must further encrypt the data using AES-256 or an equivalent industry-standard method.
Crucially, hard drives containing the stolen data can only be connected to computers that are air-gapped and physically isolated from the internet and all networks while the drives are attached. Wireless and Bluetooth capabilities must be disabled, and mobile phones or other external storage devices are prohibited from being connected during analysis.
Access to the data requires strong, unique passwords, delivered separately from the data itself. These passwords must be at least 16 characters long and include a mix of uppercase and lowercase letters, numbers, and special characters. The computers used for analysis must be newly provisioned, hardened, and fully patched before the first connection of a drive containing the data.
Chain-of-custody documentation is also a key component of the order, requiring a log to track who transferred and received custody, along with dates, times, locations, and drive serial numbers. Any security incidents involving the dataset will trigger additional reporting obligations to the defendants, including prompt written notice of unauthorized access, use, or disclosure.
While plaintiffs and their experts are prohibited from making additional copies of the complete dataset, they are allowed to create excerpts containing PII or PHI for up to 25 individuals. These excerpts must also be transmitted on encrypted, FIPS-compliant hard drives, further underscoring the court's commitment to safeguarding the compromised information throughout the litigation process.