Data Privacy
,
Data Security
,
Fraud Management & Cybercrime
Plaintiffs, Experts Face Strict Rules for Handling Data Stolen in 2024 Attack

A federal judge last week approved stringent security requirements on how plaintiffs’ attorneys and experts must safeguard a copy of a massive cache of stolen data that Change Healthcare will turn over in class action litigation involving the company’s 2024 cyberattack that affected 193 million people.
See Also: The Unstructured Data Blindspot: Why Your Most Valuable Assets Are Your Least Protected
The multidistrict litigation consolidates more than 150 proposed class action lawsuits filed by patients and healthcare providers alleging an assortment of claims, including negligence, unjust enrichment and consumer protection violations. The incident, stemming from the February 2024 ransomware attack by the BlackCat gang – also known as Alphv – disrupted operations at Change Healthcare, a technology services unit of UnitedHealth Group, for months.
A trial date has not yet been set for the case, which is centralized in the U.S. District Court for the District of Minnesota.
But on Friday, a U.S. magistrate judge in the case, Dulce Foster approved a stipulated protective order covering the “impacted data files” that defendants UnitedHealth Group and its various companies – United HealthCare Services, Optum and Change Healthcare – have been ordered to provide to plaintiffs’ counsel and their designated expert in the litigation.
The compromised data files – which are being treated as “designated discovery material” – contain personally identifiable information and protected health information and require “heightened security precautions,” according to court documents.
The order allows plaintiffs and their designated expert to examine the data stolen in the Change Healthcare attack, but under a tightly controlled, largely offline forensic environment.
The security requirements include encryption, air-gapping, device hardening, physical controls, chain-of-custody records, breach reporting and mandatory destruction to reduce the risk that highly sensitive stolen health and identity information could be compromised again.
Under the order, Change Healthcare and the other defendants can produce no more than a single copy of the complete stolen dataset to either the plaintiffs or the expert they designate in writing. The data must be transferred on an encrypted external hard drive compliant with Federal Information Processing Standards 140-2 or 140-3.
The plaintiffs’ expert also must encrypt the data using AES-256 or an equivalent industry-standard encryption method.
Hard drives containing the stolen data can be connected only to computers that are air-gapped while the drives are attached. During that time, the computers must be physically isolated from the internet, networks, other systems and other computers.
The order doesn’t require the data to be housed in one central physical location. Instead, it establishes security requirements governing where and how the data can be stored and accessed.
“All hard drives used by the plaintiffs or plaintiffs’ expert to store the impacted data files and related documents will be disconnected and stored in locked, secure locations whenever not in active use or transport with physical access controls in place to manage and track access to such secure locations,” the order said.
The plaintiffs and their experts are prohibited from making another copy of the complete set of stolen files. But they can create excerpts containing PII or PHI involving no more than 25 people.
Excerpts containing PII or PHI generally must be transmitted on FIPS 140-2 or 140-3 compliant hard drives, encrypted using AES-256 or an equivalent method, the order said.
Access requires strong, unique passwords delivered separately from the data. Those passwords must contain at least 16 characters and include uppercase and lowercase characters, a number and a special character.
The computers used to analyze the data must be newly provisioned, hardened and fully patched before a drive containing the data is connected for the first time. Wireless and Bluetooth capabilities must be disabled, and mobile phones, network cables and other external storage devices cannot be connected while the machines are being used with the stolen data, the order said.
Under the order, the chain of custody also must be documented. A log must accompany each drive and record who transferred and received custody, the date and time, location and drive serial number. Defendants receive the documentation whenever custody changes and upon reasonable request.
Other Requirements
The order also specifies that any security incidents involving the dataset will also trigger additional obligations.
The plaintiffs must report to the defendants unauthorized access, use or disclosure and HIPAA-defined security incidents. Following the discovery of a breach, written notice to defendants is required “without unreasonable delay,” and no later than two days. The notification must provide available details about the breach, affected data and individuals, responsible parties, mitigation and corrective measures.
Under the order, a suspected breach can also trigger an independent forensic investigation by a third-party firm jointly selected by plaintiffs and defendants. If plaintiffs’ counsel or experts are responsible for the incident, plaintiffs’ counsel presumptively bears the associated costs, although that presumption can be rebutted, the order said.
The data also can’t be used to find or identify additional plaintiffs. The order expressly prohibits plaintiffs, lawyers, experts, vendors and others with access from using the information in the stolen files to identify, contact, solicit or recruit people to participate in the litigation or other legal proceedings.
The stolen dataset also gets special treatment within the multidistrict litigation, “given the volume and sensitivity of certain personal information,” the order said. Unlike other produced documents, the dataset will not be placed in the broader document repository available to plaintiffs in the litigation.
Finally, the data must ultimately be destroyed. Within 30 days after the litigation ends, plaintiffs’ claims are dismissed with prejudice, or the parties otherwise agree in writing, plaintiffs and their expert must destroy all copies, excerpts and derivatives of the stolen dataset.
Electronic data must be securely wiped using at least a three-pass overwrite compliant with NIST SP 800-88 or the media must be physically destroyed by shredding, degaussing or incineration, the order said. Plaintiffs’ lead counsel must subsequently provide a detailed certification of destruction signed under penalty of perjury.
Neither attorneys representing the plaintiffs nor Change Healthcare and the other defendants immediately responded to ISMG’s request for comment on order.
Besides the compromise of 193 million individuals’ PHI, the Feb. 12, 2024, attack by Russian-speaking ransomware gang BlackCat resulted in Change Healthcare IT systems outages that disrupted claims processing and many other critical business operations for thousands of medical practices, clinics, pharmacies and hospitals across the U.S. for several months.
UnitedHealth reportedly paid a cryptocurrency ransom worth $22 million to the cybercriminals in exchange for a promise to delete the stolen Change Healthcare data.
