HomeMalware & ThreatsCourt Establishes Strict Security Measures for Change Health's Stolen Data

Court Establishes Strict Security Measures for Change Health’s Stolen Data

Published on

spot_img

Data Privacy,
Data Security,
Fraud Management & Cybercrime

Plaintiffs, Experts Face Strict Rules for Handling Data Stolen in 2024 Attack

Court Establishes Strict Security Measures for Change Health’s Stolen Data
A federal judge has ordered strict security to protect stolen data Change Healthcare will turn over to plaintiffs in class action litigation stemming from the company’s massive 2024 cyberattack. (Image: Getty Images)

A recent ruling by a federal judge has mandated rigorous security measures for handling sensitive data that Change Healthcare is required to provide to plaintiffs in a class action lawsuit regarding a significant cyberattack that took place in 2024. This data breach has had a profound impact, affecting around 193 million individuals.

The class action litigation involves multiple lawsuits—over 150—consolidated into multidistrict litigation by patients and healthcare providers. Allegations include serious claims such as negligence, unjust enrichment, and violations of consumer protection laws. The lawsuit comes in the wake of a ransomware attack perpetrated by the BlackCat gang, also known as Alphv, which crippled Change Healthcare’s operations for several months, disrupting essential healthcare services.

Currently centralized in the U.S. District Court for the District of Minnesota, the legal proceedings have not yet set a trial date. However, on a recent Friday, U.S. Magistrate Judge Dulce Foster approved a protective order that details the security protocols for “impacted data files” that must be supplied by the defendants, including UnitedHealth Group and its affiliates like UnitedHealthcare Services, Optum, and Change Healthcare.

The stolen data, classified as “designated discovery material,” encompasses both personally identifiable information (PII) and protected health information (PHI). This classification necessitates enhanced security precautions as indicated in court documents. While plaintiffs and their designated experts will have the opportunity to examine the data obtained from the Change Healthcare breach, this examination must occur in a highly controlled, largely offline forensic environment.

The court order lays out stringent security requirements which include encryption, air-gapping (the physical isolation of the data systems), device hardening, and detailed chain-of-custody documentation to ensure that the highly sensitive information is safeguarded against further compromise. These measures are critical to protecting the sensitive health and identity data that has fallen into the wrong hands.

Importantly, the defendants can only produce a single complete copy of the stolen dataset to either the plaintiffs or their designated expert. This data must be transferred via an encrypted external hard drive that adheres to Federal Information Processing Standards (FIPS) 140-2 or 140-3. The plaintiffs’ expert is also required to encrypt the dataset using AES-256 or equivalent encryption standards.

Furthermore, hard drives that carry the stolen data must only connect to computers that are air-gapped during their usage. This means these computers will have no internet or network access while the drives are attached. The security order specifies that all hard drives utilized for storing the impacted data will be disconnected and securely stored when not in active use, with physical access controls implemented to monitor who can access those secure locations.

The plaintiffs, along with their experts, are prohibited from copying the entire set of stolen files; however, they are allowed to create excerpts containing PII or PHI for up to 25 individuals. These excerpts must also follow stringent security protocols during transmission, ensuring that the data remains encrypted and secure.

In addition to these security measures, any potential security incidents involving the dataset will initiate additional obligations. Plaintiffs must promptly report any unauthorized access or HIPAA-defined security incidents to the defendants. Following a breach, written notification must be provided within two days, enumerating details regarding the breach and the parties affected, along with any mitigating measures taken.

The need for careful management of the dataset includes preventing its use to identify or recruit additional plaintiffs for the litigation. The court order imposes strict limitations on who can access the information, specifying that attorneys, experts, and other involved parties cannot utilize this sensitive data to solicit further participation in the legal proceedings.

The court has established that due to the exceptional volume and sensitivity of the information involved, the dataset will be treated differently than other documents in the litigation. It will not be included in the broader document repository accessible to plaintiffs, ensuring that it receives special handling due to its critical nature.

Lastly, upon the conclusion of the litigation or the dismissal of plaintiffs’ claims, the order stipulates that all copies of the stolen dataset must be destroyed within 30 days. Electronic data must be securely wiped following rigorous guidelines, including a three-pass overwrite compliant with NIST SP 800-88, or otherwise, the physical media must be destroyed completely through shredding or incineration. Lead counsel for the plaintiffs must certify the destruction under penalty of perjury.

This approach exemplifies the nation’s increasing focus on data security, particularly in light of significant breaches that jeopardize the privacy and integrity of millions. Following the cyberattack involving over 193 million individuals’ PHI and subsequent operational chaos for numerous medical facilities, Change Healthcare reportedly paid a ransom of $22 million in cryptocurrency to recover the stolen data. However, as the legal proceedings continue, stakeholders remain vigilant about the handling of this sensitive information.

Neither parties involved have commented on the recent court order. The implications of this case are vast, highlighting the urgent need for rigorous security protocols in the handling of sensitive healthcare data in an age where cyber threats are relentlessly evolving.

Source link

Latest articles

OpenAI Introduces GPT-5.6-Cyber as AI Shortens Vulnerability Response Time

Governance for High-Risk Cyber AI: A Comprehensive Approach for Enterprises In the face of advancing...

GitHub Already Has an EDR; You Just Need to Pay Attention to It

An Overview of the GitHub Threat Detector: Insights from Recent Supply-Chain Attacks Recent investigations into...

Building Cyber-Resilient AI in the Enterprise

Rapid Growth of Enterprise AI Faces Security Challenges Enterprise AI deployments are currently experiencing unprecedented...

More like this

OpenAI Introduces GPT-5.6-Cyber as AI Shortens Vulnerability Response Time

Governance for High-Risk Cyber AI: A Comprehensive Approach for Enterprises In the face of advancing...

GitHub Already Has an EDR; You Just Need to Pay Attention to It

An Overview of the GitHub Threat Detector: Insights from Recent Supply-Chain Attacks Recent investigations into...