Strict Security Protocols Established for Handling Stolen Data in Change Healthcare Cyberattack
A recent court decision has imposed rigorous security measures on how attorneys and experts involved in litigation against Change Healthcare must manage a treasure trove of stolen data, stemming from a significant cyberattack that occurred in February 2024. This federal judge’s ruling targets the protection of sensitive information belonging to approximately 193 million individuals, and it marks an important step in the ongoing legal proceedings related to the attack.
The case revolves around a ransomware attack executed by the cybercrime group BlackCat, also known as Alphv, which severely disrupted operations at Change Healthcare, a technology division of UnitedHealth Group. The ramifications of this breach were extensive, affecting not only the company’s internal processes but also the services provided to countless patients and healthcare providers across the United States.
As part of the class action lawsuit, over 150 claims have been consolidated, alleging various forms of misconduct including negligence, unjust enrichment, and violations of consumer protection laws. The complexities of these legal challenges necessitated a protective order to govern how the affected data files will be treated, highlighting the court’s recognition of the sensitive nature of the information involved.
On August 7, 2026, U.S. Magistrate Judge Dulce Foster approved a stipulated protective order that outlines stringent protocols governing the use of the "impacted data files." These files consist of personally identifiable information (PII) and protected health information (PHI), mandating a heightened level of security. Under the court’s ruling, only one copy of the complete stolen dataset can be provided to either the plaintiffs or their designated experts, and that copy must be transferred on an encrypted hard drive meeting Federal Information Processing Standards (FIPS) requirements.
Scrutiny of the handling process extends to how the data will be analyzed. Only devices that have been subjected to stringent security measures—including being physically isolated from the internet—will be permitted to connect to the drives containing the stolen data. In addition, the data must be stored in secured locations with strict access controls, ensuring that unauthorized individuals do not gain access.
Another pivotal aspect of the order involves the prevention of unauthorized duplication of sensitive information. While excerpts can be created for the analysis—provided they don’t contain information regarding more than 25 individuals—full copies of the dataset are strictly prohibited. This aligns with the court’s aim to mitigate the potential for further data breaches and unauthorized access.
Furthermore, the order underscores the importance of maintaining a detailed chain of custody for the hard drives that store the stolen information. Each transfer of custody must be documented, including details such as who transferred and received the drives, as well as relevant timestamps and serial numbers. This meticulous record-keeping is designed to ensure accountability at every step of the handling process.
Should any security incidents occur, the plaintiffs are obligated to inform the defendants without undue delay, ideally within two days. This prompt notification requirement is essential for fostering transparent communication and collaborative response efforts, potentially involving independent investigations into any breaches that may arise.
Importantly, the ruling prohibits using the stolen data to identify additional plaintiffs or solicit involvement in the case, further establishing boundaries regarding the ethical use of the information. The dataset will not be treated like other documents within the broader repository of evidence, instead receiving special treatment due to its sensitive nature.
The conclusion of the litigation will also trigger the mandatory destruction of all copies and derivatives of the stolen data within 30 days. This destruction must be thorough—electronic records will undergo secure wiping protocols, while physical media will be shredded, degaussed, or incinerated. Lead counsel will then be required to certify this destruction, under penalty of perjury.
The decision comes in light of a significant breach that affected the healthcare sector at large, leading to prolonged outages and disruptions in numerous medical establishments. UnitedHealth Group’s reported payment of a $22 million ransom in cryptocurrency to recover the data underscores the high stakes involved in such cyberattacks.
Severe repercussions of the BlackCat cyberattack are evident, highlighting the vulnerabilities faced in today’s digital landscape. While this legal proceeding unfolds, it will also serve as a critical case study in data privacy laws, emphasizing the responsibilities organizations owe to their clients and the stringent measures that must be imposed to protect sensitive information.
Neither parties involved have commented directly on the protective order as the situation continues to evolve, yet the ruling undeniably sets a major precedent for how stolen data will be handled in future litigation involving similar breaches.

