A US federal court has imposed strict security requirements on plaintiffs and their experts who will receive and analyze data stolen during the 2024 Change Healthcare ransomware attack.

 

What happened

According to GovInfoSecurity, U.S. Magistrate Judge Dulce Foster approved a stipulated protective order governing how Change Healthcare, UnitedHealth Group, and related companies must provide the stolen data to attorneys representing plaintiffs in the multidistrict litigation.

Under the order, plaintiffs and their designated experts may examine the compromised data, but only within a tightly controlled environment. Change Healthcare is permitted to provide no more than one complete copy of the stolen dataset to the plaintiffs or their designated expert. The measures are intended to prevent sensitive patient information from being exposed again while the data is reviewed as part of the ongoing litigation.

 

The backstory

In February 2024, Change Healthcare, a major healthcare technology and claims-processing company owned by UnitedHealth Group, suffered a ransomware attack that disrupted healthcare payments and claims processing across the United States. The attackers also stole sensitive information, including protected health information (PHI) and personally identifiable information (PII).

The incident became one of the largest healthcare data breaches in US history. Change Healthcare initially reported a much smaller number of affected individuals, but the figure continued to rise as the company investigated the incident. In July 2025, Change Healthcare notified the U.S. Department of Health and Human Services that approximately 192.7 million individuals had been affected.

The breach also triggered widespread operational disruption because Change Healthcare processes healthcare transactions between providers, insurers, and other organizations. The incident resulted in lawsuits from affected individuals and organizations, eventually leading to multidistrict litigation.

Read also: Going deeper: The Change Healthcare attack

 

Going deeper

The court order places strict controls on how the stolen Change Healthcare data can be transferred, stored, and examined. Because the files contain PII and PHI, the court classified them asdesignated discovery materialrequiring heightened security precautions.

One requirement of the court order is that Change Healthcare and the other defendants may provide only one complete copy of the stolen dataset to the plaintiffs or their designated expert. The dataset must be transferred using an encrypted external hard drive that complies with Federal Information Processing Standards (FIPS) 140-2 or 140-3. Once received, the plaintiffs’ expert must also encrypt the information using AES-256 or an equivalent industry-standard encryption method.

The court also requires the data to be examined in a largely offline environment. Computers used to access the dataset must be newly provisioned, hardened, and fully patched before the data is connected. While the stolen data is being accessed, those computers must be physically isolated from the internet, other networks, and other computer systems. Wireless and Bluetooth capabilities must be disabled, while mobile phones, network cables, and additional storage devices cannot be connected.

The order also sets rules for storing the hard drives, noting that when they are not in use or being transported, they must be kept in a locked, secure location. Access to those locations must be controlled and tracked. A chain-of-custody log must also accompany each drive, documenting who transferred or received it, the date and time, the location, and the drive's serial number.

The restrictions also limit how much of the stolen information can be reproduced. Plaintiffs and their experts cannot make another complete copy of the dataset. They may create smaller excerpts containing PII or PHI, but those excerpts generally cannot contain information relating to more than 25 individuals. These excerpts must also be encrypted when transferred.

The court has also established specific requirements in the event of another security incident. Any unauthorized access, use, or disclosure of the dataset, as well as HIPAA-defined security incidents, must be reported to the defendants without unreasonable delay and no later than two days after discovery. The notification must include available information about the incident, the affected data and individuals, those responsible, and the mitigation and corrective measures taken. A suspected breach could also lead to an independent forensic investigation by a third-party firm jointly selected by the plaintiffs and defendants. If plaintiffs’ counsel or their experts were responsible for the incident, plaintiffs’ counsel would presumptively be responsible for the investigation costs, subject to the terms of the order.

The order further prevents the stolen data from being used to identify or recruit additional plaintiffs. Attorneys, experts, vendors, and others with access cannot use information in the dataset to identify, contact, solicit, or recruit people for the litigation or other legal proceedings. Given the volume and sensitivity of the information, the dataset will also be kept separate from the broader document repository used by plaintiffs in the case.

The security requirements will also remain in place after the case ends. Once the litigation is over, all copies, excerpts, and other versions of the stolen data must be securely destroyed. The destruction must also be certified, helping ensure the information does not remain in circulation after it is no longer needed for the case.

 

What was said

The court order described the compromised files asdesignated discovery materialcontaining PII and PHI that requireheightened security precautions.This information should be treated asDesignated Discovery Material pursuant to the terms of the Protective Order and Qualified HIPAA Protective Order (ECF No. 271) (PTO 10) entered into in this litigation.

The strict requirements reflect the scale and sensitivity of the information involved. However, neither the attorneys representing the plaintiffs nor Change Healthcare and the other defendants immediately responded to GovInfoSecurity's request for comment.

According to Gov Info Security, the U.S. Department of Health and Human Services (HHS) has previously described the Change Healthcare attack as unprecedented in scale, noting its widespread effect on patients and healthcare providers. HHS said Change Healthcare reported approximately 192.7 million affected individuals as of July 2025.

 

Why it matters

The order specifically recognizes the exceptional sensitivity and volume of the information. It prevents the stolen dataset from being placed in the broader document repository available to plaintiffs in the litigation.

Additionally, the court order shows that the risks associated with a major data breach can continue long after the initial cyberattack. Even when stolen data is being handled for legitimate purposes, strict controls may be needed to prevent another exposure.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQS

What is multidistrict litigation?

Multidistrict litigation, or MDL, is a process used by US federal courts to consolidate similar lawsuits involving common questions of fact. The cases are coordinated during pretrial proceedings.

 

Why does the court order include so many security requirements?

The dataset contains highly sensitive health and personal information affecting millions of people. The safeguards are intended to reduce the risk of the data being exposed again while it is being used as evidence.