A federal magistrate judge has approved security measures so strict they treat stolen data like a live weapon. The protective order in the Change Healthcare litigation offers a guide for handling compromised datasets as litigation evidence. Your incident response and legal teams should study this now, before you need it.
What Happened
Change Healthcare faced a ransomware attack by the BlackCat gang in February 2024. The breach exposed protected health information for 193 million individuals and disrupted claims processing for months. UnitedHealth paid a $22 million cryptocurrency ransom.
Now, over 150 consolidated class action lawsuits require plaintiffs' attorneys and their experts to examine the stolen dataset. However, the court mandates that this examination occur under stringent conditions.
The Security Framework
The protective order approved by U.S. Magistrate Judge Dulce Foster sets requirements that exceed typical discovery protocols:
Data transfer: Change Healthcare can produce one complete copy of the stolen dataset to plaintiffs and one to their expert. Transfer must occur on external hard drives compliant with FIPS 140-2 or FIPS 140-3.
Encryption: AES-256 or equivalent encryption is mandatory.
Air-gapping: Hard drives can connect only to computers physically isolated from the internet and other networks while the drives are attached.
Device hardening: Analysis computers must be newly provisioned, fully patched, and hardened before first connection. Wireless and Bluetooth must be disabled. No mobile phones, network cables, or external storage devices can be connected during use.
Physical security: Drives must be stored in locked, secure locations with physical access controls when not in use or transport.
Chain of custody: A log must accompany each drive, recording who transferred and received custody, date, time, location, and drive serial number. Defendants receive this documentation whenever custody changes.
Access controls: Passwords must contain at least 16 characters with uppercase, lowercase, numbers, and special characters. Passwords must be delivered separately from the data.
Breach reporting: Written notice to defendants is required within two days of discovering unauthorized access, use, disclosure, or any HIPAA-defined security incident.
Mandatory destruction: Within 30 days after litigation ends, all copies must be destroyed using a three-pass overwrite compliant with NIST SP 800-88, or the media must be physically destroyed.
Which Controls Failed or Were Missing
The court order doesn't specify Change Healthcare's original security failures, but the attack's scope suggests key issues. BlackCat accessed systems containing 193 million individuals' protected health information, which should have been segmented, encrypted at rest, and monitored for unauthorized access.
The prolonged disruption indicates attackers moved laterally through interconnected systems. Claims processing and other operations relied on infrastructure that wasn't adequately segmented or resilient.
The $22 million ransom payment suggests UnitedHealth either lacked viable backups or couldn't restore operations quickly enough. This points to inadequate business continuity planning.
What the Standards Require
PCI DSS Requirement 1.3.1 mandates network segmentation to isolate the cardholder data environment from untrusted networks. This principle also applies to protected health information, segment sensitive data from general business systems.
HIPAA Security Rule §164.312(a)(2)(iv) requires encryption of electronic protected health information. The court's mandate for AES-256 encryption reflects what should have protected it initially.
NIST SP 800-88 provides media sanitization guidelines. The court's requirement for three-pass overwrites or physical destruction is a standard your team should apply when decommissioning storage containing sensitive data.
FIPS 140-3 establishes cryptographic module security requirements. The court's insistence on FIPS-compliant drives for data transfer sets a baseline your organization should use for any sensitive data movement.
The air-gapping requirement, while not directly regulatory, reflects a fundamental security principle: if you can't trust the network, remove the network. Your incident response plan should include procedures for isolating compromised systems and analyzing forensic evidence on air-gapped workstations.
Lessons and Action Items
Build your litigation security protocol now. Don't wait until you're under time pressure. Work with legal counsel to draft security requirements for handling compromised data in discovery. Use this court order as a template, but adapt it to your environment and data types.
Test your segmentation. If attackers breach one system, can they reach your most sensitive data? Conduct annual segmentation testing to ensure network controls isolate critical assets. Document the results and address any gaps before the next assessment.
Encrypt data at rest. If your sensitive data isn't encrypted using AES-256 or equivalent, you're risking that perimeter controls will never fail. Implement encryption now, before you're explaining to a judge why you didn't.
Prepare air-gapped forensic workstations. Your incident response toolkit should include hardened, network-isolated machines for analyzing compromised systems and data. Provision them in advance, patch them quarterly, and document chain of custody procedures for investigations.
Document your data destruction procedures. NIST SP 800-88 compliance is essential when decommissioning storage devices. Establish written procedures for three-pass overwrites or physical destruction, train your IT team, and maintain destruction certificates. You'll need that documentation in litigation.
Review your backup and recovery capabilities. UnitedHealth paid $22 million because restoration wasn't fast enough. Test your backups monthly. Measure your recovery time objectives against realistic attack scenarios. If you can't restore critical systems within hours, you're vulnerable to ransom demands.
Limit dataset copies. The court allowed exactly one complete copy to plaintiffs and one to their expert. Apply the same principle internally, minimize the number of sensitive data copies in your environment. Every copy is another attack surface.
The Change Healthcare protective order isn't just about managing litigation risk. It's a preview of how courts will treat organizations that fail to protect sensitive data before a breach. Implement these controls now, while you still control the timeline.



