A federal judge in Minnesota has signed off on a strict set of rules for how the data stolen in Change Healthcare’s 2024 cyberattack can be handled during the ongoing lawsuit.
Magistrate Judge Dulce J. Foster approved the plan, reviewed by Becker’s, Aug. 7. It applies to the combined lawsuit against UnitedHealth Group and several of its companies, including Change Healthcare, Optum and United HealthCare Services. Both sides had already agreed to the terms before asking the judge to sign off.
The rules cover the stolen data itself, which includes patients’ personal and health information. Plaintiffs’ lawyers hired their own cybersecurity expert to review the plan, and that expert told the court the safeguards are strong enough to keep the data protected.
Here’s what the rules actually require:
- UnitedHealth can hand over only one copy of the full stolen dataset. It has to go on a specific type of secure, encrypted hard drive built to a federal security standard.
- Once they have the data, plaintiffs’ lawyers or their expert must encrypt it again using a strong, industry-standard method. UnitedHealth has to send the password separately from the drive, not with it.
- The only computers allowed to touch that hard drive must be completely disconnected from the internet and every other network while the drive is plugged in. Those computers have to be freshly set up and fully updated first, with Wi-Fi and Bluetooth turned off. No phones, cables or other storage devices allowed nearby while they’re working with the data.
- Nobody’s allowed to make a second full copy of the stolen dataset. Lawyers can pull out small samples, but only involving 25 people or fewer at a time, and those samples need the same heavy-duty encryption and a strong password (at least 16 characters, mixing upper and lower case letters, a number and a symbol).
- Every time the hard drive changes hands, someone has to write it down: who took it, who received it, when, where and the drive’s serial number. UnitedHealth gets to see that log.
- If anything goes wrong, like the data getting accessed or shared in a way it shouldn’t be, plaintiffs’ side has to tell UnitedHealth within two days of finding out. If it looks like a real security incident, both sides bring in an outside forensic firm to investigate. If it turns out to be the plaintiffs’ side’s fault, their lawyers will likely have to pay for that investigation.
- Once the case wraps up, or if the plaintiffs’ claims get thrown out, everyone has 30 days to destroy every copy of the data. Digital files get wiped using a government-approved method, or the hard drives get physically destroyed. A lawyer for the plaintiffs then has to sign a sworn statement confirming it’s done.
The order also makes clear this data can’t be used to track down or recruit more people to join the lawsuit. And because the stolen files are so sensitive, they’re being kept out of the shared file library that’s normally available to everyone involved in the case.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.