Strict data handling rules have been established for the stolen Change Healthcare dataset used as discovery material in consolidated litigation against United Health Group (UHG), Change Healthcare, Optum, and other UHG subsidiaries.
Change Healthcare Dataset Contains Sensitive Information
The 2024 ransomware attack against Change Healthcare resulted in the theft of approximately 6 terabytes of data. The stolen information includes files containing the electronic protected health information (ePHI) of an estimated 192,700,000 individuals. The data includes names, contact details, insurance information, medical information, Social Security numbers, and driver’s license numbers.
UHG paid the BlackCat ransomware group a $22 million ransom to delete the stolen data. The operators kept the payment and did not pay the affiliate, which retained a copy of the data. The affiliate later joined RansomHub, which tried to extort UHG again.
The incident resulted in dozens of lawsuits, including class action lawsuits filed by affected patients and healthcare providers seeking payment for operational and financial disruptions.
Consolidated Litigation
On June 7, 2024, 49 lawsuits (19 consumer complaints and 30 healthcare provider complaints) had been consolidated by the Judicial Panel on Multidistrict Litigation. Currently, the number of included lawsuits has grown to more than 150. The In Re: Change Healthcare, Inc. Customer Data Security Breach Litigation consolidated lawsuit was filed in the U.S. District Court for the District of Minnesota.
The stolen data files are designated discovery material. The volume of records and the sensitive nature of the information require strict security practices to protect against unauthorized access and data theft. The plaintiffs’ attorneys approved the rules governing the stolen dataset. A cybersecurity expert verified that the security measures were sufficient to protect the data before the rules were submitted to the judge for approval. Magistrate Judge Dulce Foster subsequently approved the stipulated protective order.
Encrypted Hard Drive Requirements
UHG will prepare one copy of the dataset on an encrypted hard drive following federal security standard, including HIPAA. The decryption key must be provided separately so that the data cannot be accessed if the drive is lost or stolen. After receiving the hard drive, the plaintiffs’ attorneys must encrypt the data again using industry-standard encryption. They cannot make copies of the dataset or save it to the shared file library used by individuals involved in the case. The plaintiffs’ attorneys also cannot use the dataset to identify or locate potential class members.
The hard drive may only be used with computers that are air-gapped from the Internet and all networks. The computers cannot have Wi-Fi or Bluetooth connectivity. The computers must be newly provisioned and updated before they are used to access the data. No cables, phones, or storage devices may be nearby while the computers are being used.
Data access is limited to small samples. No more than 25 people may have access at any one time. All samples must be strongly encrypted and secured by a complex password with at least 16 characters.
Audit and Destruction Requirements
The plaintiffs must maintain an audit trail for the dataset. The records must include a detailed chain of custody for the hard drive and data, and the log must be provided to UHG upon request.
Within 30 days after the case ends, or if the plaintiffs’ claims are dismissed, the data is to be securely destroyed. Destruction must use the government-approved NIST SP 800-88 data wiping method, or the hard drive must be physically destroyed. A detailed certificate of destruction must be obtained under penalty of perjury.
Security Incident Reporting
If a security incident, unauthorized data access, or unauthorized data sharing occurs, UHG must be notified within 48 hours. If the incident is determined to be a genuine security incident, both sides must engage an external digital forensic firm. If the plaintiffs are determined to be responsible for the incident, they must pay the full costs of the investigation.
