Court Orders Strict Safeguards for Change Healthcare Stolen Data in Litigation
What Happened — A U.S. magistrate judge approved a protective order that obliges plaintiffs’ counsel and their designated experts to handle the Change Healthcare breach dataset (193 million records) under “heightened security precautions.” The order mandates FIPS‑140‑2/3 encrypted external drives, AES‑256 encryption, air‑gapped workstations, physical controls, chain‑of‑custody logs, breach reporting, and mandatory destruction after review.
Why It Matters for Trust & Control Assurance
- Demonstrates how a court‑mandated protective order forces organizations to prove data‑protection controls (encryption, air‑gap, chain‑of‑custody) with auditable evidence.
- Highlights the need for a continuous control‑assurance program that can capture, monitor, and report on these safeguards in real time.
- Provides a concrete test case for the Control Mapping capability: mapping encryption, isolation, and disposal controls to multiple frameworks (e.g., NIST CSF Protect, ISO 27001, HIPAA).
Who Is Affected – Healthcare providers, insurers, and any entity that may receive or store compromised PHI/PII as part of litigation or breach‑response activities; legal teams handling breach‑related discovery.
Recommended Actions – Map your current data‑protection controls to the Verisq Trust Center, verify encryption meets FIPS‑140‑2/3 standards, implement air‑gap procedures, maintain immutable chain‑of‑custody logs, and document destruction timelines.
Technical Notes – The dataset stems from the February 2024 BlackCat (AlphV) ransomware attack on Change Healthcare, exposing personally identifiable information and protected health information. The protective order limits distribution to a single copy, transferred on an encrypted external hard drive, and requires offline forensic analysis. Source: DataBreachToday