Court locks down handling of Change Healthcare’s 190 million-person dataset

A federal magistrate approved a protective order dictating how lawyers may handle the 6 TB of patient data stolen from Change Healthcare.

MedRisk Staff
By
2 Min Read

A federal court has imposed strict handling rules on the roughly 6 TB of patient data stolen from Change Healthcare in its 2024 ransomware attack, the largest healthcare breach on record.

Magistrate Judge Dulce Foster approved a stipulated protective order in the multidistrict litigation consolidated in the U.S. District Court for the District of Minnesota, covering the electronic protected health information of an estimated 192.7 million people, including names, Social Security numbers, driver’s license numbers, and medical records.

Under the order, UnitedHealth Group, Change Healthcare, Optum, and other subsidiaries will provide plaintiffs’ attorneys with a single copy of the data on an encrypted hard drive built to a federal security standard. The decryption key is delivered separately, so the data cannot be read if the drive is lost or stolen. Attorneys must re-encrypt the dataset with industry-standard encryption on receipt, and no copies may be made.

Plaintiffs’ counsel approved the rules, and a cybersecurity expert verified the security measures before the judge signed off. The protections reflect both the volume and sensitivity of the stolen files.

The attack triggered the $22 million ransom payment to the BlackCat group, whose affiliate kept a copy of the data and later joined RansomHub for a second extortion attempt. More than 150 lawsuits are now consolidated in the Minnesota action, including consumer class actions and provider claims over operational disruption.

Share This Article