Court Sets Tight Security for Change Health's Stolen Data
A federal judge approved a protective order for Change Healthcare’s stolen data in a multidistrict class action tied to its Feb. 2024 ransomware attack. The order requires largely offline, encrypted handling, chain-of-custody logs, breach reporting, limits on copying, and destruction within 30 days after case resolution. The attack affected 193 million people, according to court documents.
How this was made
The 30-second read
Why it matters
A magistrate judge approved a stipulated protective order requiring largely offline forensic handling of the stolen dataset, including encryption, air-gapping, chain-of-custody logs, breach reporting, and eventual destruction.
Market read
This is a procedural court development that tightens security controls for stolen-data discovery in the ongoing litigation, with limited direct implications for near-term earnings but some relevance to cyber/legal risk perception.
What to watch
The order could reduce the chance of secondary data exposure during litigation, which may lower reputational and regulatory risk even if it increases procedural burden.
Background
The article covers a multidistrict class action tied to Change Healthcare’s February 2024 ransomware attack (BlackCat/ALPHV) that affected 193 million people.
Ticker impact
A federal judge approved a protective order governing how UnitedHealth and its units handle the stolen Change Healthcare dataset in the 2024 cyberattack class action.
Low likelihood of a sustained UNH-specific move; any reaction would be sentiment-driven around cyber/legal risk rather than fundamentals.
The article describes procedural security requirements (encryption, air-gapping, chain-of-custody, destruction) for discovery material, with no new damages, settlement, or business disruption details beyond the already-known 2024 incident.
Market effects
Highlights heightened discovery and handling standards for healthcare cyber incidents, potentially increasing legal and compliance costs across health insurers and providers.
Primarily US litigation process, with limited direct regional market spillover.
Cyber incident litigation practices may influence cross-border privacy and security expectations, but the immediate effect is US-focused.
Counterpoint
Because the order is about how plaintiffs’ counsel can handle already-stolen data, it may not change UNH’s expected liability or operational risk materially.
Key entities
- company unitChange Healthcare
Technology services unit involved in the 2024 ransomware incident and the subject of the class action discovery protective order.
- companyUnitedHealth Group
Named defendant whose units (UnitedHealthcare Services, Optum, Change Healthcare) must comply with the protective order.
- threat actorBlackCat (ALPHV)
Ransomware gang blamed for the February 2024 attack that generated the stolen dataset.
- judicial officialDulce Foster
U.S. magistrate judge who approved the protective order in the District of Minnesota MDL.



