Court Sets Strict Security for Change Health's Stolen Data
A federal judge approved a protective order for Change Healthcare’s stolen dataset in consolidated class actions over its Feb. 2024 cyberattack that affected 193 million people, according to court documents. Plaintiffs’ counsel and experts must handle the data in largely offline, encrypted, air-gapped forensic conditions, limit copies, document chain of custody, report incidents, and destroy data after the case. UnitedHealth Group and units include Change Healthcare and Optum.
How this was made
The 30-second read
Why it matters
The protective order imposes strict controls (encryption, air-gapping, chain-of-custody, limited copying, and destruction requirements) for plaintiffs’ counsel and designated experts reviewing the stolen PHI/PII. It also adds breach reporting and potential third-party forensic investigation triggers.
Market read
This is a litigation procedure update that can affect compliance and process risk, but it does not disclose new financial terms or operational guidance.
What to watch
Potential cost and timeline impacts from forensic handling, chain-of-custody documentation, and breach-notification obligations could matter more than the headline suggests, even without new settlement terms.
Background
The article describes a multidistrict class action tied to Change Healthcare’s February 2024 ransomware attack, affecting 193 million people, and focuses on a court-approved protective order for handling the stolen dataset.
Ticker impact
A federal judge approved a protective order governing how UnitedHealth and its units handle the stolen Change Healthcare dataset in the 2024 cyberattack class action.
Limited near-term impact; any effect is likely indirect via litigation risk and compliance costs rather than a new financial disclosure.
The article is procedural (protective order) and does not introduce new damages, settlements, or guidance. It does, however, constrain how defendants and experts can access and copy the dataset, which can affect litigation process and potential incident exposure.
Market effects
Highlights heightened legal and security compliance expectations for healthcare payers and health IT providers facing large-scale ransomware incidents.
Primarily U.S. litigation process in the District of Minnesota; limited direct regional market effect.
Sets a precedent-like standard for handling stolen health data in U.S. multidistrict litigation, relevant to global healthcare cyber risk management.
Counterpoint
Because the order is about plaintiffs' and experts' handling of already-stolen data, it may not materially change Change Healthcare or UnitedHealth’s underlying cyber exposure or financial outcomes.
Key entities
- companyUnitedHealth Group
Defendant in the multidistrict litigation; its units include United HealthCare Services, Optum, and Change Healthcare.
- companyChange Healthcare
Healthcare technology services unit whose 2024 ransomware incident generated the stolen dataset at issue.
- threat_actorBlackCat (Alphv)
Ransomware gang blamed for the February 2024 attack and theft of the dataset.
- judgeDulce Foster
U.S. magistrate judge who approved the stipulated protective order.



