Stolen Change Healthcare data gets new handling rules in court order

In Data Breach News, Legal News, News
August 11, 2026

Becker’s Health IT reports:

A federal judge in Minnesota has signed off on a strict set of rules for how the data stolen in Change Healthcare’s 2024 cyberattack can be handled during the ongoing lawsuit.

[…]

Here’s what the rules actually require:

  • UnitedHealth can hand over only one copy of the full stolen dataset. It has to go on a specific type of secure, encrypted hard drive built to a federal security standard.
  • Once they have the data, plaintiffs’ lawyers or their expert must encrypt it again using a strong, industry-standard method. UnitedHealth has to send the password separately from the drive, not with it.
  • The only computers allowed to touch that hard drive must be completely disconnected from the internet and every other network while the drive is plugged in. Those computers have to be freshly set up and fully updated first, with Wi-Fi and Bluetooth turned off. No phones, cables or other storage devices allowed nearby while they’re working with the data.

Read the rest of the rules at Becker’s Health IT.