Skip to main content
Promotional banner for the pentest readiness checklist
Litigation Discovery Under Lock and Key: Air-Gapped Data Handling for Breach CasesIncident & Breach Response
6 min readFor Regulatory Affairs Professionals

Litigation Discovery Under Lock and Key: Air-Gapped Data Handling for Breach Cases

When stolen data becomes courtroom evidence, your security obligations don't end, they intensify. The protective order governing the Change Healthcare multidistrict litigation establishes a technical standard for handling 6 terabytes of stolen health records during discovery. It's a template worth studying, whether you're preparing for litigation or managing sensitive datasets that could end up in legal proceedings.

Scope: What This Guide Covers

This guide applies when your organization must produce or handle sensitive breach data during litigation. It focuses on:

  • Technical controls for air-gapped discovery environments
  • Chain-of-custody requirements for encrypted datasets
  • Incident response protocols specific to legal discovery
  • Secure destruction methods aligned with NIST SP 800-88 standards

You'll need this framework if you're a CISO preparing breach response plans, a compliance officer coordinating with legal counsel, or a security engineer building isolated analysis environments.

Key Concepts and Definitions

Air-Gapped System: A computer physically isolated from all networks, with Wi-Fi and Bluetooth disabled or removed. No internet connectivity, no local network access, no wireless capabilities.

Discovery Material: Evidence exchanged between parties during litigation. When it includes stolen data from a breach, it carries dual obligations, legal discovery requirements and data protection mandates.

Designated Counsel: Attorneys specifically authorized under a protective order to access sensitive discovery material, subject to technical and procedural restrictions.

NIST SP 800-88: Guidelines for Media Sanitization, specifying methods for secure data destruction that render recovery infeasible using state-of-the-art laboratory techniques.

Requirements Breakdown

Physical Isolation Controls

The Change Healthcare protective order requires newly provisioned computers, updated before use, then permanently disconnected from all networks. When you're working with the dataset:

  • No cables (except power and monitor connections)
  • No phones within reach
  • No USB drives, external storage, or removable media nearby
  • No wireless peripherals

A single Bluetooth keyboard or forgotten USB stick creates an exfiltration path.

Encryption at Rest and in Transit

The protective order mandates two layers:

  1. Initial encryption: UHG provides data on an encrypted hard drive built to federal security standards, with decryption keys delivered separately.
  2. Re-encryption: Plaintiffs' counsel must encrypt the data again using industry-standard encryption after receiving it.

For sample extraction, every subset requires strong encryption with passwords of at least 16 characters. This layered approach ensures that compromise of any single encryption layer doesn't expose the full dataset.

Access Restrictions

Only 25 people may access the data simultaneously. Small samples only, no bulk exports. Each access event gets logged.

You can't use the dataset to identify potential class members. This addresses a specific litigation concern, but it's also a Data Minimisation principle: limit processing to the specific legal purpose, nothing more.

Chain of Custody

Maintain a detailed audit trail covering:

  • Who accessed the drive and when
  • What samples were extracted
  • Where the drive was physically located
  • Any security incidents or anomalies

UHG can request this log at any time. Think of it as your evidence that you met your obligations, should anyone question your handling later.

Implementation Guidance

Building Your Air-Gapped Environment

Start with a clean machine. Don't repurpose an existing laptop. Provision a new system, apply all security updates, then physically disable network interfaces. If you're building this for the first time:

  1. Document the hardware configuration (make, model, serial numbers).
  2. Create a baseline image before loading discovery data.
  3. Establish a secure physical location with access controls.
  4. Define who can enter the room and under what circumstances.

Sample Extraction Workflow

When you need to analyze a subset of the data:

  1. Boot the air-gapped system.
  2. Extract the minimum necessary sample.
  3. Encrypt the sample with a complex password (16+ characters).
  4. Log the extraction: date, time, operator, sample description, justification.
  5. Transfer the encrypted sample to analysis systems using approved methods only.

Never decrypt samples on networked systems. If you need to share findings with your legal team, share analysis results, redacted summaries, statistical outputs, not raw data.

Incident Response Protocol

The protective order requires notification to the producing party within 48 hours of any security incident. Define "incident" broadly:

  • Unauthorized access attempts
  • Missing or misplaced drives
  • Encryption key compromise
  • Accidental network connection
  • Physical security breaches

If an incident occurs and you're at fault, you'll pay for the external forensic investigation. Budget accordingly.

Common Pitfalls

Underestimating physical security: Air-gapping is worthless if someone can walk into your office and photograph the screen. Implement physical access controls, screen privacy filters, and room-level logging.

Treating samples as less sensitive: Encrypted samples are still discovery material. Don't email them, don't store them in shared drives, don't upload them to cloud analysis platforms. The encryption requirement exists because samples leave the air-gapped environment, but they remain subject to the protective order.

Ignoring the destruction timeline: You have 30 days after case conclusion to destroy the data using NIST SP 800-88 methods or physically destroy the drive. Set a calendar reminder. Get a certificate of destruction under penalty of perjury.

Assuming your forensic tools are safe: If you load forensic software onto the air-gapped system, verify it doesn't include phone-home features, automatic updates, or cloud integration. Read the license agreement. Check the binaries.

Forgetting about metadata: When you extract samples, you're creating new files with new metadata, timestamps, file paths, user accounts. That metadata becomes part of your chain of custody. Document it.

Quick Reference Table

Requirement Specification Verification Method
Initial encryption Federal security standard, keys delivered separately Confirm separate key delivery before accepting drive
Re-encryption Industry-standard encryption after receipt Document encryption method and key management
Sample encryption Strong encryption, 16+ character password Test password complexity before use
System isolation Air-gapped, no Wi-Fi/Bluetooth, newly provisioned Physical inspection, network scan (before isolation)
Physical controls No cables, phones, or storage devices nearby Room checklist before each session
Access limit Maximum 25 simultaneous users Access log review
Sample size Small samples only Define "small" with legal counsel, enforce technically
Audit trail Detailed chain of custody Daily log entries, weekly review
Incident notification Within 48 hours to producing party Documented escalation procedure
Data destruction NIST SP 800-88 or physical destruction within 30 days Certificate of destruction under penalty of perjury

What This Means for Your Breach Response Plan

If you're building or updating your incident response plan, consider litigation discovery requirements now. The Change Healthcare protective order isn't unique, it's a reasonable standard for handling stolen data in legal proceedings.

Ask yourself: If your breach data became discovery material tomorrow, could you produce it securely? Do you have air-gapped systems available? Have you documented your encryption methods? Can you establish chain of custody from the moment data leaves production systems?

The protective order also reinforces a broader principle: sensitive data doesn't become less sensitive because it's evidence. Your Health Insurance Portability and Accountability Act obligations, your contractual commitments, your duty of care, they all continue during litigation. The court's protective order sits on top of those existing obligations, not instead of them.

For security engineers, this is your reminder that "legal hold" doesn't mean "uncontrolled access." Build technical controls into your discovery process from the start. For compliance officers, it's evidence that courts recognize the risks inherent in discovery and will impose meaningful security requirements when the stakes are high enough.

The Change Healthcare breach affected an estimated 192,700,000 individuals. The protective order governing its litigation reflects that scale. Your next breach might not be that large, but the principles remain: isolate, encrypt, log, and destroy. Make them part of your standard practice now.

Application Security Isn’t Optional Anymore.

You Might Also Like