When a federal magistrate judge approved the protective order for Change Healthcare's stolen dataset, the 193 million affected individuals weren't the only ones watching. Every legal team handling breach-related litigation just received a preview of what courts will expect when compromised data becomes evidence.
You're going to handle stolen data in discovery. The question is whether you'll do it under court supervision after a misstep, or whether you'll build the controls now.
Why These Mistakes Keep Happening
Legal teams treat discovery as a document management problem. Security teams treat it as an access control problem. Neither group owns the intersection, so the gap becomes a vulnerability. Discovery platforms are built for searchability and collaboration, not for handling data that threat actors already exfiltrated once. Your standard e-discovery workflow assumes the documents are sensitive but not radioactive. Stolen PII and PHI are radioactive.
The Change Healthcare order codifies what happens when courts recognize that distinction. The security requirements (FIPS 140-2/140-3 compliant drives, air-gapping, mandatory breach reporting within two days) aren't aspirational. They're enforceable. If you're defending a breach lawsuit, you'll face similar demands.
Mistake 1: Treating Stolen Data Like Standard ESI
Your outside counsel receives the dataset and loads it into the same document review platform they use for contract disputes. The platform lives in a commercial cloud environment with standard access controls. Reviewers log in from home networks. The data is encrypted at rest, which feels sufficient.
Why it happens: Discovery workflows optimize for attorney efficiency. Multi-factor authentication and role-based access feel like security. But stolen data carries different risk. It's already been weaponized once. If your review platform gets compromised, you're not just losing work product, you're re-victimizing the data subjects.
The consequence: You've created a second breach surface. If the platform is breached or an insider misuses access, you're now the defendant in a separate action. The court in your underlying case will not be sympathetic.
The fix: Establish a separate forensic environment for stolen datasets. The Change Healthcare order requires air-gapping during access. You don't need to replicate that exactly, but you do need controls that acknowledge the threat model. Use dedicated, hardened workstations. Disable network connectivity during review sessions. Implement session recording and keystroke logging for accountability. Require FIPS 140-2 or 140-3 validated encryption for data at rest and in transit. If your e-discovery vendor can't support these requirements, you need a different vendor for this data.
Mistake 2: Making Unauthorized Copies
Your expert witness needs a subset of records for analysis. An associate creates a spreadsheet with excerpts and emails it to the expert. Later, a paralegal makes another copy for deposition prep. By the time you inventory what exists, you've got seven copies across four locations.
Why it happens: Legal work requires collaboration. Copying documents is muscle memory. No one thinks of it as data proliferation because it's all "our side." But each copy is a new exposure point.
The consequence: You've lost chain of custody and control. When the court asks how many copies exist and where they are, you can't answer with certainty. If any copy is compromised, you can't prove it wasn't the one you made.
The fix: Implement a strict copy control regime before you receive the data. The Change Healthcare order limits plaintiffs to one complete copy and restricts excerpts to 25 individuals' data. You should adopt similar limits even if the court doesn't impose them. Require written approval from lead counsel for any excerpt. Maintain a copy register that logs every derivative, who created it, when, and for what purpose. Use technical controls (read-only access, disabled copy/paste functions) where possible. Treat every copy as a separate security incident waiting to happen.
Mistake 3: Skipping the Chain of Custody Log
The hard drive arrives at your office. Someone signs for it and puts it in the file room. When you need it, you retrieve it. No one tracks who accessed it, when, or what they did with it.
Why it happens: Chain of custody feels like a criminal law concept, not a civil discovery obligation. Your team focuses on analyzing the content, not documenting the handling.
The consequence: When opposing counsel questions whether your analysis is based on the original dataset or a modified version, you have no contemporaneous records. Your expert's conclusions become impeachable. Worse, if the data is later compromised, you can't establish when or how.
The fix: Create a physical custody log that travels with every drive. The Change Healthcare order requires logging who transferred custody, who received it, date, time, location, and drive serial number. Do this from day one. Require sign-out and sign-in for every access. Store drives in locked containers with access logs. Treat the dataset like you'd treat original evidence in a criminal case, because functionally, that's what it is.
Mistake 4: Using Compromised or Unpatched Systems
Your expert connects the drive to their regular work laptop. The machine hasn't been patched in two months. It's running endpoint protection, but the definitions are outdated. The expert works from coffee shops and airport lounges.
Why it happens: Experts are independent contractors with their own IT practices. You don't control their environment. They resist "burdensome" security requirements because it slows them down.
The consequence: You've introduced the dataset to an uncontrolled environment with unknown vulnerabilities. If that laptop is compromised, the stolen data is compromised again. You're liable, not the expert.
The fix: Specify device requirements in your expert engagement letter. The Change Healthcare order requires newly provisioned, hardened, fully patched computers with wireless and Bluetooth disabled. Require your expert to use a dedicated machine for this work, not their general-purpose laptop. Provide the machine yourself if necessary. Require written confirmation that the device meets your specifications before you transfer the data. This isn't negotiable.
Mistake 5: Ignoring Incident Reporting Obligations
Your paralegal accidentally emails an excerpt to the wrong recipient. They realize the error immediately, recall the message, and tell no one. Or your expert's laptop is stolen from a car. They report it to local police but not to you for three days.
Why it happens: People fear consequences. Admitting a mistake feels like inviting discipline. The incident seems minor or contained, so it doesn't trigger anyone's reporting instinct.
The consequence: You've violated your duty to the court and to opposing counsel. The Change Healthcare order requires reporting unauthorized access or disclosure within two days. If you don't report promptly, you lose credibility and potentially face sanctions. The underlying data subjects may suffer additional harm.
The fix: Establish a no-penalty reporting culture for security incidents involving litigation data. Make it clear that immediate reporting is mandatory and that concealment carries consequences, not the initial mistake. Draft incident response procedures specific to stolen data in discovery. Include notification timelines (the two-day window from the Change Healthcare order is a good baseline), escalation paths, and forensic investigation triggers. Require every person with access to acknowledge these procedures in writing.
Mistake 6: Failing to Plan for Destruction
The case settles. Everyone moves on. The hard drive sits in your file room for two years because no one's sure whether it's okay to destroy it. Or an associate deletes files from their laptop but doesn't securely wipe the drive.
Why it happens: Data destruction isn't part of standard case-closing procedures. No one wants to be the person who destroyed something that later turns out to be needed. Secure wiping seems like overkill for a simple file deletion.
The consequence: You're retaining highly sensitive data without a legal basis. If that data is later compromised, you're liable for maintaining it longer than necessary. Standard deletion doesn't prevent forensic recovery, so the data remains accessible.
The fix: Build destruction into your engagement terms from the start. The Change Healthcare order requires destruction within 30 days of case conclusion, using NIST SP 800-88 compliant three-pass overwrite or physical destruction. Set calendar reminders tied to case milestones. Require written certification of destruction under penalty of perjury. Don't rely on individuals to remember. Make it a checklist item that blocks case closure until it's complete.
Prevention Checklist
Before you receive stolen data in discovery:
- Establish a dedicated forensic environment (air-gapped or equivalent controls)
- Draft copy control procedures limiting excerpts and requiring approval
- Create physical custody logs and secure storage protocols
- Specify device security requirements for all personnel with access
- Implement two-day incident reporting procedures with no-penalty culture
- Schedule destruction milestones and assign responsibility
- Require FIPS 140-2/140-3 validated encryption for all transfers
- Disable network connectivity, wireless, and Bluetooth during access sessions
- Obtain written acknowledgment of security procedures from all access holders
- Designate a security point-of-contact for the litigation team
The Change Healthcare protective order isn't an outlier. It's a template. Courts are recognizing that stolen data in litigation requires security controls that match the threat. If you wait for a judge to order these measures, you've already failed. Build them into your discovery practice now.





