Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
When Litigation Dictates Your Security ControlsData Privacy
7 min readFor Compliance Officers

When Litigation Dictates Your Security Controls

You're facing a data breach lawsuit. The court has ordered you to produce the stolen dataset to plaintiffs' counsel. Now you need to decide: Do you fight the production order, negotiate custom security terms, or accept standard protective order language?

This isn't theoretical. The Change Healthcare multidistrict litigation, from the 2024 ransomware attack affecting 193 million people, resulted in a court-mandated security protocol resembling NIST SP 800-53 more than a typical discovery order. The judge didn't just say "keep it confidential." The order specifies FIPS 140-2 compliant encryption, air-gapped analysis environments, three-pass data wiping per NIST SP 800-88, and breach notification within two days.

For compliance officers managing breach response programs, this raises a critical question: When do you accept judicial security mandates, and when do you push back?

The Decision You're Facing

You're in active litigation over a data breach. The plaintiffs want access to the compromised dataset to prove their damages and your negligence. Your options:

  • Accept a stipulated protective order with enhanced security controls
  • Oppose production entirely and force the court to rule
  • Propose alternative technical measures that reduce your exposure

Each path carries different risk profiles, cost implications, and strategic consequences for your broader compliance program.

Key Factors That Affect Your Choice

Scale and sensitivity of the compromised data. The Change Healthcare dataset contained protected health information for 193 million individuals. When dealing with PHI, financial records, or other regulated data at this scale, courts won't accept vague promises to "keep it secure." If your breach involved fewer than 10,000 records of low-sensitivity data, you've got more negotiating room.

Your existing security posture during the breach. If your incident response documentation shows you were already using FIPS 140-2 compliant encryption and air-gapped forensic environments when the breach occurred, arguing against those same controls in litigation looks inconsistent. Conversely, if you can demonstrate that your current security architecture exceeds what plaintiffs are proposing, you've got leverage.

Whether you paid a ransom. UnitedHealth reportedly paid $22 million in cryptocurrency to the BlackCat gang. If you paid attackers for a deletion promise, plaintiffs will argue you can't simultaneously claim the data is too sensitive to share under court supervision. Your ransom payment becomes evidence that you've already made risk decisions about the dataset.

Regulatory obligations that survive litigation. HIPAA Security Rule requirements don't pause during discovery. If producing the dataset to plaintiffs' counsel creates a new disclosure that triggers additional breach notification obligations under the Health Information Technology for Economic and Clinical Health Act, you need to account for that cost and reputational damage.

Your tolerance for a second breach during litigation. The Change Healthcare protective order requires plaintiffs to report "unauthorized access, use or disclosure" within two days and potentially fund an independent forensic investigation if their team causes a security incident. You're betting that plaintiffs' counsel and their designated experts will implement controls correctly. If they don't, you're explaining to regulators why the same data got compromised twice.

Path A: Accept Enhanced Security Terms

Choose this path when:

  • The dataset is already widely distributed (193 million affected individuals means the data likely exists in multiple threat actor repositories)
  • You can't credibly argue the data is too sensitive to produce, especially if you paid a ransom
  • The proposed controls align with your own security standards, making opposition look defensive rather than principled
  • You want to demonstrate good faith cooperation to the court before trial

What you're committing to: In the Change Healthcare case, this meant producing a single complete dataset copy on a FIPS 140-2 or FIPS 140-3 compliant encrypted external hard drive. The receiving party must use AES-256 encryption, air-gapped computers with disabled wireless and Bluetooth, and maintain chain-of-custody logs. Any excerpts containing PII or PHI are limited to 25 individuals and require the same transfer protocols.

Implementation requirements: You'll need to verify that plaintiffs' designated expert can actually meet these standards before production. Request their security architecture documentation. Confirm they understand that "air-gapped while the drives are attached" means complete physical isolation, not just network segmentation. Specify the computer hardening baseline (CIS Critical Security Controls benchmarks, for example) and patch currency requirements.

Cost considerations: Producing data under these constraints isn't cheap. You're creating forensically sound copies, encrypting drives to federal standards, and potentially funding third-party verification. Budget $50,000-$200,000 for a large-scale production with enhanced security controls, depending on dataset complexity.

Risk mitigation: The Change Healthcare order prohibits using the stolen data to identify or recruit additional plaintiffs. It also requires destruction within 30 days of case resolution, with certification signed under penalty of perjury. These provisions limit how long the data remains exposed and prevent it from becoming a plaintiff recruitment tool.

Path B: Oppose Production and Force a Court Ruling

Choose this path when:

  • The dataset contains information that could enable identity theft or fraud if re-disclosed (Social Security numbers, financial account details, authentication credentials)
  • You can demonstrate that plaintiffs can prove their claims using anonymized or statistical summaries rather than the complete dataset
  • The breach is still under active criminal investigation and production could compromise law enforcement efforts
  • You've got strong technical evidence that plaintiffs' proposed security controls are inadequate

What you're arguing: The data is so sensitive that even court-supervised production creates unacceptable re-disclosure risk. You're not hiding evidence; you're protecting breach victims from compounded harm.

Evidentiary burden: You'll need expert testimony on the specific harms that could result from re-disclosure. Generic "cybersecurity is important" arguments won't work. Quantify the fraud risk. Show the court what threat actors could do with the specific data elements in your dataset that they couldn't do with publicly available information.

Likely outcome: Courts generally favor disclosure in civil litigation, especially when plaintiffs can demonstrate that the data is essential to proving damages. You'll probably lose this fight unless you can offer a genuine alternative (see Path C). But forcing the court to rule creates an appellate record if you need to challenge the decision later.

Strategic consideration: Opposing production entirely can backfire if the court views it as obstruction. You're signaling that you prioritize your litigation position over breach victims' interests. That narrative doesn't help when the same judge is deciding negligence claims.

Path C: Propose Alternative Technical Measures

Choose this path when:

  • You've got in-house expertise to design a more secure production method than plaintiffs proposed
  • The dataset can be analyzed effectively through controlled access rather than full production
  • You're willing to fund a neutral third-party expert facility

What you're offering: Instead of producing the complete dataset to plaintiffs' counsel, you propose a secure data clean room environment. Plaintiffs' designated expert accesses the data on-site at a neutral facility you control, runs approved queries, and receives only the statistical outputs or specific record excerpts necessary to support their claims.

Technical architecture: You're essentially creating a SOC 2 Type II-compliant analysis environment with Role-Based Access Control, session logging, and data loss prevention controls. The expert can't download the complete dataset, copy it to removable media, or extract more data than the court authorizes.

Control framework: Reference NIST Cybersecurity Framework (CSF) 2.0 functions: Identify (data classification), Protect (access controls), Detect (monitoring), Respond (incident procedures), Recover (data destruction). Show the court you're applying the same rigor to litigation discovery that you should have applied to prevent the breach.

Cost and logistics: You're funding the secure facility, technical infrastructure, and potentially a neutral expert to oversee access. This costs more than producing a hard drive, but it gives you visibility into exactly what plaintiffs extract from the dataset. Budget $100,000-$500,000 depending on the analysis timeline and dataset complexity.

Negotiation leverage: Courts appreciate creative solutions that balance plaintiffs' legitimate discovery needs with data protection obligations. If you can demonstrate that your alternative provides plaintiffs everything they need to prove their case while reducing re-disclosure risk, you've got a strong argument.

Summary Matrix

Decision Path When to Choose Key Requirements Primary Risk
Accept Enhanced Security Terms Dataset widely distributed; can't credibly oppose production; want to show cooperation FIPS 140-2/140-3 encryption, air-gapped analysis, AES-256, chain-of-custody logs, destruction certification Second breach during plaintiffs' custody; compliance costs
Oppose Production Data enables fraud/identity theft; plaintiffs can use anonymized alternatives; active criminal investigation Expert testimony on re-disclosure harms; alternative evidence proposals Court views opposition as obstruction; likely to lose and create bad appellate record
Propose Alternative Measures In-house expertise available; dataset supports controlled access model; willing to fund neutral facility Secure data clean room, Role-Based Access Control, session logging, DLP controls, statistical outputs only Higher cost; complex logistics; court may reject as unnecessarily restrictive

The Change Healthcare protective order represents a new baseline. Courts are no longer accepting generic confidentiality language when the stakes involve millions of individuals' health and identity information. Whether you accept judicial security mandates or propose alternatives, you're building the evidentiary record that will define your negligence exposure at trial.

Your security controls during litigation aren't separate from your compliance program. They're evidence of what you believe reasonable data protection looks like.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like