Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation
The court overseeing the Change Healthcare multidistrict litigation (MDL) has imposed strict rules governing access to and use of the stolen dataset, limiting how parties and their experts may handle the breached data as the litigation proceeds.
Key Facts
| Attribute | Detail |
|---|---|
| Litigation | Change Healthcare multidistrict litigation (US) |
| Development | Court order imposing strict dataset-use rules on parties and experts |
| Significance | One of the largest healthcare data breaches on record |
| Disclosure date | 2026-08-12 |
Context
The order is the latest legal milestone in the Change Healthcare matter and sets procedural guardrails for how sensitive records are handled by experts on both sides โ a reminder that the life of a major breach extends long past disclosure, through litigation and regulatory scrutiny. For AU/NZ organisations, the case remains a reference point on third-party healthcare-processing concentration risk and the downstream legal complexity of large health-data losses (see the Ceva logistics and healthcare supply-chain themes in the August digests).
Related Pages
- Data Breaches Announced By Five Small Healthcare Organizations โ ongoing healthcare breach notifications
Sources: raw/digests/Cyber-Digest-2026-08-13