USDC SDNY DOCUMENT UNITED STATES DISTRICT COURT ELECTRONICALLY FILED SOUTHERN DISTRICT OF NEW YORK DOC #: eee DG DATE FILED: 6/12/2024 UNITED STATES OF AMERICA, See □□ Plaintiff, 20-CV-2593 (ALC) (KHP) -against- ANTHEM, INC., ORDER Defendant.
KATHARINE H. PARKER, United States Magistrate Judge: This case, brought by the U.S. government against Anthem, Inc. (“Anthem”) pursuant to the False Claims Act (“FCA”), asserts that Anthem knowingly disregarded its duty to ensure the accuracy of certain information it submitted to the Centers for Medicare and Medicaid Services (“CMS”), a part of the U.S. Department of Health and Human Services (“HHS”), resulting in it being paid more than it was entitled to for its insurance programs for Medicare recipients.
A core part of the information to be exchanged in this case is the protected health information of Anthem’s members (i.e., patient’s medical information and records). At issue is the level of security needed to protect the health data that is turned over to the government in discovery and who should pay for the costs of that security.1 The government has proposed a robust set of protections for the data including that the data will be housed on a bespoke platform, not connected to the internet, accessible by only ten individuals—all of whom are U.S. citizens who have been subject to a criminal background check. The system does not allow for
1 The parties do not dispute the level of protection being provided for other types of information produced in discovery and each side is bearing the costs of protecting the other information each receives (e.g., security in place to protect emails reviewed and produced on a review platform such as Relativity).
transfer of data; rather, the only way to transfer data is encrypted physical storage ini�ated by one of three authorized persons. Addi�onally, all data is encrypted at the file level and would remain encrypted if it were somehow removed from the pla�orm. The security system
proposed by the government is HITRUST-cer�fied.2 The monthly cost already being incurred by the government for this level of security is about $5,000/month. Anthem agrees that the pla�orm has many protec�ons in place but states that it needs addi�onal protec�ons—most that would come into play in the event of a future data breach—
which will cost an addi�onal $4,300/month. The specific addi�onal protec�ons sought include tracking and logging of all ac�vity on the pla�orm, not just tracking and logging data moving in or out of the system; monitoring of internal ac�vity logs; certain data loss preven�on controls to mi�gate poten�al security gaps in transfer protocols; and certain measures to address security vulnerabili�es exploited in the Microso� “Midnight Blizzard” cyber-atack. See ECF 216-1,
Declara�on of Chandrasekhar Nagasundaram Vice President, Technology-Cybersecurity for Anthem. Anthem contends the addi�onal measures it is seeking are consistent with industry standards and with applicable regulatory guidance. The issue of data security in discovery and how costs should be allocated for same is one
that does not appear to have been addressed in any other court decision. Under the federal rules, there is a presump�on that the responding party bears the expense of complying with and responding to discovery requests and of preserving its own
2 HITRUST stands for Health Informa�on Trust Alliance—an organiza�on governed by representa�ves from the healthcare industry that provides a cer�fiable framework to help healthcare organiza�ons and their providers protect sensi�ve health informa�on in keeping with legal/regulatory requirements. 2 informa�on for li�ga�on. Oppenheimer Fund Inc. v. Sanders, 437 U.S. 340, 358 (1978). Who should bear the cost of maintaining the security of data turned over in li�ga�on is a slightly different ques�on. It is typical for Courts to issue protec�ve orders governing discovery, but
those orders do not usually address secure storage of data or who bears the costs of protec�ng electronically stored informa�on produced in discovery. Rather, those orders typically describe the process for designa�ng informa�on confiden�al, challenges to designa�ons, individuals authorized access to confiden�al informa�on, and the return or destruc�on of informa�on at the conclusion of the li�ga�on.
Nonetheless, the undersigned’s model protec�ve order includes the following: “Any Personally Iden�fying Informa�on (“PII”) (e.g., social security numbers, financial account numbers, passwords, and informa�on that may be used for iden�ty the�) exchanged in discovery shall be maintained by the receiving party in a manner that is secure and confiden�al and shared only with authorized individuals in a secure manner. The producing party may specify the minimal level of protec�on expected in the storage and transfer of its informa�on. In the event the party who received PII experiences a data breach, it shall immediately no�fy the producing party of same and cooperate with the producing party to address and remedy the breach. Nothing herein shall preclude the producing party from asser�ng legal claims or cons�tute a waiver of legal rights and defenses in the event of li�ga�on arising out of the receiving party’s failure to appropriately protect PII from unauthorized disclosure.”
Accordingly, the protec�ve order in this case contains this language and allows the producing party to specify the minimum level of security expected. See ECF No. 96. It does not address cost-shi�ing in the event the receiving party disputes the level of protec�on specified by the producing party. 3 The Court is mindful of the increasing data security risks faced by law firms and en��es in li�ga�on.3 In 2022, the American Bar Associa�on reported that 27% of law firms reported having experienced a security breach.4 IBM Security issued a report in 2023 indica�ng that the
average cost of a data breach is more than $4 million. IBM Security, “Cost of a Data Breach Report 2023.” htps://www.ibm.com/reports/data-breach (last visited June 11, 2024). And, indeed, there already has been a data breach in this case. Specifically, one of the government’s vendors experienced a ransomware atack that compromised some of Anthem’s data, resul�ng in the vendor having to send no�ce to impacted individuals, pay for two-years of credit
monitoring, and a lawsuit. ECF No. 96 ¶3. Accordingly, Anthem is righ�ully concerned about the protec�on of its data in this case. Further, HHS has recognized that healthcare informa�on is frequently a target of cyberatacks and care must be taken to protect health informa�on.5 Federal Rule of Civil Procedure 26(c)(1)(B) grants the court discre�on to allocate expenses for disclosure or discovery upon a showing of “good cause.” The Court in Zubulake v.
UBS Warburg LLC, 217 F.R.D. 309, 323 (S.D.N.Y. 2003), set forth various factors to aid courts in analyzing which party should bear the cost of electronic discovery. Those factors include: 1) “the extent to which the request is specifically tailored to discover the relevant informa�on”; 2) “the availability of such informa�on from other sources”; 3) “the total cost of produc�on, compared to the amount in controversy”; 4) “the total cost of produc�on, compared to the
3 htps://nysba.org/hackers-working-for-lucra�ve-cyber-atack-industry-see-law-firms-as-rich-targets/ (last visited June 11, 2024) 4 htps://www.americanbar.org/groups/law prac�ce/resources/tech-report/2022/cybersecurity/ (last visited June 11, 2024) 5 www.aspr.hhs.gov/cyber/documents/Healthcare.Sector.Cybersecurity, Introduc�on to the Strategy of the U.S.
Free access — add to your briefcase to read the full text and ask questions with AI
USDC SDNY DOCUMENT UNITED STATES DISTRICT COURT ELECTRONICALLY FILED SOUTHERN DISTRICT OF NEW YORK DOC #: eee DG DATE FILED: 6/12/2024 UNITED STATES OF AMERICA, See □□ Plaintiff, 20-CV-2593 (ALC) (KHP) -against- ANTHEM, INC., ORDER Defendant.
KATHARINE H. PARKER, United States Magistrate Judge: This case, brought by the U.S. government against Anthem, Inc. (“Anthem”) pursuant to the False Claims Act (“FCA”), asserts that Anthem knowingly disregarded its duty to ensure the accuracy of certain information it submitted to the Centers for Medicare and Medicaid Services (“CMS”), a part of the U.S. Department of Health and Human Services (“HHS”), resulting in it being paid more than it was entitled to for its insurance programs for Medicare recipients.
A core part of the information to be exchanged in this case is the protected health information of Anthem’s members (i.e., patient’s medical information and records). At issue is the level of security needed to protect the health data that is turned over to the government in discovery and who should pay for the costs of that security.1 The government has proposed a robust set of protections for the data including that the data will be housed on a bespoke platform, not connected to the internet, accessible by only ten individuals—all of whom are U.S. citizens who have been subject to a criminal background check. The system does not allow for
1 The parties do not dispute the level of protection being provided for other types of information produced in discovery and each side is bearing the costs of protecting the other information each receives (e.g., security in place to protect emails reviewed and produced on a review platform such as Relativity).
transfer of data; rather, the only way to transfer data is encrypted physical storage ini�ated by one of three authorized persons. Addi�onally, all data is encrypted at the file level and would remain encrypted if it were somehow removed from the pla�orm. The security system
proposed by the government is HITRUST-cer�fied.2 The monthly cost already being incurred by the government for this level of security is about $5,000/month. Anthem agrees that the pla�orm has many protec�ons in place but states that it needs addi�onal protec�ons—most that would come into play in the event of a future data breach—
which will cost an addi�onal $4,300/month. The specific addi�onal protec�ons sought include tracking and logging of all ac�vity on the pla�orm, not just tracking and logging data moving in or out of the system; monitoring of internal ac�vity logs; certain data loss preven�on controls to mi�gate poten�al security gaps in transfer protocols; and certain measures to address security vulnerabili�es exploited in the Microso� “Midnight Blizzard” cyber-atack. See ECF 216-1,
Declara�on of Chandrasekhar Nagasundaram Vice President, Technology-Cybersecurity for Anthem. Anthem contends the addi�onal measures it is seeking are consistent with industry standards and with applicable regulatory guidance. The issue of data security in discovery and how costs should be allocated for same is one
that does not appear to have been addressed in any other court decision. Under the federal rules, there is a presump�on that the responding party bears the expense of complying with and responding to discovery requests and of preserving its own
2 HITRUST stands for Health Informa�on Trust Alliance—an organiza�on governed by representa�ves from the healthcare industry that provides a cer�fiable framework to help healthcare organiza�ons and their providers protect sensi�ve health informa�on in keeping with legal/regulatory requirements. 2 informa�on for li�ga�on. Oppenheimer Fund Inc. v. Sanders, 437 U.S. 340, 358 (1978). Who should bear the cost of maintaining the security of data turned over in li�ga�on is a slightly different ques�on. It is typical for Courts to issue protec�ve orders governing discovery, but
those orders do not usually address secure storage of data or who bears the costs of protec�ng electronically stored informa�on produced in discovery. Rather, those orders typically describe the process for designa�ng informa�on confiden�al, challenges to designa�ons, individuals authorized access to confiden�al informa�on, and the return or destruc�on of informa�on at the conclusion of the li�ga�on.
Nonetheless, the undersigned’s model protec�ve order includes the following: “Any Personally Iden�fying Informa�on (“PII”) (e.g., social security numbers, financial account numbers, passwords, and informa�on that may be used for iden�ty the�) exchanged in discovery shall be maintained by the receiving party in a manner that is secure and confiden�al and shared only with authorized individuals in a secure manner. The producing party may specify the minimal level of protec�on expected in the storage and transfer of its informa�on. In the event the party who received PII experiences a data breach, it shall immediately no�fy the producing party of same and cooperate with the producing party to address and remedy the breach. Nothing herein shall preclude the producing party from asser�ng legal claims or cons�tute a waiver of legal rights and defenses in the event of li�ga�on arising out of the receiving party’s failure to appropriately protect PII from unauthorized disclosure.”
Accordingly, the protec�ve order in this case contains this language and allows the producing party to specify the minimum level of security expected. See ECF No. 96. It does not address cost-shi�ing in the event the receiving party disputes the level of protec�on specified by the producing party. 3 The Court is mindful of the increasing data security risks faced by law firms and en��es in li�ga�on.3 In 2022, the American Bar Associa�on reported that 27% of law firms reported having experienced a security breach.4 IBM Security issued a report in 2023 indica�ng that the
average cost of a data breach is more than $4 million. IBM Security, “Cost of a Data Breach Report 2023.” htps://www.ibm.com/reports/data-breach (last visited June 11, 2024). And, indeed, there already has been a data breach in this case. Specifically, one of the government’s vendors experienced a ransomware atack that compromised some of Anthem’s data, resul�ng in the vendor having to send no�ce to impacted individuals, pay for two-years of credit
monitoring, and a lawsuit. ECF No. 96 ¶3. Accordingly, Anthem is righ�ully concerned about the protec�on of its data in this case. Further, HHS has recognized that healthcare informa�on is frequently a target of cyberatacks and care must be taken to protect health informa�on.5 Federal Rule of Civil Procedure 26(c)(1)(B) grants the court discre�on to allocate expenses for disclosure or discovery upon a showing of “good cause.” The Court in Zubulake v.
UBS Warburg LLC, 217 F.R.D. 309, 323 (S.D.N.Y. 2003), set forth various factors to aid courts in analyzing which party should bear the cost of electronic discovery. Those factors include: 1) “the extent to which the request is specifically tailored to discover the relevant informa�on”; 2) “the availability of such informa�on from other sources”; 3) “the total cost of produc�on, compared to the amount in controversy”; 4) “the total cost of produc�on, compared to the
3 htps://nysba.org/hackers-working-for-lucra�ve-cyber-atack-industry-see-law-firms-as-rich-targets/ (last visited June 11, 2024) 4 htps://www.americanbar.org/groups/law prac�ce/resources/tech-report/2022/cybersecurity/ (last visited June 11, 2024) 5 www.aspr.hhs.gov/cyber/documents/Healthcare.Sector.Cybersecurity, Introduc�on to the Strategy of the U.S. Department of Health and Human Services (“HHS”) (last visited June 11, 2024). 4 resources available to each party”; 5) “the rela�ve ability of each party to control costs and its incen�ve to do so”; 6) “the importance of the issues at stake in the li�ga�on”; and 7) “the rela�ve benefits to the par�es of obtaining informa�on.” 217 F.R.D. 322. These factors were
developed over twenty years ago in the infancy of electronic discovery and before 2006 amendments to the Rules designed to address issues raised by difficul�es in “loca�ng, retrieving, and providing discovery of some electronically stored informa�on.” Advisory Commitee Notes, 2006 Amendment to Rule 26(b)(2). Thus, these factors are informa�ve, but are not all directly relevant to the ques�on of whether a producing party who wishes a certain
level of data security be provided for data produced in discovery can require the receiving party to bear the full cost of such data security protec�ons for the dura�on of the li�ga�on un�l the data is destroyed or returned.6 In most cases, the receiving party will bear the costs of maintaining the security of data
and the risk of a data breach, as each side will receive data and will need to protect that data pursuant to the terms of any protec�ve order and the level of security and costs will be similar for both sides. Addi�onally, there are strong financial and reputa�onal incen�ves for par�es and their lawyers to ensure the security of the data they receive in discovery. Nevertheless, there may be some instances when it is appropriate to shi� certain costs of data security.
6 Courts have referenced these factors in determining cost shi�ing in similar contexts, however. See, e.g., IME Watchdog, Inc. v. Gelardi, 22 Civ. 1023, 2022 WL 2316137 (E.D.N.Y. June 28, 2022)(finding Zubulake factors were consistent with finding that the par�es should share the cost of forensic examina�on of electronic devices); In the Matter of the Complaint of Specialist LLC, 16 Civ. 5010, 16 Civ. 2515, 16 Civ. 3353, 16 Civ. 3579, 16 Civ. 4643, 16 Civ. 7001, 2016 WL 6884919 (recognizing the party possessing informa�on normally must bear the expense of preserving it for li�ga�on but nevertheless shi�ing costs of preserva�on of physical evidence – a ship – and no�ng that Zubulake factors, while not necessarily directly applicable, were consistent with shi�ing costs).
5 Further, there may be different levels of security needed for different types of informa�on produced in a li�ga�on.
A�er careful considera�on, the Court has iden�fied the following, non-exclusive factors as relevant to determining whether there is good cause to shi� all or a por�on of costs of data security measures from the receiving party to the producing party: 1) the nature of the informa�on to be protected and risks and costs associated with unauthorized disclosure of such informa�on; 2) the reasonableness of the security measures requested by the producing party
(which can include an evalua�on of the degree of risk mi�gated by the security requested rela�ve to less costly security measures); 3) the cost of the data security requested rela�ve to the overall costs of discovery and amount in controversy; and 4) rela�ve ability of the par�es to pay the costs of the security requested by the producing party. These factors are not necessarily en�tled to the same weight in every case and should be balanced based on the
par�culars of each case. As to factor one, the informa�on sought to be protected here is medical informa�on and related personally iden�fying informa�on about individuals who are not par�es to this li�ga�on. This type of informa�on is o�en the subject of cyber atacks, and includes deeply
personal details about the non-par�es included in the data set. This data has already been the subject of a cyber atack in this case, meaning that it is a high risk target of future cyber atacks. The costs associated with compromise of this informa�on are high because of the number of people who could be affected by a security breach. Further, the costs associated with addressing a large security breach are in the millions of dollars. Given these risks, and 6 par�cularly given the previous breach, Anthem’s concern for the security of the data is reasonable and this factor weighs against shi�ing the costs of that security to Anthem.
As to factor two, the security requested by Anthem is the security requested of all of its vendors and thus not unusual nor newly calculated to cause hardship to the Plain�ff. On the other hand, the system proposed by the government is already secure and takes into account health industry standards for protec�on of informa�on. Addi�onally, unlike with Anthem’s regular vendors, the informa�on will not be accessible via the internet, is encrypted and will be
accessible to only 10 people. It is not clear how much addi�onal risk will be mi�gated from the addi�onal measures proposed by Anthem. Ul�mately, the only technical opinion offered by the par�es is from Anthem’s head of Cybersecurity Threat Management, whose declara�on iden�fies specific vulnerabili�es in the government’s proposal. The Court can not rely on the representa�ons of lawyers for the government to conclude that their proposed safeguards are
sufficient. Therefore, this factor also weighs against shi�ing the costs of data security to Anthem. As to factor three, the cost of the addi�onal data security measures is about $60,000 per year, which would nearly double the Governments data-hos�ng and security costs. At the same
�me, the Government is alleging that Anthem unlawfully obtained and retained millions of dollars in payments. ECF No. 26-1. Therefore, the annual costs of the addi�onal security measures are a rounding error rela�ve to the en�re amount in controversy, and this factor also weighs against shi�ing the costs of data security to Anthem.
7 As to factor four, both sides have an ability to pay the cost of the addi�onal security, but they are not equally resourced. Anthem has retained a global law firm to defend this ac�on, O’Melveny, whose associates regularly bill at rates about $500/hour, and whose partners bill at
rates exceeding $1000/hour. See e.g., Mogan v. Sacks, Ricketts & Case LLP, 2022 WL 1458518, at *2 (N.D. Cal. May 9, 2022)(lis�ng rates charged by O’Melveny counsel and partners.) It generates billions of dollars in revenues and has significant resources to defend this ac�on. The Department of Jus�ce also is well-resourced, but the Court is mindful that it is financed by tax dollars and pursuing this case to recover public funds it asserts were overpaid to Anthem.
Nevertheless, the disparity in resources and source of those resources is not so great, especially in light of the total cost of li�ga�on and amount in controversy, as to raise concerns that the producing party (Anthem) is seeking to make prosecu�ng the case against it financially untenable. On the whole, this factor weighs sightly in favor of shi�ing the costs of data security to Anthem, but not as strongly as in a situa�on where there is a greater financial disparity between the par�es.
A�er considering all of these factors, the Court finds that the addi�onal security measures requested by Anthem are propor�onate to the nature of the informa�on sought to be protected, reasonable in light of the only evidence provided on the level of security required, and propor�onate to the total amount in controversy and the overall costs of li�ga�on. While
Anthem is slightly beter posi�oned to absorb these addi�onal costs, that factor alone does not outweigh the others par�cularly where there has already been a data breach due to the
8 requesting party’s prior insufficient protections. Accordingly, the government has not shown good cause to shift the burden to Anthem to pay for the additional security requested.
CONCLUSION
For the reasons set forth above, Plaintiff shall implement the additional security measures requested by Anthem and bear the cost of the additional security measures. However, this decision is without prejudice to a renewed motion under Rule 26 to shift the costs of this enhanced security if Defendant engages in conduct that unreasonably extends discovery So as to increase the costs to Plaintiff. See e.g., Est. of Shaw v. Marcus, 2017 WL 825317, at *6 (S.D.N.Y. Mar. 1, 2017)(noting discovery-related misconduct was relevant to analysis of whether discovery cost-shifting was appropriate). It is also without prejudice as to any rights the government may have as a prevailing party to recover costs.
SO ORDERED. Ket haut H ankle New York, New York June 12, 2024 Katharine H. Parker U.S. Magistrate Judge