United States v. Anthem, Inc.

District Court, S.D. New York·Decided June 12, 2024·No. 1:20-cv-02593·Unknown

Opinion

USDC SDNY DOCUMENT UNITED STATES DISTRICT COURT ELECTRONICALLY FILED SOUTHERN DISTRICT OF NEW YORK DOC #: eee DG DATE FILED: 6/12/2024 UNITED STATES OF AMERICA, See □□ Plaintiff, 20-CV-2593 (ALC) (KHP) -against- ANTHEM, INC., ORDER Defendant.

KATHARINE H. PARKER, United States Magistrate Judge: This case, brought by the U.S. government against Anthem, Inc. (“Anthem”) pursuant to the False Claims Act (“FCA”), asserts that Anthem knowingly disregarded its duty to ensure the accuracy of certain information it submitted to the Centers for Medicare and Medicaid Services (“CMS”), a part of the U.S. Department of Health and Human Services (“HHS”), resulting in it being paid more than it was entitled to for its insurance programs for Medicare recipients.

A core part of the information to be exchanged in this case is the protected health information of Anthem’s members (i.e., patient’s medical information and records). At issue is the level of security needed to protect the health data that is turned over to the government in discovery and who should pay for the costs of that security.1 The government has proposed a robust set of protections for the data including that the data will be housed on a bespoke platform, not connected to the internet, accessible by only ten individuals—all of whom are U.S. citizens who have been subject to a criminal background check. The system does not allow for

1 The parties do not dispute the level of protection being provided for other types of information produced in discovery and each side is bearing the costs of protecting the other information each receives (e.g., security in place to protect emails reviewed and produced on a review platform such as Relativity).

transfer of data; rather, the only way to transfer data is encrypted physical storage ini�ated by one of three authorized persons. Addi�onally, all data is encrypted at the file level and would remain encrypted if it were somehow removed from the pla�orm. The security system

proposed by the government is HITRUST-cer�fied.2 The monthly cost already being incurred by the government for this level of security is about $5,000/month. Anthem agrees that the pla�orm has many protec�ons in place but states that it needs addi�onal protec�ons—most that would come into play in the event of a future data breach—

which will cost an addi�onal $4,300/month. The specific addi�onal protec�ons sought include tracking and logging of all ac�vity on the pla�orm, not just tracking and logging data moving in or out of the system; monitoring of internal ac�vity logs; certain data loss preven�on controls to mi�gate poten�al security gaps in transfer protocols; and certain measures to address security vulnerabili�es exploited in the Microso� “Midnight Blizzard” cyber-atack. See ECF 216-1,

Declara�on of Chandrasekhar Nagasundaram Vice President, Technology-Cybersecurity for Anthem. Anthem contends the addi�onal measures it is seeking are consistent with industry standards and with applicable regulatory guidance. The issue of data security in discovery and how costs should be allocated for same is one

that does not appear to have been addressed in any other court decision. Under the federal rules, there is a presump�on that the responding party bears the expense of complying with and responding to discovery requests and of preserving its own

2 HITRUST stands for Health Informa�on Trust Alliance—an organiza�on governed by representa�ves from the healthcare industry that provides a cer�fiable framework to help healthcare organiza�ons and their providers protect sensi�ve health informa�on in keeping with legal/regulatory requirements. 2 informa�on for li�ga�on. Oppenheimer Fund Inc. v. Sanders, 437 U.S. 340, 358 (1978). Who should bear the cost of maintaining the security of data turned over in li�ga�on is a slightly different ques�on. It is typical for Courts to issue protec�ve orders governing discovery, but

those orders do not usually address secure storage of data or who bears the costs of protec�ng electronically stored informa�on produced in discovery. Rather, those orders typically describe the process for designa�ng informa�on confiden�al, challenges to designa�ons, individuals authorized access to confiden�al informa�on, and the return or destruc�on of informa�on at the conclusion of the li�ga�on.

Nonetheless, the undersigned’s model protec�ve order includes the following: “Any Personally Iden�fying Informa�on (“PII”) (e.g., social security numbers, financial account numbers, passwords, and informa�on that may be used for iden�ty the�) exchanged in discovery shall be maintained by the receiving party in a manner that is secure and confiden�al and shared only with authorized individuals in a secure manner. The producing party may specify the minimal level of protec�on expected in the storage and transfer of its informa�on. In the event the party who received PII experiences a data breach, it shall immediately no�fy the producing party of same and cooperate with the producing party to address and remedy the breach. Nothing herein shall preclude the producing party from asser�ng legal claims or cons�tute a waiver of legal rights and defenses in the event of li�ga�on arising out of the receiving party’s failure to appropriately protect PII from unauthorized disclosure.”

Accordingly, the protec�ve order in this case contains this language and allows the producing party to specify the minimum level of security expected. See ECF No. 96. It does not address cost-shi�ing in the event the receiving party disputes the level of protec�on specified by the producing party. 3 The Court is mindful of the increasing data security risks faced by law firms and en��es in li�ga�on.3 In 2022, the American Bar Associa�on reported that 27% of law firms reported having experienced a security breach.4 IBM Security issued a report in 2023 indica�ng that the

average cost of a data breach is more than $4 million. IBM Security, “Cost of a Data Breach Report 2023.” htps://www.ibm.com/reports/data-breach (last visited June 11, 2024). And, indeed, there already has been a data breach in this case. Specifically, one of the government’s vendors experienced a ransomware atack that compromised some of Anthem’s data, resul�ng in the vendor having to send no�ce to impacted individuals, pay for two-years of credit

monitoring, and a lawsuit. ECF No. 96 ¶3. Accordingly, Anthem is righ�ully concerned about the protec�on of its data in this case. Further, HHS has recognized that healthcare informa�on is frequently a target of cyberatacks and care must be taken to protect health informa�on.5 Federal Rule of Civil Procedure 26(c)(1)(B) grants the court discre�on to allocate expenses for disclosure or discovery upon a showing of “good cause.” The Court in Zubulake v.

UBS Warburg LLC, 217 F.R.D. 309, 323 (S.D.N.Y. 2003), set forth various factors to aid courts in analyzing which party should bear the cost of electronic discovery. Those factors include: 1) “the extent to which the request is specifically tailored to discover the relevant informa�on”; 2) “the availability of such informa�on from other sources”; 3) “the total cost of produc�on, compared to the amount in controversy”; 4) “the total cost of produc�on, compared to the

3 htps://nysba.org/hackers-working-for-lucra�ve-cyber-atack-industry-see-law-firms-as-rich-targets/ (last visited June 11, 2024) 4 htps://www.americanbar.org/groups/law prac�ce/resources/tech-report/2022/cybersecurity/ (last visited June 11, 2024) 5 www.aspr.hhs.gov/cyber/documents/Healthcare.Sector.Cybersecurity, Introduc�on to the Strategy of the U.S.

Free access — add to your briefcase to read the full text and ask questions with AI

United States v. Anthem, Inc., (S.D.N.Y. 2024).

United States v. Anthem, Inc. (United States v. Anthem, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Oppenheimer Fund, Inc. v. Sanders
437 U.S. 340 (Supreme Court, 1978)
Zubulake v. UBS Warburg LLC
217 F.R.D. 309 (S.D. New York, 2003)