United States v. Anthem, Inc.
- Andrew Carter
- 1:20-cv-02593
- U.S. District Court · Southern District of New York
- 9
In United States v. Anthem, Magistrate Judge Parker ordered the government to pay for enhanced security protecting health data produced in discovery.
The United States and Anthem, Inc. are affected by the cost-allocation ruling. The security measures protect medical and personally identifying information belonging to Anthem members who are not parties to the case.
What happened
United States v. Anthem, Inc. is a False Claims Act case about whether Anthem received excess payments for Medicare insurance programs. The dispute here concerned how to protect Anthem members’ medical information exchanged during discovery.
The government proposed a secure, offline system costing about $5,000 per month. Anthem requested additional protections costing about $4,300 more per month and argued that the government should pay for them because the government’s vendor had previously suffered a data breach.
Magistrate Judge Parker ruled that the government had not shown good cause to make Anthem pay. She ordered the government to implement the additional security measures and bear their cost, while allowing a renewed cost-shifting request if Anthem unreasonably extended discovery.
The detailed version
- United States v. Anthem, Inc. · No. 1:20-cv-02593
- Andrew Carter
- June 12, 2024
Background
The United States brought this False Claims Act case against Anthem, Inc. The government alleges that Anthem knowingly failed to ensure the accuracy of information submitted to the Centers for Medicare and Medicaid Services, causing Anthem to receive more money than it was entitled to for insurance programs serving Medicare recipients.
The discovery at issue includes protected health information belonging to Anthem members, who are not parties to the case. The government proposed storing the information on a specially designed platform that is not connected to the internet, is accessible to only ten people who are United States citizens and have undergone criminal background checks, and uses encryption and restricted physical transfer procedures. The government was already paying about $5,000 per month for that system.
Anthem sought additional protections, including logging all platform activity, monitoring internal activity logs, data-loss-prevention controls, and measures addressing vulnerabilities associated with the Microsoft “Midnight Blizzard” cyberattack. Those measures would cost about $4,300 more per month. The opinion also states that a government vendor had previously experienced a ransomware attack that compromised some of Anthem’s data.
Legal framework
Federal Rule of Civil Procedure 26(c)(1)(B) allows a court, for good cause, to allocate expenses related to disclosure or discovery. The court noted the usual rule that the responding party pays the expense of responding to discovery and preserving its own information. It treated the cost of securing information after it is produced to the opposing party as a different question.
The court identified four nonexclusive factors for deciding whether to shift some or all data-security costs from the receiving party to the producing party:
- the nature of the information and the risks and costs of unauthorized disclosure; - the reasonableness of the requested security measures, including the additional risk they address compared with less costly measures; - the security cost compared with the overall discovery costs and the amount in dispute; and - the parties’ relative ability to pay.
Application
The court concluded that the medical and identifying information was highly sensitive, was a frequent target of cyberattacks, and posed substantial potential costs if disclosed. The prior breach in this case made Anthem’s security concerns reasonable. This factor weighed against shifting the costs to Anthem.
The court found that Anthem’s requested measures were used for its vendors and were not unusual. It also found that the government’s proposed system was already secure in several important respects, but that the court could not determine the additional risks without relying solely on the government’s lawyers because the technical evidence came from Anthem’s cybersecurity executive. This factor also weighed against shifting the costs to Anthem.
The additional measures would cost about $60,000 per year and would nearly double the government’s hosting and security costs. But the government alleges that Anthem obtained and retained millions of dollars unlawfully, making the additional annual cost small compared with the amount in dispute. This factor weighed against shifting the costs.
Both parties could pay the additional cost, although they were not equally resourced. Anthem had substantial resources, and the government was also well-resourced, but the government is financed by tax dollars and was seeking to recover public funds. This factor weighed slightly in favor of shifting costs to Anthem, but not enough to overcome the other factors.
Ruling
The court found that Anthem’s requested security measures were proportionate to the sensitivity of the information, reasonable based on the evidence, and proportionate to the amount in dispute and overall litigation costs. It ruled that the government had not shown good cause to shift the cost of the additional security to Anthem.
The court ordered the government to implement the additional security measures requested by Anthem and bear their cost. The decision is without prejudice to a renewed request under Rule 26 to shift those costs if Anthem engages in conduct that unreasonably extends discovery and increases the government’s expenses. The decision also does not affect any rights the government may have as a prevailing party to recover costs.
Read the full 9-page opinion on CourtListener, the free public archive maintained by the Free Law Project.