Learn · confidentiality · protective orders
Protective orders in practice for medical imaging
Imaging in litigation is almost always somebody’s protected health information, which is why it so often moves under a protective order — and why the order’s promises are only as good as the handling. What the paper typically requires, where the endgame collides with preservation duties, and what changes when the platform enforces the order instead of trusting every recipient to.
What the order typically requires
Protective orders vary in wording and vary by court, but the ones that cover medical records converge on the same obligations: designated material is used for this litigation only; access is limited to an enumerated set — counsel, staff, retained experts, sometimes insurers and mediators — often with each recipient signing an acknowledgment; copies are not made beyond what the work requires; the material is stored securely; disclosure outside the permitted set is reported; and the parties can be required to account for what was disclosed to whom. Some add stipulated remedies for breach, and some designate tiers — attorneys’-eyes-only material sits inside a smaller circle still.
Read as a systems requirement rather than as boilerplate, that is: an access-control list, a use restriction, a copy restriction, an audit trail, and a revocation story. Which is worth noticing, because the way imaging conventionally travels — discs in the mail, ZIPs on email, files on a shared drive — provides none of those.
The copy problem
The moment a disc is copied to an expert’s laptop, the order’s guarantees go dark. Counsel cannot see whether the files were copied again, opened by someone outside the permitted set, or synced by backup software into a consumer cloud account nobody considered. The obligations continue to bind the people; the material itself is beyond anyone’s observation. Most protective-order compliance, in practice, is an honor system running on other people’s laptops — discovered to have failed, if ever, only when the material surfaces somewhere it should not be. A signed acknowledgment is not an audit trail, and an emailed promise to delete is not deletion.
Return-or-destroy meets the duty to preserve
Most orders end the same way: within some period after the matter concludes, designated material is returned or destroyed and the destruction certified. That clause collides, routinely, with everything else that binds a firm to keep things: preservation obligations that outlive the case when related litigation is reasonably anticipated, appeal windows, malpractice-defense and file-retention practice, and carve-outs the order itself usually grants for work product and court filings — which, in an imaging case, are shot through with references to the very material the order says to destroy. The collision is manageable, but only if the firm can answer two questions precisely: where is every copy, and what is actually deleted when we say deleted. A practice that scattered copies across discs and inboxes cannot answer either; the certification it signs is hopeful rather than known.
Enforcement as a property of the platform
This is the part the order cannot do for itself, and where Slicefield is deliberately opinionated. Imaging shared from a matter moves on role-scoped links — expert, recipient or intake — and each link can do only its job. When the matter is marked as under a protective order, the envelope hardens no matter what was asked for: watermarking is forced on and downloading is forced off, on every link, and the enforcement lives on the server — not in the recipient’s browser agreeing to behave. What a link may see is re-resolved on every read, never stamped into the link when it was minted: narrow the scope, or quarantine a study, and it disappears from every outstanding link at that moment, including links created before the change. Every link is revocable — the order’s access list, made operational.
The order’s accounting obligation is answered the same way: every open by every link holder lands on the matter’s append-only audit ledger, which nothing in the product can update or delete, and the printable chain-of-custody report lists every link ever created and everything that happened on it. When the court, or opposing counsel, asks who has had access to the designated imaging, that is a report, not a reconstruction from memory and email.
And the endgame becomes answerable. Because recipients under a hardened envelope were viewing rather than accumulating downloads, the copies to chase at return-or-destroy time are the ones the order actually contemplated, in known hands. Where preservation duties point the other way, a legal hold on the matter freezes the deletion machinery — the firm’s own delete actions refuse, automated cleanup skips the matter — until the hold is released, and both the hold and its release are ledger events, reason included. The full set of mechanisms is on the security & chain of custody page.
Negotiating the order with the platform in mind
Two practical drafting notes follow from all of this. First, when the order enumerates permitted handling, language that contemplates audited, view-only access through a controlled platform is easier to comply with — provably — than language written for discs and copies; counsel can offer the audit trail as part of the protocol rather than defending its absence later. Second, at the destruction stage, a certification is stronger when it can attach an accounting: what existed, who accessed it, and when it was deleted or placed under hold. The neighboring article on production formats covers the other half of the negotiation — what form the designated material should be produced in to begin with.
This article is general background for litigators, not legal advice, and reading it creates no attorney–client relationship. How any rule applies turns on the jurisdiction, the court and the facts of the particular case — those judgments belong to counsel.
All articles · Security & chain of custody · Open the first disc free