Tift Regional Health System Agrees to $1.2 Million Settlement Over 2022 Data Breach

Tift Regional Health System Inc has agreed to pay $1.2 million to settle a class action lawsuit arising from a 2022 cyberattack that exposed patient information.

Tift Regional Health System Inc, a nonprofit health system in south central Georgia, also known as Southwell, Inc., is a defendant in the litigation. The organization identified suspicious activity within its computer network on or around August 16, 2022. A forensic investigation determined that an unauthorized third party accessed the network from August 11, 2022 until August 17, 2022.

The breached network contained documents with patient names, birth dates, various types of sensitive health records, and Social Security numbers. Tift Regional Health stated that the documents may have been accessed or copied during the attack. The data breach was reported to the HHS Office for Civil Rights as involving the protected health information (PHI) of 180,142 individuals.

The ransomware group Hive claimed responsibility for the attack. Hive claimed that it had stolen 1 terabyte of data and subsequently leaked some of the information on its data leak site.

Consolidated Class Action Litigation

Multiple class action lawsuits were filed against Tift Regional Health System and the other defendant following the data breach. The lawsuits were consolidated into a single action in the Superior Court of Tift County, State of Georgia, because they contained overlapping claims.

The consolidated lawsuit alleged that the cyberattack and data breach resulted from failures to properly secure, safeguard, and encrypt patient information. The lawsuit also alleged failures involving the timely destruction of patient information when it was no longer required.

The lawsuit challenged the amount of time taken to notify affected individuals. The individuals were not notified about the data breach until August 11, 2023, almost one year after the incident occurred, which is a violation of HIPAA breach notification rules.

The claims included breach of contract, negligence, negligence per se, breach of the covenant of good faith and fair dealing, breach of implied contract, breach of fiduciary duty, invasion of privacy, unjust enrichment, and violation of the Georgia Uniform Deceptive Trade Practices Act. The lawsuit also sought equitable and injunctive relief.

The defendants did not admit any claims and contentions and claimed no wrongdoing or liability.

Settlement Terms and Data Security Measures

The parties agreed to a settlement to avoid the costs and risks associated with a trial. The defendants agreed to establish a $1,200,000 settlement fund for class member benefits after deductions for attorneys’ fees and expenses, settlement administration costs, and service awards for four class representatives.

The defendants also implemented additional measures to secure sensitive data in their possession. The measures will be maintained for at least two years at an estimated cost of $4.5 million. They provided class members with a credit and medical data monitoring and identity theft protection service for two years.

Class members can also submit one of two types of cash claims. One claim provides reimbursement for documented and unreimbursed losses up to $5,000 per class member. The other provides an alternative cash payment. Cash payments will be distributed on a pro rata basis after other claims and costs are deducted. The payments will exhaust the settlement fund. The payments are expected to be approximately $75 per class member, although the amount may be higher or lower.

Court Approval and Settlement Deadlines

The settlement has received preliminary approval from the court. The final fairness hearing is scheduled for September 14, 2026. The deadline for opting out of the settlement and objecting to it is September 15, 2026. Claims must be submitted by October 15, 2026.