Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit
Tift Regional Health System Inc, a non-profit health system serving patients in south central Georgia, has agreed to pay $1.2 million to settle a class action lawsuit stemming from a 2022 cyberattack that exposed patient data.
Tift Regional Health, which operates as Southwell, Inc., which is also a defendant, identified suspicious activity within its computer network on or around August 16, 2022. The forensic investigation confirmed that its network was accessed by an unauthorized third party between August 11, 2022, and August 17, 2022. The compromised parts of the network contained documents that included patient names, birth dates, Social Security numbers, and a range of sensitive medical information. Tift Regional Health said those documents may have been accessed or copied in the attack. A ransomware group – Hive – claimed responsibility for the attack. Hive claimed to have stolen 1 terabyte of data and proceeded to leak some of that data on its data leak site. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 180,142 individuals.
Multiple class action lawsuits were filed against the defendants in response to the data breach. The lawsuits were consolidated into a single action – In Tift Regional Health System, Inc. Data Breach Litigation – in the Superior Court of Tift County, State of Georgia, as the lawsuits had overlapping claims. The consolidated lawsuit alleged that the cyberattack and data breach were due to the defendants’ failures to properly secure, safeguard, and encrypt patient data, and destroy patient data in a timely manner when it was no longer required. The lawsuit also took issue with the length of time it took to notify the affected individuals. They were not notified about the data breach until August 11, 2023, almost a year after the incident occurred.
The lawsuit asserted claims for negligence, negligence per se, breach of fiduciary duty, breach of implied contract, breach of contract, breach of the covenant of good faith and fair dealing, unjust enrichment, invasion of privacy, violation of the Georgia Uniform Deceptive Trade Practices Act, and for equitable and injunctive relief. The defendants deny the claims and contentions in the lawsuit and maintain there was no wrongdoing and no liability.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Both sides agreed to a settlement to avoid the costs and risks of a trial. The defendants have agreed to establish a $1,200,000 settlement fund to pay benefits to the class members after attorneys’ fees and expenses, settlement administration costs, and service awards for the four class representatives have been deducted. The defendants have also implemented a range of additional measures to better secure sensitive data in their possession, and those measures will be maintained for at least two years at an estimated cost of $4.5 million.
All class members are entitled to enroll in a two-year credit/medical data monitoring and identity theft protection service, and claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to a maximum of $5,000 per class member, or a claim may be submitted for an alternative cash payment.
The cash payments will be paid pro rata after all other claims and costs have been deducted, and they will exhaust the settlement fund. The cash payments are expected to be approximately $75 per class member but may be higher or lower. The settlement has received preliminary approval from the court, and the final fairness hearing is scheduled for September 14, 2026. The deadline for opting out and objecting to the settlement is September 15, 2026. Claims must be submitted by October 15, 2026.


