Tift Regional Health System Inc. decided to pay $1.2 million to resolve a class action lawsuit arising from a 2022 cyberattack that compromised patient data.
Nonprofit health system Tift Regional Health System Inc. provides patient care in south central Georgia, together with Southwell, Inc., which is also a defendant in the litigation.
Tiff Regional Health System identified suspicious activity within its computer network on or around August 16, 2022. A forensic investigation determined that an unauthorized third party hacked the network from August 11, 2022 until August 17, 2022. The affected portions of the network contained documents with patient names, various sensitive health information, birth dates, and Social Security numbers. Tift Regional Health stated that the documents may have been accessed or stolen during the attack.
The Hive ransomware group claimed to have been behind the attack. Hive also claimed to have stolen 1 terabyte of data and subsequently leaked some of the data on its data leak site.
The data breach report submitted to the HHS’ Office for Civil Rights indicated that the protected health information (PHI) of 180,142 individuals were affected.
Consolidated Class Action Litigation
Multiple class action lawsuits were filed against the defendants following the data breach. The cases were consolidated into a single action titled In Tift Regional Health System, Inc. Data Breach Litigation in the Superior Court of Tift County, State of Georgia.
The consolidated lawsuit alleged that the cyberattack and data breach resulted from failures to properly secure, safeguard, and encrypt patient information. The lawsuit also alleged failures to destroy patient data in a timely manner after the information was no longer required.
The litigation also challenged the amount of time taken to notify affected individuals. The individuals were not notified about the data breach until August 11, 2023, almost one year after the incident.
The lawsuit asserted claims involving negligence, negligence per se, invasion of privacy, breach of fiduciary duty, breach of contract, breach of implied contract, unjust enrichment, breach of the covenant of good faith and fair dealing, violation of the Georgia Uniform Deceptive Trade Practices Act, and equitable and injunctive relief.
The defendants denied the claims and contentions in the lawsuit and maintained that there was no wrongdoing or liability.
$1.2 Million Settlement Fund
The parties agreed to settle the litigation to avoid the costs and risks associated with a trial.
Under the settlement, the defendants agreed to establish a $1,200,000 settlement fund. The fund will be used to provide benefits to class members after paying attorneys’ fees and expenses, settlement management costs, and service awards for the four class representatives.
The defendants have also implemented additional measures intended to secure sensitive data in their possession. Those measures will remain in place for at least two years at an estimated cost of $4.5 million.
Class Member Benefits and Settlement Deadlines
Class members are entitled to enroll in a two-year credit and medical data monitoring and identity theft protection service.
Class members may also submit one of two types of cash claims. One option provides reimbursement for documented, unreimbursed losses up to $5,000 per class member. The other option provides an alternative cash payment.
Cash payments will be distributed on a pro rata basis after other claims and settlement costs have been deducted. Those payments will exhaust the settlement fund. The payments are expected to be approximately $75 per class member, although the amount may be higher or lower.
The settlement has received preliminary approval from the court. The final fairness hearing is scheduled for September 14, 2026. The deadline for class members to opt out of or object to the settlement is September 15, 2026. Claims must be submitted by October 15, 2026.
