Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-26 ยท updated: 2026-08-26 ยท tags: [incident, ransomware, ransomware-group, sector-healthcare, le-action] ยท confidence: high ยท severity: medium ยท affected_sectors: [healthcare] ยท au_impact: false

Tift Regional Health System Pays $1.2 Million to Settle Class Action Over 2022 Hive Ransomware Breach

Georgia-based healthcare provider Tift Regional Health System (operating as Southwell) agreed to a $1.2 million settlement to resolve consolidated class-action litigation arising from a major August 2022 ransomware attack claimed by the Hive ransomware group.

Overview

Attribute Detail
Target Organisation Tift Regional Health System / Southwell (Georgia, USA)
Settlement Amount $1.2 million USD
Threat Actor Hive Ransomware Group
Breach Window 11 August 2022 โ€“ 17 August 2022
Impacted Population 180,142 individuals (reported to HHS OCR)
Compromised Records Patient names, dates of birth, Social Security numbers, protected health information (PHI)
Date 2026-08-25

Breach Background & Legal Claims

In mid-August 2022, Hive ransomware operators breached Tift Regional's IT environment, claiming the exfiltration of approximately 1 terabyte of data before encrypting local network shares and publishing sample patient files on their dark web leak platform.

The class-action lawsuit concentrated on specific operational and governance failures: 1. Notification Delays: Affected patients and employees were not notified until 11 August 2023 โ€” nearly a full year following the initial compromise. 2. Data Retention & Encryption Failures: Plaintiffs alleged that the health system maintained legacy sensitive records without adequate encryption or data minimisation controls.

Under the settlement terms, the $1.2 million fund provides financial compensation for out-of-pocket expenses, credit monitoring services, and institutional investments in enterprise security hardening.

Significance

The settlement underscores the prolonged legal, financial, and regulatory tail of healthcare ransomware intrusions. Even years after law enforcement disrupted Hive's core infrastructure, victim organisations face substantial liability stemming from historical compliance and notification delays.

Sources