Tift Regional Health System Pays $1.2 Million to Settle Class Action Over 2022 Hive Ransomware Breach
Georgia-based healthcare provider Tift Regional Health System (operating as Southwell) agreed to a $1.2 million settlement to resolve consolidated class-action litigation arising from a major August 2022 ransomware attack claimed by the Hive ransomware group.
Overview
| Attribute | Detail |
|---|---|
| Target Organisation | Tift Regional Health System / Southwell (Georgia, USA) |
| Settlement Amount | $1.2 million USD |
| Threat Actor | Hive Ransomware Group |
| Breach Window | 11 August 2022 โ 17 August 2022 |
| Impacted Population | 180,142 individuals (reported to HHS OCR) |
| Compromised Records | Patient names, dates of birth, Social Security numbers, protected health information (PHI) |
| Date | 2026-08-25 |
Breach Background & Legal Claims
In mid-August 2022, Hive ransomware operators breached Tift Regional's IT environment, claiming the exfiltration of approximately 1 terabyte of data before encrypting local network shares and publishing sample patient files on their dark web leak platform.
The class-action lawsuit concentrated on specific operational and governance failures: 1. Notification Delays: Affected patients and employees were not notified until 11 August 2023 โ nearly a full year following the initial compromise. 2. Data Retention & Encryption Failures: Plaintiffs alleged that the health system maintained legacy sensitive records without adequate encryption or data minimisation controls.
Under the settlement terms, the $1.2 million fund provides financial compensation for out-of-pocket expenses, credit monitoring services, and institutional investments in enterprise security hardening.
Significance
The settlement underscores the prolonged legal, financial, and regulatory tail of healthcare ransomware intrusions. Even years after law enforcement disrupted Hive's core infrastructure, victim organisations face substantial liability stemming from historical compliance and notification delays.