Tift Regional Health System, Inc., a non-profit health system in south central Georgia that operates as Southwell, Inc., has agreed to a $1.2 million class-action settlement over a 2022 Hive ransomware intrusion that exposed the protected health information of 180,142 patients. The HIPAA Journal reports that Tift identified suspicious network activity on or around August 16, 2022, and that forensic investigators later confirmed an unauthorized third party had access to the network from August 11 through August 17, 2022. The Hive ransomware operation claimed the attack, said it had stolen 1 terabyte of data, and published a portion of it on its leak site. Both HIPAA Journal and MedRisk agree on the 180,142 figure, which matches the total reported to the HHS Office for Civil Rights. The consolidated case, In re Tift Regional Health System, Inc. Data Breach Litigation, Case No. 2023CV0313, is pending in the Superior Court of Tift County, Georgia, with a final approval hearing set for September 14, 2026 and a claims deadline of October 15, 2026.
What Happened
The intrusion window is the most consistently corroborated element of this incident. HIPAA Journal and MedRisk both place unauthorized access between August 11 and August 17, 2022, a roughly seven-day dwell period inside a regional hospital network. HIPAA Journal adds a detail MedRisk does not: Tift detected the suspicious activity itself on or around August 16, meaning the adversary operated undetected for approximately five days and retained some level of access for at least a day after detection.
Hive, a ransomware-as-a-service operation later disrupted by an international law enforcement action in January 2023, took public credit. The group claimed 1 TB of exfiltrated data and leaked a subset when payment did not materialize. None of the available sources indicate that Tift paid a ransom.
The notification timeline became a central grievance in the litigation. MedRisk states affected individuals were not notified until August 2023, "nearly a year after the intrusion." HIPAA Journal is more specific, citing August 11, 2023, which would be almost exactly one year to the day from the start of the intrusion. Multiple class actions were filed and consolidated in Tift County Superior Court. Plaintiffs alleged the defendants failed to properly secure, safeguard, and encrypt patient data, failed to destroy patient data in a timely manner once it was no longer needed, and took too long to notify. Tift and Southwell deny wrongdoing, and the court has made no finding on the merits.
Settlement terms are largely consistent across sources but not entirely. All accounts agree on a $1,200,000 non-reversionary fund, an estimated $75 alternative cash payment, and two years of monitoring. OpenClassActions specifies that monitoring as CyEx Medical Shield Complete with $1 million in medical identity theft insurance. The documented-loss cap is where accounts diverge: MedRisk and OpenClassActions both report up to $5,000 per person, while The Financial Wire states the official claim form caps documented-loss reimbursement at $4,500 and describes that as a correction to earlier reporting. Claimants should treat the claim form itself as authoritative and assume the lower figure until confirmed.
The $75 figure is an estimate, not an entitlement. The Financial Wire explains the mechanics clearly: the alternative cash payment is what remains after approved attorneys' fees, administration costs, service awards, monitoring benefits, and documented-loss claims are paid, divided pro rata among valid claimants. A heavier-than-expected claims rate drives that number down.
MedRisk alone reports that Tift also agreed to security upgrades estimated at $4.5 million over two years. No other source in this set corroborates that commitment, and it should be treated as unconfirmed pending review of the settlement agreement.
Deadlines also require care. OpenClassActions and MedRisk both give October 15 as the claims deadline, with OpenClassActions specifying October 15, 2026 for both online submissions and mailed postmarks, and noting the notice does not specify a cutoff time or timezone. MedRisk lists an opt-out deadline of September 15, which is not corroborated elsewhere in this source set and sits oddly after the September 14 fairness hearing. Class members intending to opt out should verify that date directly with the settlement administrator rather than relying on secondhand reporting.
What Was Taken
The compromised portions of the network contained documents holding patient names, dates of birth, Social Security numbers, and a range of sensitive medical information. Tift's position, reflected consistently in HIPAA Journal and MedRisk, is that these documents "may have been accessed or copied," the standard hedged formulation used when forensic telemetry cannot definitively prove exfiltration of specific files.
Hive's own claim removes much of that ambiguity. The group asserted 1 TB of stolen data and leaked part of it publicly, which is direct evidence of exfiltration regardless of what the victim's forensics could independently confirm. Threat actor leak-site claims are self-serving and frequently inflated, but a partial leak is verification that data left the network.
The class definition, per The Financial Wire, covers U.S. residents whose private information may have been compromised in the attack, including but not limited to people who received a breach notice. That "including" matters: individuals who believe they were affected but never received a notice are directed to contact the administrator for an eligibility check rather than filing based on treatment history alone.
The exposed combination is the worst-case set for healthcare. Names, dates of birth, and Social Security numbers support identity theft and synthetic identity fraud indefinitely. Clinical detail supports targeted extortion, insurance fraud, and social engineering. None of it can be rotated the way a password can.
Why It Matters
The economics here are the story. A $1.2 million fund divided across 180,142 class members works out to roughly $6.66 per record before fees, administration, service awards, and monitoring costs are deducted. That is the ceiling, not the payout. The realized per-person cash recovery is estimated at $75 only because the overwhelming majority of class members in settlements like this never file a claim.
For defenders building a business case, this cuts both ways. The direct settlement liability for exposing 180,000 patient records is modest relative to the cost of the security program that would have prevented it. If MedRisk's unconfirmed $4.5 million remediation figure is accurate, Tift is spending nearly four times the settlement amount on controls it will now implement under legal pressure rather than budget planning. The lesson is not that breaches are cheap. It is that the settlement is the smallest line item.
The notification gap deserves separate attention. Roughly twelve months elapsed between intrusion and patient notification, and it became an explicit cause of action in the consolidated complaint. HIPAA requires notification within 60 days of discovery of a breach. A year-long gap invites regulatory scrutiny independently of any civil litigation, and it materially extends the window in which victims are unable to take protective action while their data is already circulating publicly.
There is also a broader regional signal worth naming carefully. Four of the eight sources supplied for this brief concern a separate and unrelated incident: the 2025 breach of MCBS, LLC (Medical Computer Business Services), an Augusta, Georgia medical billing and revenue cycle management firm. That incident affected 1,261,464 individuals across seven HIPAA-covered entity clients including South Georgia Radiology Consultants, SkinPath Solutions, and Stephen W. Brown & Radiology Associates of Augusta. It has no established connection to Tift, and this brief does not assert one. It does illustrate that Georgia healthcare organizations and their business associates have been repeatedly and successfully targeted across a multi-year span, and that the aggregator tier now represents larger single-point exposure than most individual hospitals.
Accounts of the MCBS incident differ on several points. BleepingComputer and MedRisk place unauthorized access between September 22 and 26, 2025, while HIPAA Journal and HEAL Security give September 22 to September 25. The claiming group, PEAR, is expanded as "Pure Extortion and Ransom" by HIPAA Journal and HEAL Security but as "Pure Extraction and Ransom" by MedRisk. Claimed exfiltration volume is reported as 3 TB by HIPAA Journal and HEAL Security and 3.3 TB by MedRisk. MCBS itself did not name the threat actor. These discrepancies are noted for completeness and are not attributable to the Tift matter.
The Attack Technique
None of the available sources disclose an initial access vector for the Tift intrusion. No exploited CVE, no phishing campaign, no compromised credential, no vulnerable edge appliance is named. Four years on and through a full litigation cycle, the technical entry point remains publicly unreported. Any specific claim about how Hive got in would be invention.
What the sources do establish is the operational shape: unauthorized network access sustained from August 11 to August 17, 2022, sufficient lateral reach to access document repositories containing structured patient identifiers and clinical records, and successful bulk exfiltration on the order of a terabyte before or alongside deployment of ransomware. The plaintiffs' allegations imply that data at rest was not encrypted and that retention policies left records on the network past their useful life, though these are litigation claims rather than confirmed forensic findings.
For contrast, the MCBS incident detailed in the accompanying sources reflects a different model. PEAR is described consistently by HIPAA Journal, HEAL Security, and MedRisk as a data theft and extortion group that does not deploy encryption at all. Hive encrypted and leaked. PEAR simply takes and publishes. Defenders who still equate ransomware defense with backup and restore capability are solving only half of the 2022 problem and none of the 2026 one.
What Organizations Should Do
Instrument for exfiltration, not just encryption. A seven-day dwell period ending in a terabyte leaving the network is a data movement problem before it is a ransomware problem. Alert on volumetric egress anomalies, outbound connections to cloud storage and file transfer services, and archive utility execution on servers that host document repositories. Backups do not help once the data is on a leak site.
Close the gap between detection and containment. Tift detected suspicious activity on or around August 16 per HIPAA Journal, yet the confirmed access window extends through August 17. Any interval between detection and full eviction is time the adversary uses to finish exfiltrating and to establish persistence. Rehearse containment as a timed exercise with a defined authority to disconnect.
Encrypt sensitive data at rest and enforce retention limits. Both failures were pleaded directly in the consolidated complaint. Field-level or database-level encryption of Social Security numbers and clinical identifiers reduces the value of stolen documents. Aggressive, documented, and actually executed deletion of records past their retention requirement reduces the blast radius of any future intrusion at effectively zero ongoing cost.
Treat 60-day breach notification as a hard operational deadline. The roughly year-long delay between the Tift intrusion and patient notification became its own cause of action. Pre-build the notification workflow: forensic scoping timelines, data review capacity, mailing vendor contracts, and call center arrangements should be established before an incident, not negotiated during one.
Audit your business associates and demand incident telemetry. MCBS held data for seven covered entities and exposed 1.26 million people in a single compromise. Contractual security requirements, documented breach notification timelines, and evidence of independent assessment should be non-negotiable for any aggregator, billing firm, or revenue cycle vendor holding your patient data.
Segment document repositories from general network access. The compromised portions of the Tift network contained files with names, dates of birth, Social Security numbers, and medical detail in accessible document form. Network segmentation, least-privilege file share permissions, and monitored access to bulk PHI stores raise the cost of turning an initial foothold into a terabyte extraction.
Sources: Georgia health system pays $1.2M over Hive attack on 180,000 patien... | Data breach at medical billing firm MCBS affects 1.26 million people | Tift Regional Health System Pays $1.2 Million to Settle Data Breach... | MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals | MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals -... | Medical billing firm MCBS breach hits 1.26 million patients as PEAR... | A Georgia health system could pay breach victims an estimated $75,... | Tift Regional Health Data Breach Settlement — $75 Cash