Patients learned about a 2022 attack almost a year after it happened, and the complaint made that delay one of its central allegations.
What happened
Tift Regional Health System and Southwell, Inc., a non-profit provider in south central Georgia, will pay $1.2 million to settle consolidated litigation over a 2022 cyberattack, according to the court-authorized settlement notice. Forensic investigators established that an unauthorized party reached the network between August 11 and August 17, 2022, with the organization spotting suspicious activity on or around August 16. Files accessed during that window may have held names, dates of birth, Social Security numbers, and medical information. A ransomware group calling itself Hive claimed the attack, said it had taken a terabyte of data, and posted some of it on its leak site. The case, In re Tift Regional Health System, Inc. Data Breach Litigation, Case No. 2023CV0313, sits in the Superior Court for Tift County. Defendants deny wrongdoing and the court has made no finding on the merits.
Going deeper
Plaintiffs alleged that the defendants failed to properly secure, safeguard, and encrypt patient information, which appears in nearly every case of this kind. Two further allegations are less common. One claimed the organization retained patient data past the point it was needed rather than destroying it, meaning records that could have been deleted before August 2022 remained available to be taken. The other challenged how long patients waited to hear anything, since notification letters did not go out until August 11, 2023. A final approval hearing is set for September 14, 2026, and class members are being offered two years of medical identity monitoring.
What was said
The settlement notice describes the incident as "the targeted cyberattack on Tift's computer systems that occurred in August 2022," stating that certain files containing private information were accessed, according to the court-approved notice. It records that the defendants deny they did anything wrong, that the court has not decided who is right, and that the parties agreed to settle to avoid the costs, risks, and uncertainties of continuing the case.
In the know
Hive rented its ransomware to affiliates who carried out the intrusions and split the proceeds, and healthcare ranked among its priority sectors. The FBI, CISA, and the Department of Health and Human Services counted more than 1,300 victims worldwide and roughly $100 million in ransom payments since June 2021, in a joint advisory published three months after the Tift intrusion. That advisory recorded a habit worth knowing about for anyone investigating an intrusion afterward, since affiliates shut down backup and antivirus processes, removed shadow copies, which are the snapshots Windows keeps so files can be restored to an earlier state, and wiped Windows event logs. The operation ended in January 2023 when the Justice Department announced that the FBI had spent six months inside Hive's own networks, capturing decryption keys and passing more than 1,300 of them to victims, preventing $130 million in ransom payments.
The big picture
Hacking and IT incidents accounted for 88% of all patient records exposed between 2010 and 2024, with ransomware rising from no recorded cases in 2010 to more than 30% of breaches by 2021, according to a cross-sectional analysis in JAMA Network Open covering HIPAA-regulated entities. Against that background, the retention allegation is what other organizations should take from this case. OCR has told regulated entities that a risk analysis should account for what data they hold and where it sits, and that disposal plans need to be current rather than assumed, in guidance on disposing of electronic devices and media. Records already destroyed cannot be taken. Reviewing retention schedules against what systems actually contain, and confirming deletion happens when those schedules say it should, closes an exposure no security control reaches.
FAQs
Does a settlement mean an organization admitted fault?
No. Settlements typically state that the defendant denies wrongdoing and that the court has made no determination, with both sides agreeing to resolve the matter rather than continue litigating. Courts approve settlements based on fairness to the class rather than on any finding about the underlying conduct.
What retention obligations apply to patient records?
HIPAA requires covered entities to retain certain documentation for six years, while state laws set medical record retention periods that vary considerably and often run longer. Neither framework requires keeping records indefinitely, and data held past every applicable period represents exposure without a corresponding legal obligation.
Why would attackers delete event logs before encrypting?
Logs record which systems were reached and what was accessed, which is the evidence an organization needs to determine the scope of a breach. Removing them slows the investigation and can leave a covered entity unable to demonstrate a low probability of compromise in its risk assessment.
What happens when a ransomware group is dismantled after an attack?
Law enforcement action against the group does not undo the disclosure, since data already published stays available and copies held by affiliates remain outside anyone's control. Takedowns can produce decryption keys for victims still locked out, though they do not affect breach notification obligations or civil exposure.
