Subscribe To Our Newsletter
Tift Regional Health System Inc. and Southwell Inc. agreed to a $1.2 million class action settlement to resolve claims that they failed to prevent an August 2022 ransomware attack.
If you received healthcare services or had records stored at Tift Regional Health System, your personal and sensitive medical information may have been exposed during a major security incident. Tift Regional Health System Inc. and Southwell Inc. have agreed to a $1.2 million class action settlement to resolve allegations that the healthcare provider failed to adequately safeguard patient data during an August 2022 ransomware attack.
Everyday people trust hospitals and health networks to keep their private health details secure. When a network experiences a cyberattack, patient lives can be thrown into disarray through identity theft, financial fraud, and unauthorized exposure of personal medical histories.
This settlement offers cash payments for out-of-pocket losses, estimated flat cash distributions for affected consumers, and free identity monitoring services. You may be eligible to submit a claim for cash benefits or credit protection if your personal information was impacted in the security incident.
In August 2022, Georgia-based Tift Regional Health System was targeted in a cyberattack that disrupted system operations and allowed unauthorized third parties access to sensitive files. According to the class action lawsuit, cybercriminals executed a ransomware attack on Tift’s internal network, compromising personal and medical information belonging to patients and related individuals.
The lawsuit alleges that the healthcare organization failed to implement basic, industry-standard cybersecurity protections. Plaintiffs claim that Tift did not maintain reasonable measures to protect patient data, omitting crucial safeguards such as multifactor authentication (MFA) and robust endpoint detection software.
Because of these alleged failures, sensitive personal data was exposed to unauthorized bad actors. Affected consumers reported spending significant time, energy, and out-of-pocket money managing the risk of fraud, checking credit reports, and securing their personal files.
The class action lawsuit was filed in Georgia state court under the title In re: Tift Regional Health System Inc. Data Breach Litigation, Case No. 2023CV0313, in the Superior Court for Tift County. The plaintiffs asserted that Tift Regional Health System had a legal duty to protect confidential patient information and failed to take reasonable steps to prevent foreseeable cyber threats.
Key allegations in the lawsuit center around:
Failure to Safeguard Data: Neglecting to use adequate, modern safeguards like endpoint monitoring and multi-factor authentication.
Risk of Fraud: Exposing patients to heightened, ongoing risks of financial identity theft and medical identity theft.
Loss of Personal Value: Inconvenience, stress, and monetary losses incurred by consumers trying to secure their credit profiles after receiving breach notices.
Tift Regional Health System and Southwell Inc. deny all allegations of wrongdoing and maintain that they took proper precautions to protect information. However, to avoid the delay, expense, and uncertainty of an extended legal trial, both parties agreed to create a $1.2 million settlement fund to compensate affected patients.
The $1.2 million settlement agreement offers distinct forms of relief depending on whether you experienced out-of-pocket financial losses as a direct result of the breach. You may be eligible to choose the option that best fits your situation:
If you suffered actual financial harm or incurred expenses due to the data breach, you can submit a claim for up to $5,000 in cash reimbursement. Eligible expenses include:
Unreimbursed bank fees, credit charges, or fraudulent transactions.
Costs associated with purchasing credit reports, credit freezes, or monitoring software.
Fees paid for replacement government identification documents or driver’s licenses.
Postage, travel, communication, or notary expenses linked to resolving identity theft issues.
To claim this benefit, you must provide supporting documentation such as bank statements, receipts, credit bureau letters, or bills verifying your losses.
If you did not suffer specific out-of-pocket losses or do not have receipts, you can still request a cash payment. Class members can opt for a pro rata cash distribution. While the actual amount depends on the total number of valid claims filed, settlement administrators estimate these payments will be around $75. No documentation of financial loss is required to receive this payment.
All class members, regardless of whether they choose a cash payout, are eligible to enroll in two years of free credit monitoring services. This package includes up to $1 million in medical identity theft insurance along with specialized alerts for:
Exposure of healthcare insurance identification numbers.
Unauthorized access to medical record numbers.
Unapproved spending or activity in Health Savings Accounts (HSAs).
You may be eligible to participate in this class action settlement if you are a resident of the United States whose private information or medical records were compromised in the August 2022 Tift Regional Health System data breach.
Individuals who received an official notice from Tift Regional Health System or Southwell Inc. regarding the August 2022 incident are considered part of the settlement class. If you received a breach notification letter by mail or email, your details were identified in the impacted file set.
If you are unsure whether your data was part of the breach, you can check your eligibility or contact the settlement administrator using the official channel:
Settlement Website: TiftDataSettlement.com
Toll-Free Phone: 833-421-7345
Mailing Address: Tift Data Security Incident Settlement, c/o Settlement Administrator, P.O. Box 25226, Santa Ana, CA 92799-9958
To protect your legal rights and claim your share of the settlement funds, you must pay attention to several upcoming court dates and deadlines:
| Deadline / Event | Date | What It Means |
| Final Approval Hearing | September 14, 2026 | The court decides whether to grant final approval to the $1.2M settlement structure. |
| Exclusion & Objection Deadline | September 15, 2026 | Last day to opt out of the settlement or file a legal objection to the settlement terms with the court. |
| Claim Form Deadline | October 15, 2026 | Last day to submit your claim form online or by mail to receive cash or credit monitoring benefits. |
If you do nothing, you will lose your right to sue Tift Regional Health System or Southwell Inc. in the future over these data breach claims, and you will not receive any settlement money or credit monitoring.
Filing a claim is quick and can be completed online from your computer or phone. Here is what you need to do before the deadline:
Visit the Settlement Portal: Navigate to the official settlement website at TiftDataSettlement.com.
Obtain Your Claim Form: Enter your Unique ID and PIN (found on the physical breach notice mailed to you). If you do not have an ID, you can download a paper form or fill out a claim online using your personal details.
Choose Your Benefits: Select whether you are requesting reimbursement for up to $5,000 in documented expenses or selecting the estimated $75 flat cash payment. Indicate if you wish to enroll in the two years of free credit monitoring.
Attach Documentation: If claiming out-of-pocket losses, attach digital copies, photos, or PDFs of your receipts, bank statements, or credit reports clearly showing the monetary loss.
Submit Before the Deadline: Complete the form and submit it online by October 15, 2026. If mailing a physical form, ensure it is postmarked by October 15, 2026.
When healthcare providers fail to secure sensitive personal data, everyday people bear the cost of identity monitoring and fraud defense. Class action settlements exist so that individual consumers do not have to stand alone when challenging large entities.
Don’t stand alone. If your personal information was exposed in the Tift Regional Health System incident, take a few minutes to submit your claim before the October 15, 2026 deadline. Participating in class actions helps hold companies accountable and ensures that corporations prioritize cybersecurity and consumer protection moving forward.
New cases and investigations, settlement deadlines, and news straight to your inbox.