A Georgia health system has agreed to pay $1.2M to resolve a class action over a 2022 Hive ransomware attack that exposed the records of 180,142 patients.
An intruder moved through the health system’s network from August 11 through August 17, 2022, according to a forensic investigation, and files containing patient names, birth dates, Social Security numbers, and clinical details may have been viewed or copied. The Hive ransomware operation took credit for the intrusion, said it had removed 1 TB of data, and posted a portion of that trove on its leak site.
Affected individuals were not notified until August 2023, nearly a year after the intrusion. Multiple lawsuits were consolidated into a single action in Tift County Superior Court, where plaintiffs alleged the system failed to properly safeguard and encrypt patient data. The defendants deny wrongdoing.
Under the settlement, the health system will fund a $1.2M pool for class members, provide two years of credit and medical data monitoring, and reimburse documented losses up to $5,000 per person, with an alternative cash payment of roughly $75. The system also agreed to security upgrades estimated to cost $4.5M over two years. The court granted preliminary approval, a fairness hearing is set for September 14, opt-outs are due September 15, and claims must be filed by October 15.