Tift Regional Health System
Disclosed Oct 14, 20223 years ago180,142 affectedConfirmed
The covered entity (CE), Tift Regional Health System, reported that it was the victim of a cyber-attack affecting the protected health information (PHI) of 180,142 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license numbers, diagnoses, lab results, medications, financial information, and Social Security numbers. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional administrative and technical safeguards and provided complimentary credit monitoring services to affected individuals. The CE also provided its business associates and employees with additional training on the requirements to secure PHI. OCR provided the CE with technical assistance regarding the HIPAA Breach Notification Rule.
What is known
| People affected | 180,142 (as reported by the organization) |
|---|---|
| Disclosed | Oct 14, 2022 |
| Happened | Aug 11, 2022 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Vermont Attorney General: 2023-08-11 Tift Regional Health System Data Breach Notice to Consumersago.vermont.gov · Official notice | Official notice |
| Indiana Attorney General 2023 data breach report: Tift Regional Health Systemin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Tift Regional Health System (Healthcare Provider, GA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 14, 2022 | 180,142 |
| Vermont AGresidents of VT | Aug 11, 2023 | |
| Indiana AGresidents of IN | Aug 11, 2023 | 154 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · disclosed: 2023-08-11 to 2022-10-14 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Tift Regional Health System, reported that it was the victim of a cyber-attack affecting the protected health information (PHI) of 180,142 individuals. The PHI involved included names, addresses, dates of birth, dri · backfill source
- 2026-09-25 · records_basis: empty to organization · backfill source
- 2026-09-25 · records: empty to 180142 · backfill source
- 2026-09-25 · occurred: empty to 2022-08-11 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Vermont AG), confirmed by Vermont AG. Record counts are as reported. Not legal advice.