Memorial Hospital and Manor (Hospital Authority of the City of Bainbridge and Decatur County)

Memorial Hospital and Manor (Hospital Authority of the City of Bainbridge and Decatur County)

In November 2024, Memorial Hospital and Manor suffered a **targeted cyberattack** that compromised its internal network, leading to unauthorized access to sensitive patient data. The breach exposed **private and health information**, including names, dates of birth, Social Security numbers, and protected health records of approximately **105,000 current and former patients**. The incident prompted a class action lawsuit, resulting in a settlement offering affected individuals up to **$5,000 in compensation** for documented losses, $100 for lost time, or a flat $40 payment, alongside **one year of medical identity theft monitoring**.The breach forced the hospital to address financial and reputational damage, with settlement funds covering legal fees, administrative costs, and claimant payouts. While the hospital denied wrongdoing, the attack highlighted vulnerabilities in healthcare cybersecurity, exposing patients to **identity theft, fraud, and medical data exploitation**. The settlement reflects the severe consequences of healthcare data breaches, where compromised personal and health records can have long-term impacts on victims.

Source: https://www.claimdepot.com/settlements/memorial-hospital-data-settlement

Memorial Hospital and Manor cybersecurity rating report: https://www.rankiteo.com/company/memorial-hospital-and-manor

"id": "MEM47104747112425",
"linkid": "memorial-hospital-and-manor",
"type": "Cyber Attack",
"date": "11/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '105,000 (current and former '
                                              'patients)',
                        'industry': 'Healthcare',
                        'location': 'Bainbridge, Decatur County, Georgia, USA',
                        'name': 'Memorial Hospital and Manor (Hospital '
                                'Authority of the City of Bainbridge and '
                                'Decatur County)',
                        'type': 'Hospital/Healthcare Provider'}],
 'customer_advisories': {'claim_deadline': '2026-01-05',
                         'claim_options': ['Documented losses (up to $5,000)',
                                           'Lost time ($25/hour, max $100)',
                                           'Flat payment ($40)',
                                           'Medical data monitoring (1 year of '
                                           'CyEx Medical Shield Pro)'],
                         'payout_methods': ['PayPal',
                                            'Venmo',
                                            'Zelle',
                                            'Paper check'],
                         'payout_timeline': 'Within 85 days of final court '
                                            'approval (hearing on 2026-01-20)',
                         'required_documents': ['Unique ID and PIN from '
                                                'settlement notice',
                                                'Supporting documentation for '
                                                'documented losses (receipts, '
                                                'invoices, bank statements)',
                                                'Written description for lost '
                                                'time claims']},
 'data_breach': {'data_exfiltration': 'Likely (unauthorized access to files)',
                 'number_of_records_exposed': '105,000',
                 'personally_identifiable_information': ['Names',
                                                         'Dates of birth',
                                                         'Social Security '
                                                         'numbers'],
                 'sensitivity_of_data': 'High (includes SSNs and PHI)',
                 'type_of_data_compromised': ['Personal information (PII)',
                                              'Protected Health Information '
                                              '(PHI)']},
 'date_detected': '2024-11-02',
 'description': 'A targeted cyberattack on Memorial Hospital and Manor’s '
                'internal network in November 2024 resulted in unauthorized '
                'access to files containing sensitive personal and health '
                'information of approximately 105,000 current and former '
                'patients. The breach led to a class action lawsuit, which was '
                'settled with options for affected individuals to claim '
                'compensation for documented losses, lost time, or a flat '
                'payment, along with medical data monitoring services.',
 'impact': {'brand_reputation_impact': 'Class action lawsuit and settlement',
            'data_compromised': ['Names',
                                 'Dates of birth',
                                 'Social Security numbers',
                                 'Protected health information'],
            'financial_loss': {'claim_options': [{'coverage_period': '2024-11-02 '
                                                                     'to '
                                                                     '2026-01-05',
                                                  'eligible_expenses': ['Credit '
                                                                        'monitoring '
                                                                        'fees',
                                                                        'ID '
                                                                        'replacement '
                                                                        'costs',
                                                                        'Postage '
                                                                        'for '
                                                                        'bank '
                                                                        'communications',
                                                                        'Identity '
                                                                        'theft '
                                                                        'or '
                                                                        'fraud-related '
                                                                        'losses'],
                                                  'max_amount': '$5,000',
                                                  'type': 'Documented losses'},
                                                 {'eligible_activities': ['Changing '
                                                                          'passwords',
                                                                          'Investigating '
                                                                          'suspicious '
                                                                          'activity',
                                                                          'Researching '
                                                                          'the '
                                                                          'incident'],
                                                  'max_amount': '$100',
                                                  'rate': '$25/hour (max 4 '
                                                          'hours)',
                                                  'type': 'Lost time '
                                                          'compensation'},
                                                 {'amount': '$40',
                                                  'type': 'Flat payment'}],
                               'settlement_fund': {'attorneys_fees': '$500,000',
                                                   'medical_data_monitoring': 'Cost '
                                                                              'determined '
                                                                              'by '
                                                                              'number '
                                                                              'of '
                                                                              'claims',
                                                   'payments_to_claimants': 'Total '
                                                                            'determined '
                                                                            'by '
                                                                            'number '
                                                                            'of '
                                                                            'valid '
                                                                            'claims',
                                                   'service_awards': '$1,500 '
                                                                     'per '
                                                                     'class '
                                                                     'representative'}},
            'identity_theft_risk': 'High (includes SSNs and PHI)',
            'legal_liabilities': 'Class action lawsuit settled (allegations '
                                 'denied by hospital)',
            'systems_affected': ['Internal network files']},
 'investigation_status': 'Settled (class action lawsuit)',
 'references': [{'source': 'Class Action Settlement Notice (Memorial Hospital '
                           '& Manor Data Breach)'},
                {'source': 'Settlement Administrator Contact (MHM Data '
                           'Incident Settlement)'}],
 'regulatory_compliance': {'legal_actions': 'Class action lawsuit (settled; '
                                            'allegations denied)'},
 'response': {'communication_strategy': 'Notice sent to affected individuals; '
                                        'class action settlement with claim '
                                        'options (online/mail)'},
 'stakeholder_advisories': 'Notice sent to 105,000 affected individuals with '
                           'claim instructions',
 'title': 'Memorial Hospital & Manor Data Breach (November 2024)',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.