DaVita Inc., one of the largest kidney dialysis providers in the United States, has agreed to pay $15 million to resolve consolidated class action litigation over the April 2025 Interlock ransomware attack that compromised patient data. Bloomberg Law reports the deal, with lead plaintiff Julian Jenkins, received preliminary approval on Aug. 21, 2026 in the U.S. District Court for the District of Colorado; HIPAA Journal and teiss identify the consolidated case as Julian Jenkins, et al v. DaVita Inc., and shattered.io gives the docket number as No. 1:25-cv-01358-RMR-SBP. The forensic investigation put the number of individuals whose electronic protected health information was compromised at 2,689,826, a figure reported precisely by HIPAA Journal and teiss and rounded to "approximately 2.7 million" by Healthcare Dive, Cyberink Times and informedclearly. Bloomberg Law's account is the outlier, describing the class as "hundreds of thousands of current and former patients." DaVita denies the claims and, per shattered.io, has made no admission of liability.
What Happened
On April 12, 2025, the Interlock ransomware group accessed DaVita's network, exfiltrated data, and encrypted systems, disrupting normal operations. That date is consistent across HIPAA Journal, teiss and informedclearly, the last of which attributes it to DaVita's SEC 8-K filing. informedclearly further reports, citing that filing and the subsequent forensic work, that the initial compromise actually occurred on March 24, 2025, giving the intruders close to three weeks of undetected access before the encryption event. No other source in this set corroborates the March 24 date, so treat the dwell-time figure as single-source.
DaVita has consistently maintained that patient care continued. Healthcare Dive, teiss and Cyberink Times all report the company reverted to manual processes and backup systems, with Cyberink Times noting DaVita told HealthExec at the time that clinics were able to operate off paper backups. The company engaged third-party incident responders and notified federal law enforcement.
Scale of the estate varies by how it is counted. Healthcare Dive and Cyberink Times cite more than 2,600 U.S. outpatient centers; HIPAA Journal and teiss describe more than 3,000 dialysis centers across the United States and 14 other countries. Both are likely correct at different scopes, domestic versus global.
The direct cost of the incident is genuinely disputed. Cyberink Times, Healthcare Dive and teiss all report $25 million in 2025, with Cyberink Times attributing the figure to a DaVita statement to investors. informedclearly reports $13.5 million. The $25 million figure carries more weight, appearing in two established outlets and traceable to company disclosure, but the discrepancy is worth flagging rather than smoothing over. Either way, the cost is separate from the $15 million settlement fund.
What Was Taken
The exposed data set is unusually broad, and unusually damaging for a dialysis population. Combining the source accounts:
- Names, addresses, contact information, dates of birth and demographic information
- Social Security numbers
- Health insurance information and health-insurance numbers
- Clinical information and dialysis lab test results
- Tax information
- Billing and insurance claim data
- Images of checks written to the provider, and, per Bloomberg Law, payment card numbers
Volume claims also differ by source and by who is making them. Interlock claimed to have exfiltrated more than 20 terabytes (HIPAA Journal, teiss, informedclearly). After DaVita did not pay, the group posted roughly 1.5 terabytes to its dark web leak site (HIPAA Journal, teiss, which attributes the leak detail to one of the initial complaints). Cyberink Times characterizes the leaked trove as over 683,000 files totaling 1.5 TB. informedclearly adds that the exfiltration included more than 200 million rows of patient and operational records.
On the ransom itself, accounts differ. HIPAA Journal, Healthcare Dive and teiss all state or imply the ransom went unpaid, which is why the leak occurred. Cyberink Times says only that a ransom was demanded and it is not clear whether one was paid. The non-payment reading is better sourced.
Why It Matters
Dialysis is not elective. Patients on maintenance hemodialysis need treatment roughly three times a week, and a multi-day outage is a clinical emergency rather than an IT inconvenience. That DaVita kept clinics running on paper and backups is the single most defensible element of its response, and it is the operational lesson most healthcare organizations should take from this incident.
The settlement is also a data point in the pricing of healthcare breach liability. Roughly $15 million against approximately 2.69 million class members works out to under $6 per affected individual before fees and administration costs, and shattered.io notes the agreement is framed as "a settlement not to exceed $15,000,000," language that permits the final payout to land lower once claims are tallied. Set against a $25 million direct incident cost and at least ten underlying lawsuits (Healthcare Dive), the total financial exposure is well north of the headline number. The litigation theory itself is the standard modern stack: negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, invasion of privacy, and state consumer protection violations, all premised on a failure to implement reasonable and appropriate security controls.
Finally, informedclearly ranks this as the third-largest healthcare data breach reported in 2025. Combined with SSNs, tax records and check images, the exposed set supports identity theft, tax fraud and account takeover simultaneously, not just medical privacy harm.
The Attack Technique
None of the seven sources discloses Interlock's initial access vector at DaVita. Any specific claim about phishing, a vulnerable edge appliance, or a compromised credential would be speculation, and it is not in the record here.
What the sources do establish is the group's operating model. Healthcare Dive and teiss both cite the Health Information Sharing and Analysis Center identifying Interlock as a known offender against healthcare organizations, including the ransomware attack on Ohio-based Kettering Health. The group runs double extortion: steal data, encrypt systems, then threaten publication of the stolen material to pressure payment. DaVita's case followed that playbook to its conclusion, with the leak site posting occurring after non-payment.
The sequencing matters for defenders. If informedclearly's March 24 compromise date is accurate, exfiltration of 20 TB preceded detection by roughly three weeks. The encryption event was the alarm; the theft had already happened. Detection tuned to ransomware payloads rather than to anomalous outbound data volume will consistently be late.
What Organizations Should Do
- Instrument for egress, not just encryption. Alert on bulk outbound transfers, unusual destinations, and abnormal database read volumes. A 20 TB exfiltration should be detectable long before files start encrypting. Baseline normal data movement per system and per service account so anomalies are visible.
- Assume dwell time and hunt for it. Multi-week undetected access is the norm in these intrusions. Run periodic threat hunts for staging directories, archiving utilities, and credential dumping activity rather than relying solely on preventive controls.
- Segment clinical from corporate and back-office systems. The DaVita exposure spans lab results, billing, insurance claims and scanned check images, which suggests broad lateral reach. Restricting movement between clinical, revenue-cycle and imaging repositories limits how much one intrusion can harvest.
- Rehearse the paper fallback. DaVita's ability to sustain dialysis on manual processes and backups is what kept this from becoming a patient safety event. Test downtime procedures under realistic conditions, including staff who have never used them, and keep current printed census, medication and treatment-parameter data available offline.
- Harden and test backups. Maintain immutable, offline-recoverable copies, verify restoration end to end on a schedule, and confirm backup infrastructure credentials are not reachable from the general domain.
- Reduce retained sensitive data. Check images, tax records and SSNs held longer than legally required convert a network intrusion into a decade of identity fraud liability. Enforce retention limits and encrypt at-rest data stores holding financial identifiers.
- Prepare the legal and notification track in advance. Ten lawsuits arrived quickly and consolidated fast. Pre-negotiated forensic, notification and credit monitoring arrangements shorten the window in which the organization is improvising under regulatory deadlines.
Sources: DaVita settles ransomware attack lawsuit for $15M | DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation | DaVita agrees to pay $15M to settle claims from data breach Health... | DaVita Breach: 2.7M Patients Exposed by Interlock Ransomware crime... | DaVita $15M Data Breach Settlement 2026: What It Pays | DaVita to pay $15 million to settle data breach lawsuit affecting ... | DaVita, Patients Get Early Nod in $15 Million Data Breach Deal