Dialysis giant DaVita Inc. has confirmed that an April 2025 ransomware intrusion attributed to the Interlock group resulted in the theft of protected health information belonging to roughly 2.7 million individuals, a figure drawn from the company's own breach notification and U.S. Department of Health and Human Services records. HHS filings cited by TECHSHOTS put the quarterly cost of the incident at $13.5 million, comprising $12.5 million in administrative and remediation spend and $1 million in additional patient care expense. Healthcare Dive and CyberInk Times report a larger full-year figure of $25 million in 2025 costs disclosed to investors, which appears to encompass rather than contradict the quarterly number. Separately, a $15 million class action settlement received preliminary approval from a Colorado federal judge on August 21, 2026.
What Happened
The intrusion began on April 12, 2025, when the Interlock ransomware group accessed DaVita's network, exfiltrated data, and encrypted portions of the environment. The HIPAA Journal and ClassActionU place the detection date on or around the same day, with ClassActionU noting the incident was also disclosed in filings to the U.S. Securities and Exchange Commission.
DaVita reverted to manual processes and backup systems to keep clinics running. Accounts differ slightly on operational impact: TECHSHOTS, citing HHS records, describes temporary operational disruptions with patient care continuing uninterrupted across the company's outpatient clinics and home programs, and the HIPAA Journal likewise refers to temporary disruption to operations. CyberInk Times reports that DaVita told HealthExec at the time that there was no disruption to patient care because clinics worked off paper backups. The practical reading is that back-office and IT systems were degraded while clinical delivery was sustained through fallback procedures.
Estimates of DaVita's footprint also vary by source and scope: Healthcare Dive, The Harm Report, and CyberInk Times cite roughly 2,600 U.S. outpatient centers, while TECHSHOTS references nearly 3,000 outpatient clinics and home programs and the HIPAA Journal counts more than 3,000 centers across the U.S. and 14 other countries.
A DaVita spokesperson told Healthcare Dive and CyberInk Times: "We understand the importance of safeguarding personal information. We responded promptly to this attack and remain focused on strengthening our cybersecurity defenses."
What Was Taken
The victim count is the single most inconsistent figure across the record, and the inconsistency is structural rather than journalistic. Reported numbers range from 1.2 million to 2.7 million:
- 2,689,826 individuals is the precise forensic determination reported by the HIPAA Journal, consistent with the ~2.7 million figure in HHS records (TECHSHOTS), Healthcare Dive, and CyberInk Times.
- ~2.4 million people is the class size reported by ClassAction.org and The Harm Report. The Harm Report explicitly frames this as the litigation class drawn from a breach that DaVita's own notification put at 2.7 million.
- 2.3 million members is the class size stated in Judge Regina M. Rodriguez's preliminary approval order, per Settlement Insight, which also notes the court referenced "the resolution of over 2.3 million claims."
- ~1.2 million individuals was the class size pleaded in the original complaint, again per Settlement Insight's reading of the order.
Treat 2.7 million as the breach population (primary notification and regulator filing) and the 2.3 to 2.4 million figures as the narrower settlement class. The 1.2 million figure reflects an early pleading stage, not a revised forensic count.
Data elements reported across sources include names, contact information and addresses, Social Security numbers, health insurance information, clinical information including diagnoses, treatment history and dialysis lab test results, tax information, and images of checks written to the provider. The lab database specifically was identified as a source of exposed records.
On volume, the HIPAA Journal reports Interlock claimed exfiltration of more than 20 terabytes and leaked approximately 1.5 terabytes on its data leak site after the ransom went unpaid. CyberInk Times independently describes a leaked trove of over 683,000 files totaling 1.5TB, corroborating the leaked volume while the 20TB claim rests on attacker assertion alone. CyberInk Times adds that the data was listed for sale on the dark web, with no indication of whether anyone purchased it, and that it is not clear whether a ransom was ever paid, though the leak itself strongly implies non-payment.
Why It Matters
This is a reference case for how healthcare ransomware economics actually resolve. The direct incident cost of $25 million in 2025 and the $15 million settlement are separate line items, and CyberInk Times explicitly notes the investor-disclosed attack cost is unrelated to the settlement. Combined disclosed exposure therefore approaches $40 million before counting regulatory outcomes, which are not addressed in any of these sources.
The per-victim recovery is where the asymmetry becomes stark. Settlement Insight's analysis of the 23-page preliminary approval order notes the $15 million total relief includes a $10 million non-reversionary settlement fund, and that the court itself calculated a payout of $4.17 per person if every class member files, against the widely reported estimated $50 pro rata payment. Settlement Insight also computes a claims schedule from the order's intervals: objections and exclusions at 90 days from August 21, 2026, claims at 120 days, and a fairness hearing no earlier than 180 days. That timeline derives from a single source's reading of the docket and has not been corroborated elsewhere.
The victim population matters operationally. Dialysis patients are chronically ill, frequently older, and dependent on uninterrupted treatment schedules, which raises both the coercive leverage of an encryption event and the downstream fraud risk from exposed SSN plus clinical data combinations.
Interlock is a repeat healthcare offender. Healthcare Dive cites the Health Information Sharing and Analysis Center identifying the group as a known offender in the sector, and notes its attack on Ohio-based Kettering Health. CyberInk Times describes the group as active across healthcare and the public sector.
The Attack Technique
None of the available sources disclose the initial access vector. DaVita has not publicly detailed how Interlock reached the network, and the court filings summarized in these reports allege inadequate security controls generally rather than identifying a specific exploited weakness. Any claim about phishing, edge device exploitation, or credential abuse in this specific intrusion would be speculation.
What is confirmed is the operational model. Interlock ran a textbook double extortion sequence: exfiltrate first, encrypt second, then threaten publication. Healthcare Dive describes the group's standard playbook as stealing sensitive data and encrypting systems, then threatening to leak if the ransom is refused. The Harm Report characterizes the same pattern as a two-step tactic allowing extortion twice, once for decryption and once against publication. DaVita declined to pay, and Interlock followed through by publishing approximately 1.5TB to its leak site. The exfiltration stage completed before DaVita could interrupt the intrusion, per The Harm Report, indicating dwell time sufficient for bulk data staging and egress at multi-terabyte scale.
What Organizations Should Do
- Instrument for bulk egress, not just encryption. A 1.5TB to 20TB exfiltration is not subtle. Baseline normal outbound volume per host and per service account, and alert on sustained transfers to unfamiliar destinations or newly registered cloud storage endpoints. Encryption is the last stage; egress detection is where the loss is still preventable.
- Segment clinical and lab data stores from general IT. The exposed lab database is the highest-sensitivity asset in this incident. Databases holding test results, diagnoses, and SSNs should sit behind separate authentication boundaries with their own access logging, so a foothold in corporate IT does not translate into bulk PHI access.
- Test the manual fallback before you need it. DaVita sustained care delivery on paper processes and backups. That only works if staff have rehearsed it. Run downtime drills covering patient scheduling, treatment orders, and lab result handling with clinical staff, not just IT.
- Validate backup isolation and restoration timing. Backups must be offline or immutable and restoration must be timed against real recovery objectives. A backup that an attacker can encrypt alongside production is not a backup.
- Enforce phishing-resistant MFA on all remote and administrative access. With no disclosed initial access vector, close the categories that dominate healthcare intrusions: VPN and remote access gateways, privileged accounts, and third-party vendor connections.
- Plan for the disclosure phase now. DaVita's $13.5 million quarterly and $25 million annual costs are dominated by administrative and remediation work, not ransom. Pre-build notification workflows, forensic retainers, and regulatory filing processes so the response phase does not become the most expensive part of the incident.
- Track Interlock specifically if you operate in healthcare or public sector. The group has demonstrated repeat targeting of the vertical and consistent willingness to publish when payment is refused. Ingest current Interlock IOCs and hunt retroactively.
Sources: TECHSHOTS DaVita Ransomware Attack Exposes 2.7 Million Pat... | DaVita agrees to pay $15M to settle claims from data breach Health... | DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation | Up to $15M DaVita Settlement Wraps Up Class Action Suit Over ... | DaVita - $15M Deal Over Ransomware Breach of 2.4M Patients | Up to $15 Million DaVita Settlement Wraps Up Class Action Lawsuit O... | DaVita settles ransomware attack lawsuit for $15M | DaVita $15M Settlement: $50 Estimated, $4.17 If Everyone Files — Cl...