Cybersecurity

DaVita Agrees to Pay $15 Million to Settle Data Breach Claims Affecting 2.7 Million People

DaVita, one of the largest providers of dialysis services in the United States, has tentatively agreed to pay $15 million to settle a proposed class action related to a ransomware attack and data breach that occurred last year. The settlement still requires final court approval.

2026-09-03
3 min read
3 views
فريق تحرير certi.news
DaVita Agrees to Pay $15 Million to Settle Data Breach Claims Affecting 2.7 Million People

DaVita, one of the largest providers of kidney care and dialysis services in the United States, has agreed to pay $15 million to settle a proposed class action arising from a data breach that affected approximately 2.7 million people. The company signed the settlement agreement, which was approved by a judge in Colorado last week, but the agreement remains at the preliminary approval stage.

The case concerns a ransomware attack carried out by the Interlock group in April 2025, targeting DaVita systems that operate more than 2,600 outpatient dialysis centers in the United States. After discovering the attack, the company said it had to revert to manual procedures and rely on backup systems while responding to the incident.

What Data Was Compromised?

Information in the complaint and settlement agreement indicates that the breach may have exposed patients’ names, addresses, Social Security numbers, health insurance information, and laboratory test results related to dialysis, as well as images of checks made payable to the company.

After the attackers failed to obtain a ransom, Interlock posted the victims’ personal information on the dark web, according to an initial legal complaint. According to the Health Information Sharing and Analysis Center, the group uses a double-extortion method that combines data theft and system encryption with threats to leak the information.

The Cost Exceeds the Settlement Amount

The article says the attack cost DaVita approximately $25 million during 2025 and also led to at least ten lawsuits being filed. These lawsuits were later consolidated into a single complaint that is now being settled. The plaintiffs say, and the settlement agreement states, that they suffered multiple forms of harm, including an ongoing risk of fraud and identity theft because of the nature of the leaked data.

DaVita described the attack as an incident it handled quickly, and a spokesperson said the company understands the importance of protecting personal information and continues to strengthen its cybersecurity defenses. The source provides no technical details about these defenses or the operational changes the company implemented after the incident.

Why Does This Matter?

The case shows that the impact of a ransomware attack on a healthcare organization is not limited to system outages or the direct cost of recovery. Returning to manual procedures may affect workflow, while the exposure of patient data adds a long-term legal and privacy dimension, particularly when Social Security numbers, test results, and insurance information are involved.

The attack’s connection to a group known for targeting the healthcare sector also illustrates the importance of protecting backups and maintaining the ability to continue providing services when systems are isolated, without assuming that not paying the ransom eliminates the risks. However, the available information alone does not establish the cause of the breach or how successful DaVita’s new security measures have been, nor does it yet resolve the final legal liability.

The court has not yet set a date for the final approval hearing, which is expected to take place next year according to the article. Therefore, the $15 million represents a proposed settlement, not a final judgment or a confirmed payout of claims at this stage.

News source
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news