The Challenge
On April 12, 2025, the Interlock ransomware group infiltrated DaVita's network, stealing data and encrypting files. This breach impacted one of the largest kidney dialysis providers in the U.S., compromising the electronic protected health information (ePHI) of 2,689,826 individuals. The stolen data included names, contact information, Social Security numbers, health insurance details, clinical records, and tax information.
Interlock claimed to have stolen over 20 terabytes of data. When DaVita refused to pay the ransom, the group published about 1.5 terabytes on its dark web leak site. This led to multiple class action lawsuits, consolidated in the United States District Court for the District of Colorado under Julian Jenkins, et al v. DaVita Inc. The plaintiffs alleged negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, invasion of privacy, and violations of state consumer protection statutes.
The core allegation was that DaVita failed to implement reasonable cybersecurity measures. This led to a $15 million settlement proposal, with no admission of liability, to resolve the litigation.
The Environment and Constraints
DaVita operates over 3,000 kidney dialysis centers across the U.S. and 14 other countries, creating a vast attack surface. Each location handles sensitive patient data under the HIPAA Security Rule's administrative, physical, and technical safeguard requirements. The organization must balance operational continuity at numerous sites with centralized security controls to prevent unauthorized access.
Ransomware groups like Interlock now use double-extortion tactics: stealing data first, then encrypting systems, and threatening publication if the ransom isn't paid. This changes the risk calculation. Even if systems are restored from backups, the stolen data remains compromised. Your Breach Notification Rule obligations persist despite recovery.
The forensic investigation was crucial for both legal defense and settlement terms. Without it, DaVita couldn't determine the scope of compromised records, the timeline of unauthorized access, or specific data elements at risk. This investigation established the 2.69 million figure defining the class.
The Approach Taken
DaVita engaged forensic investigators immediately after detecting the intrusion. The investigation mapped the attack timeline, identified compromised systems, and cataloged accessed data types. This informed breach notifications to affected individuals and the legal strategy.
Instead of litigating negligence claims through trial, DaVita negotiated a settlement with a $10 million non-revisionary fund. Class members can claim up to $2,500 for documented losses directly tied to the breach, such as fraud charges and credit monitoring costs. All class members, regardless of documented losses, qualify for a pro rata cash payment from the remaining fund.
The settlement also covers attorneys' fees, administration costs, and service awards for the five class representatives. DaVita maintained its position: no admission of negligence, fault, or liability. The settlement resolves claims without establishing legal precedent on what "reasonable and appropriate" cybersecurity measures require.
Results and Metrics
The proposed $15 million settlement includes several components. The $10 million non-revisionary fund ensures distribution to class members regardless of claim volume. If all 2.3 million eligible class members submit valid claims, the pro rata payment drops to about $4.17 per person. Based on typical response rates in data breach settlements, DaVita's counsel anticipates payments closer to $50 per class member.
This structure creates an interesting dynamic. Class members with documented losses can recover actual damages up to $2,500. Those without documented harm still receive compensation, but the amount depends on claim volume.
The settlement doesn't include injunctive relief requiring DaVita to implement specific security controls. There's no consent decree mandating multi-factor authentication, network segmentation, or endpoint detection. The resolution is purely financial.
What They Would Do Differently
While DaVita hasn't publicly detailed its security posture before or after the incident, the class action allegations highlight gaps that any covered entity should address proactively.
Access controls are crucial. Ransomware groups often gain access through phishing, exploiting vulnerabilities, or purchasing access. Once inside, they move laterally to find high-value targets. The HIPAA Security Rule's Required Specification at 45 CFR § 164.312(a)(1) for unique user identification, combined with the Addressable Specification for automatic logoff at § 164.312(a)(2)(iii), would limit how far a compromised account can roam.
Network segmentation contains breaches. If your dialysis centers, billing systems, HR databases, and clinical applications all sit on the same network, an attacker who compromises one system can reach them all. The Security Rule's Addressable Specification for integrity controls at § 164.312(c)(1) suggests mechanisms to protect ePHI from improper alteration or destruction. Segmentation isn't explicitly required, but it's effective in meeting that specification.
Forensic readiness reduces legal exposure. DaVita's investigation determined the scope of compromised data, requiring time, resources, and expertise. Organizations that maintain detailed logs, implement endpoint detection and response tools, and document their network architecture can complete forensic investigations faster and with greater precision. Faster investigations mean faster breach notifications, reducing uncertainty for affected individuals.
Takeaways for Your Team
Document your risk analysis and safeguard decisions. The Security Rule at 45 CFR § 164.308(a)(1)(ii)(A) requires a risk analysis assessing threats to ePHI. When plaintiffs allege you failed to implement "reasonable and appropriate" measures, your risk analysis serves as evidence of informed decisions about which safeguards to deploy. If you haven't documented why you chose certain controls over others, you're arguing from a weak position.
Treat forensic investigation as a compliance deliverable, not just an IT project. Your forensic report determines your Breach Notification Rule obligations, OCR reporting requirements, and potential exposure in class action litigation. Engage qualified forensic investigators who understand healthcare data environments and can testify to their findings if necessary.
Understand that "no admission of liability" doesn't mean "no problem." DaVita paid $15 million to resolve claims it denies. That's a rational business decision when litigation costs, distraction, and reputational damage exceed the settlement amount. But it's also a signal that your cybersecurity posture will be judged by plaintiffs' attorneys, juries, and OCR investigators who don't care about your budget constraints or competing priorities.
Recognize the double-extortion model changes your risk calculus. Backup and recovery plans address ransomware encryption but not data exfiltration. If attackers steal your data before encrypting it, you face Breach Notification Rule obligations even if you restore from backups and never pay the ransom. Your security controls need to detect and block data exfiltration, not just file encryption.
The class members in this case will receive between $4 and $2,500 each, depending on their documented losses and the claim rate. DaVita will pay $15 million and move forward with no admission of wrongdoing. But the real cost isn't measured in settlement funds. It's measured in the 2.69 million individuals whose data now circulates on dark web forums, the operational disruption during the attack, and the ongoing reputational damage to an organization that provides life-sustaining dialysis treatment.
Your forensic investigation happens after the breach. Your access controls, network segmentation, and logging capabilities need to be in place before the first phishing email lands.



