NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation

In 2025, the kidney dialysis giant DaVita experienced a ransomware attack that involved the theft of sensitive patient data. Some of the affected individuals took legal action in response to the data breach, which they claim has put them at risk of identity theft and fraud. Following extensive negotiations, a $15 million settlement has been proposed to bring the litigation to an end.

DaVita operates more than 3,000 kidney dialysis centers in the United States and 14 other countries. On April 12, 2025, the Interlock ransomware group accessed its network, exfiltrated data, and encrypted files, causing temporary disruption to operations. The forensic investigation determined that the electronic protected health information of 2,689,826 individuals was compromised in the incident, including names, contact information, Social Security numbers, health insurance information, clinical information, and tax information. Interlock claimed to have exfiltrated more than 20 terabytes of data and proceeded to leak around 1.5 terabytes of that data on its web data leak site when the ransom was not paid.

Multiple class action lawsuits were filed in response to the data breach that alleged that it occurred as a result of the defendant’s failure to implement reasonable and appropriate cybersecurity measures. The lawsuits were consolidated – Julian Jenkins, et al v. DaVita Inc. – in the United States District Court for the District of Colorado as they had overlapping claims.

The lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, invasion of privacy, and violations of state consumer protection statutes. The lawsuit alleged that the plaintiffs face a current, imminent, and ongoing risk of fraud and identity theft as a result of the theft of their personal and health information, and the publication of that information on the dark web. The defendant denies the claims and contentions in the lawsuit, including claims of negligence, fault, and liability.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All parties were able to negotiate a settlement to resolve the litigation, with no admission of liability or wrongdoing by DaVita. The proposed $15,000,000 settlement covers attorneys’ fees and expenses, settlement administration costs, service awards for the five class representatives, and a $10,000,000 non-revisionary settlement fund to pay relief to the class members.

Class members may submit a claim for up to $2,500 as reimbursement for documented, unreimbursed out-of-pocket losses due to the data breach. All class members, including those who submit a claim for reimbursement of losses, may claim a pro rata cash payment. The amount will depend on the number of valid claims received. The class consists of approximately 2.3 million individuals, and if everyone submits a claim, that would amount to around $4.17 per class member; however, based on the expected response rate, the cash payments are anticipated to be around $50 per class member.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist