🏳️‍⚧️ trans rights are human rights 🏳️‍⚧️
Theme
◀
▶

Inside DaVita’s Proposed $15 Million Ransomware Settlement

Data breach investigation

Roughly 2.4 million people fall within a proposed settlement after an attack potentially exposed identifiers, insurance information and medical records. The headline amount is only the beginning of the accounting.

Primary source: settlement agreement filed December 31, 2025 · Jenkins v. DaVita, Inc., No. 1:25-cv-01358 · Status: proposed settlement; court approval not established by the supplied record
Ransomware · Health data · Class action

TL;DR

  • DaVita says it discovered around April 12, 2025 that the ransomware group Interlock had attacked its systems. It publicly disclosed the incident two days later.
  • The proposed settlement class contains approximately 2,394,674 people whose personal information was potentially accessed without authorization.
  • The information varied by person and may have included Social Security numbers, insurance information, health conditions, treatment records and dialysis laboratory results.
  • The deal creates a $10 million fund and a separate supplemental payment of up to $5 million. The total monetary obligation is capped at $15 million.
  • Class members could claim a variable cash payment, three years of one-bureau credit monitoring and up to $2,500 for qualifying documented losses.

For affected people, the practical question is not simply whether the deal is worth $15 million. It is how much remains for claims, what proof will be required and whether the court approves the terms.

Transparency notice: This investigation relies on the settlement agreement, draft claim forms, draft class notices and an unsigned proposed preliminary-approval order filed as an exhibit on December 31, 2025. The documents contain both agreed facts and plaintiffs’ allegations. DaVita denies wrongdoing and liability. The supplied record does not establish a final judgment, a liability finding or even entry of the proposed preliminary-approval order.

The Facts

DaVita discovered on or around April 12, 2025 that Interlock, a ransomware group, had attacked its computer systems, according to the settlement agreement. On April 14, the dialysis provider disclosed the incident in a filing with the Securities and Exchange Commission. After completing its investigation, DaVita began notifying potentially affected people in early August.

The proposed settlement reaches far beyond the five named plaintiffs. It defines the class as all people in the United States whose personal information was potentially accessed without authorization and estimates that group at nearly 2.4 million.

2,394,674Approximate number of people in the proposed settlement class
$15MMaximum total monetary liability under the agreement
3 yearsOne-bureau credit monitoring available to class members who submit a valid claim

The plaintiffs, who said they were current or former DaVita patients, alleged they had supplied their information as a condition of receiving services. Their consolidated complaint accused DaVita of failing to secure that information and alleged that personal data was published on the dark web. Those claims have not been adjudicated. The settlement source does not disclose how the attackers entered DaVita’s systems, how much data they obtained or how many class members experienced confirmed misuse.

April 12, 2025, approximately

DaVita discovered the ransomware attack attributed in the agreement to Interlock.

April 14, 2025

DaVita disclosed the attack in a Form 8-K securities filing.

April 30, 2025

The first class action identified in the agreement was filed in Colorado federal court.

July 30, 2025

Plaintiffs filed their consolidated amended complaint.

Early August 2025

DaVita began directly notifying potentially affected individuals after completing its investigation.

October 6, 2025

The parties reached a settlement in principle after a day-long mediation.

December 31, 2025

The settlement agreement was filed as an exhibit in the federal case.

What Information Was at Stake

The records at issue were not limited to email addresses or account passwords. Depending on the person, the settlement says the potentially accessed data could combine identity, financial and medical information.

CategoryInformation identified in the agreementEvidentiary status
Identity and contact dataNames, addresses, dates of birth, Social Security numbers and internal DaVita identifiersPotentially accessed; the data varied by individual
Health and insurance dataHealth insurance information, health conditions, treatment information and dialysis lab resultsPotentially accessed; not attributed to every class member
Financial and tax dataTax identification numbers and, in limited cases, images of checks written to DaVitaPotentially accessed for some individuals
Dark-web publicationPlaintiffs alleged that class members’ personal information was published on the dark webAllegation; no court finding is established in the supplied record

That distinction matters. The settlement’s class definition is based on potential unauthorized access, not proof that every listed field was taken from every person. Nor does inclusion in the class establish that a person suffered identity theft or a financial loss.

What the Attack Meant for Affected People

The direct documented consequence is that DaVita identified approximately 2.4 million people whose information may have been accessed and began notifying potentially affected individuals. The proposed deal offers monitoring and reimbursement because misuse of identifiers can require people to watch credit files, dispute transactions or document fraud.

The agreement lists identity theft, falsified tax returns, real-estate title fraud, financial fraud and government-benefit fraud as examples of losses that could qualify for reimbursement. That list is not a finding that those events occurred. The supplied document does not quantify confirmed fraud, identify the total losses already incurred or provide individual accounts of harm.

The source establishes the scale of potential exposure. It does not establish that all 2.4 million people lost money, suffered identity theft or had the same information accessed.

For patients whose medical information was involved, the affected material could reveal health conditions, treatment details or dialysis test results. The agreement recognizes those records as part of the potentially accessed information, but it does not document a separate payment for loss of privacy or emotional distress. Its reimbursement provision expressly excludes emotional distress, bodily injury and punitive damages.

How the $15 Million Deal Actually Works

The proposed settlement is built from two pools with different purposes. It is not a single $15 million account distributed directly among class members.

$10 million settlement fund

Pays notice and administration, settlement-account taxes, court-approved service awards, attorneys’ fees and costs, claimed credit monitoring and pro rata cash payments.

The fund is non-reversionary if the settlement becomes effective, meaning unused money generally does not return to DaVita.

Up to $5 million supplemental amount

Pays valid documented-loss claims and any supplemental attorneys’ fee award approved by the court.

Unused supplemental money is returned to DaVita after the distribution period described in the agreement.

Cash payments

Draft notices estimate a pro rata cash payment of $50. That is not guaranteed. The administrator would divide what remains in the $10 million fund after approved deductions by the number of eligible claims. More claims, higher administration costs or more credit-monitoring elections can reduce the payment.

Documented losses

A class member could request up to $2,500 for an actual, unreimbursed monetary loss fairly traceable to the attack. The loss must have occurred between April 11, 2025 and the eventual claim deadline. Claimants would need outside documentation, an explanation connecting the loss to the attack and a sworn statement that the loss was not already reimbursed.

The settlement administrator would have sole authority to decide whether a claimed loss is valid and fairly traceable. If combined valid losses and a court-approved supplemental fee exceed $5 million, the loss reimbursements would be reduced proportionally.

Credit monitoring

Claimants could receive three years of one-bureau credit monitoring, dark-web monitoring, identity-theft insurance of up to $1 million and managed identity-recovery services. The insurance figure is coverage, not a cash payment. The cost of monitoring comes from the $10 million fund.

The Fee Structure Comes Out of the Same Pools

Class counsel may ask the court for up to one-third of the $10 million settlement fund, plus reasonable litigation costs. That request, if approved, would be paid before pro rata cash payments are calculated.

Counsel may also request up to $1.5 million from the supplemental pool. Because that pool is capped at $5 million and also pays documented-loss claims, approval of the maximum supplemental fee would leave no more than $3.5 million in that pool for those claims before any proportional reduction.

The five class representatives may each seek a service award of up to $2,500 from the main fund. None of these awards is automatic; the court may approve less. The agreement says approval or denial of the fee and service requests does not determine whether the rest of the settlement survives.

The Price of Doing Nothing

If the court approves the deal and it becomes final, class members would need to submit a timely, valid claim to receive money or monitoring. The claim deadline would fall 90 days after the notice date.

ChoiceBenefitEffect on legal rights
Submit a claimEligible settlement benefitsRemain in the class and release covered claims if the settlement becomes final
Do nothingNo settlement benefitRemain bound by the release if the settlement becomes final
Opt outNo settlement benefitPreserve the ability to pursue covered claims independently
ObjectMay ask the court to reject or alter the dealRemain in the class and become bound if the court approves the settlement

The proposed release is broad. Class members who do not opt out would give up known and unknown claims connected to the ransomware attack, the alleged unauthorized disclosure and the facts that could have been asserted in the case. Receiving nothing because no claim was filed would not prevent that release.

What the Deal Does Not Require

Document analysis

The agreement resolves claims through money, monitoring and a release. It does not identify a required cybersecurity audit, a technical remediation plan, minimum security controls or court-supervised changes to DaVita’s data practices.

That absence does not establish that DaVita made no security changes after the attack. It means the supplied settlement agreement does not make specific reforms part of the consideration exchanged for releasing the class claims. The source also does not describe the attack’s entry point or the safeguards in place before it occurred, leaving no documentary basis here for judging whether any undisclosed technical response addresses the original weakness.

DaVita’s Response

DaVita denies the plaintiffs’ legal claims, allegations of wrongdoing and liability. The agreement states that the settlement cannot be treated as an admission that the company violated a law, that the plaintiffs’ allegations are valid or that the claims would be suitable for class treatment outside the settlement.

The parties say they settled to avoid the cost, burden and uncertainty of continued litigation. Plaintiffs’ counsel say the claims have merit and describe the deal as fair and beneficial to the class. Neither position has been tested at trial.

What the Court Has—and Has Not—Decided

The lawsuits were consolidated in the U.S. District Court for the District of Colorado. After informal information exchanges and mediation, the parties executed the agreement and submitted a proposed order asking the court to certify a class for settlement purposes, approve the notice process and schedule a final hearing.

The proposed order attached to the filing contains language that would preliminarily approve the deal, but it is a draft with blank hearing dates and no judge’s signature. It is not itself a ruling. Based only on the supplied source, the court has not made a liability finding, decided that DaVita failed to protect the data or finally approved compensation.

The Draft Notices Still Need Cleanup

The exhibits are not publication-ready notices. Website addresses, telephone numbers, deadlines and the final-approval hearing remain placeholders. More substantively, the drafts contain inconsistencies that should be resolved before class members are asked to act.

  • The controlling agreement and most notice language describe one-bureau credit monitoring. One draft postcard claim panel instead says three-bureau monitoring.
  • Several draft notice pages identify the lawsuit as No. 1:25-cv-10358. The filed case number is 1:25-cv-01358.
  • The estimated $50 cash payment appears in draft notices, while the agreement makes clear that the final amount depends on deductions and the number of valid claims.

These defects do not prove the settlement will be administered incorrectly. They do show why the court-approved notice, rather than the drafts attached to the December filing, will be the document class members need to follow.

What to Watch

  • The federal court: whether it enters preliminary approval, requires changes to the notices or questions the fund and fee structure.
  • DaVita and the settlement administrator: the final website, claim form, deadlines and correction of the one-bureau versus three-bureau discrepancy.
  • Class counsel’s fee application: the amounts requested from both the $10 million fund and the supplemental pool.
  • Final approval: objections, opt-outs and whether the court finds the deal fair, reasonable and adequate.
  • Actual claims: the number of valid submissions will determine the cash payment and whether documented-loss reimbursements must be reduced.

The most important unresolved figure is not the $15 million ceiling. It is the amount that will ultimately reach affected people after fees, administration, monitoring costs, proof requirements and participation rates are known.

The source document for this investigation is attached below.

Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 2240