Roughly 2.4 million people fall within a proposed settlement after an attack potentially exposed identifiers, insurance information and medical records. The headline amount is only the beginning of the accounting.
Ransomware · Health data · Class actionTL;DR
- DaVita says it discovered around April 12, 2025 that the ransomware group Interlock had attacked its systems. It publicly disclosed the incident two days later.
- The proposed settlement class contains approximately 2,394,674 people whose personal information was potentially accessed without authorization.
- The information varied by person and may have included Social Security numbers, insurance information, health conditions, treatment records and dialysis laboratory results.
- The deal creates a $10 million fund and a separate supplemental payment of up to $5 million. The total monetary obligation is capped at $15 million.
- Class members could claim a variable cash payment, three years of one-bureau credit monitoring and up to $2,500 for qualifying documented losses.
For affected people, the practical question is not simply whether the deal is worth $15 million. It is how much remains for claims, what proof will be required and whether the court approves the terms.
The Facts
DaVita discovered on or around April 12, 2025 that Interlock, a ransomware group, had attacked its computer systems, according to the settlement agreement. On April 14, the dialysis provider disclosed the incident in a filing with the Securities and Exchange Commission. After completing its investigation, DaVita began notifying potentially affected people in early August.
The proposed settlement reaches far beyond the five named plaintiffs. It defines the class as all people in the United States whose personal information was potentially accessed without authorization and estimates that group at nearly 2.4 million.
The plaintiffs, who said they were current or former DaVita patients, alleged they had supplied their information as a condition of receiving services. Their consolidated complaint accused DaVita of failing to secure that information and alleged that personal data was published on the dark web. Those claims have not been adjudicated. The settlement source does not disclose how the attackers entered DaVita’s systems, how much data they obtained or how many class members experienced confirmed misuse.
DaVita discovered the ransomware attack attributed in the agreement to Interlock.
DaVita disclosed the attack in a Form 8-K securities filing.
The first class action identified in the agreement was filed in Colorado federal court.
Plaintiffs filed their consolidated amended complaint.
DaVita began directly notifying potentially affected individuals after completing its investigation.
The parties reached a settlement in principle after a day-long mediation.
The settlement agreement was filed as an exhibit in the federal case.
What Information Was at Stake
The records at issue were not limited to email addresses or account passwords. Depending on the person, the settlement says the potentially accessed data could combine identity, financial and medical information.
| Category | Information identified in the agreement | Evidentiary status |
|---|---|---|
| Identity and contact data | Names, addresses, dates of birth, Social Security numbers and internal DaVita identifiers | Potentially accessed; the data varied by individual |
| Health and insurance data | Health insurance information, health conditions, treatment information and dialysis lab results | Potentially accessed; not attributed to every class member |
| Financial and tax data | Tax identification numbers and, in limited cases, images of checks written to DaVita | Potentially accessed for some individuals |
| Dark-web publication | Plaintiffs alleged that class members’ personal information was published on the dark web | Allegation; no court finding is established in the supplied record |
That distinction matters. The settlement’s class definition is based on potential unauthorized access, not proof that every listed field was taken from every person. Nor does inclusion in the class establish that a person suffered identity theft or a financial loss.
What the Attack Meant for Affected People
The direct documented consequence is that DaVita identified approximately 2.4 million people whose information may have been accessed and began notifying potentially affected individuals. The proposed deal offers monitoring and reimbursement because misuse of identifiers can require people to watch credit files, dispute transactions or document fraud.
The agreement lists identity theft, falsified tax returns, real-estate title fraud, financial fraud and government-benefit fraud as examples of losses that could qualify for reimbursement. That list is not a finding that those events occurred. The supplied document does not quantify confirmed fraud, identify the total losses already incurred or provide individual accounts of harm.
The source establishes the scale of potential exposure. It does not establish that all 2.4 million people lost money, suffered identity theft or had the same information accessed.
For patients whose medical information was involved, the affected material could reveal health conditions, treatment details or dialysis test results. The agreement recognizes those records as part of the potentially accessed information, but it does not document a separate payment for loss of privacy or emotional distress. Its reimbursement provision expressly excludes emotional distress, bodily injury and punitive damages.
How the $15 Million Deal Actually Works
The proposed settlement is built from two pools with different purposes. It is not a single $15 million account distributed directly among class members.
$10 million settlement fund
Pays notice and administration, settlement-account taxes, court-approved service awards, attorneys’ fees and costs, claimed credit monitoring and pro rata cash payments.
The fund is non-reversionary if the settlement becomes effective, meaning unused money generally does not return to DaVita.
Up to $5 million supplemental amount
Pays valid documented-loss claims and any supplemental attorneys’ fee award approved by the court.
Unused supplemental money is returned to DaVita after the distribution period described in the agreement.
Cash payments
Draft notices estimate a pro rata cash payment of $50. That is not guaranteed. The administrator would divide what remains in the $10 million fund after approved deductions by the number of eligible claims. More claims, higher administration costs or more credit-monitoring elections can reduce the payment.
Documented losses
A class member could request up to $2,500 for an actual, unreimbursed monetary loss fairly traceable to the attack. The loss must have occurred between April 11, 2025 and the eventual claim deadline. Claimants would need outside documentation, an explanation connecting the loss to the attack and a sworn statement that the loss was not already reimbursed.
The settlement administrator would have sole authority to decide whether a claimed loss is valid and fairly traceable. If combined valid losses and a court-approved supplemental fee exceed $5 million, the loss reimbursements would be reduced proportionally.
Credit monitoring
Claimants could receive three years of one-bureau credit monitoring, dark-web monitoring, identity-theft insurance of up to $1 million and managed identity-recovery services. The insurance figure is coverage, not a cash payment. The cost of monitoring comes from the $10 million fund.
The Fee Structure Comes Out of the Same Pools
Class counsel may ask the court for up to one-third of the $10 million settlement fund, plus reasonable litigation costs. That request, if approved, would be paid before pro rata cash payments are calculated.
Counsel may also request up to $1.5 million from the supplemental pool. Because that pool is capped at $5 million and also pays documented-loss claims, approval of the maximum supplemental fee would leave no more than $3.5 million in that pool for those claims before any proportional reduction.
The five class representatives may each seek a service award of up to $2,500 from the main fund. None of these awards is automatic; the court may approve less. The agreement says approval or denial of the fee and service requests does not determine whether the rest of the settlement survives.
“Defendant’s total monetary liability under this Agreement shall not exceed fifteen million United States Dollars ($15,000,000.00).”Settlement and Release Agreement, paragraph 45
The Price of Doing Nothing
If the court approves the deal and it becomes final, class members would need to submit a timely, valid claim to receive money or monitoring. The claim deadline would fall 90 days after the notice date.
| Choice | Benefit | Effect on legal rights |
|---|---|---|
| Submit a claim | Eligible settlement benefits | Remain in the class and release covered claims if the settlement becomes final |
| Do nothing | No settlement benefit | Remain bound by the release if the settlement becomes final |
| Opt out | No settlement benefit | Preserve the ability to pursue covered claims independently |
| Object | May ask the court to reject or alter the deal | Remain in the class and become bound if the court approves the settlement |
The proposed release is broad. Class members who do not opt out would give up known and unknown claims connected to the ransomware attack, the alleged unauthorized disclosure and the facts that could have been asserted in the case. Receiving nothing because no claim was filed would not prevent that release.
What the Deal Does Not Require
Document analysisThe agreement resolves claims through money, monitoring and a release. It does not identify a required cybersecurity audit, a technical remediation plan, minimum security controls or court-supervised changes to DaVita’s data practices.
That absence does not establish that DaVita made no security changes after the attack. It means the supplied settlement agreement does not make specific reforms part of the consideration exchanged for releasing the class claims. The source also does not describe the attack’s entry point or the safeguards in place before it occurred, leaving no documentary basis here for judging whether any undisclosed technical response addresses the original weakness.
DaVita’s Response
DaVita denies the plaintiffs’ legal claims, allegations of wrongdoing and liability. The agreement states that the settlement cannot be treated as an admission that the company violated a law, that the plaintiffs’ allegations are valid or that the claims would be suitable for class treatment outside the settlement.
The parties say they settled to avoid the cost, burden and uncertainty of continued litigation. Plaintiffs’ counsel say the claims have merit and describe the deal as fair and beneficial to the class. Neither position has been tested at trial.
What the Court Has—and Has Not—Decided
The lawsuits were consolidated in the U.S. District Court for the District of Colorado. After informal information exchanges and mediation, the parties executed the agreement and submitted a proposed order asking the court to certify a class for settlement purposes, approve the notice process and schedule a final hearing.
The proposed order attached to the filing contains language that would preliminarily approve the deal, but it is a draft with blank hearing dates and no judge’s signature. It is not itself a ruling. Based only on the supplied source, the court has not made a liability finding, decided that DaVita failed to protect the data or finally approved compensation.
“The Parties agree and understand that neither this Settlement Agreement, nor the Settlement it represents, shall be construed as an admission by DaVita of any wrongdoing whatsoever.”Settlement and Release Agreement, paragraph 19
The Draft Notices Still Need Cleanup
The exhibits are not publication-ready notices. Website addresses, telephone numbers, deadlines and the final-approval hearing remain placeholders. More substantively, the drafts contain inconsistencies that should be resolved before class members are asked to act.
- The controlling agreement and most notice language describe one-bureau credit monitoring. One draft postcard claim panel instead says three-bureau monitoring.
- Several draft notice pages identify the lawsuit as No. 1:25-cv-10358. The filed case number is 1:25-cv-01358.
- The estimated $50 cash payment appears in draft notices, while the agreement makes clear that the final amount depends on deductions and the number of valid claims.
These defects do not prove the settlement will be administered incorrectly. They do show why the court-approved notice, rather than the drafts attached to the December filing, will be the document class members need to follow.
What to Watch
- The federal court: whether it enters preliminary approval, requires changes to the notices or questions the fund and fee structure.
- DaVita and the settlement administrator: the final website, claim form, deadlines and correction of the one-bureau versus three-bureau discrepancy.
- Class counsel’s fee application: the amounts requested from both the $10 million fund and the supplemental pool.
- Final approval: objections, opt-outs and whether the court finds the deal fair, reasonable and adequate.
- Actual claims: the number of valid submissions will determine the cash payment and whether documented-loss reimbursements must be reduced.
The most important unresolved figure is not the $15 million ceiling. It is the amount that will ultimately reach affected people after fees, administration, monitoring costs, proof requirements and participation rates are known.
The source document for this investigation is attached below.



