DaVita has agreed to pay up to $15 million to settle class action litigation over its April 2025 ransomware attack, which compromised data on 2,689,826 current and former dialysis patients. The US District Court for the District of Colorado granted preliminary approval to the deal in Jenkins et al. v. DaVita Inc. on August 21, 2026.

The Interlock ransomware group carried out the April 12, 2025 attack and claimed to have taken more than 20 terabytes of data. Roughly 1.5 terabytes ended up leaked on the group's dark web site. The stolen records included names, Social Security numbers, health insurance details, clinical information, treatment data, and lab results.

Class members, a group of roughly 2.4 million people, can claim up to $2,500 for documented out-of-pocket losses, a pro rata cash payment expected to land near $50, and three years of credit monitoring with identity theft insurance. About $10 million of the fund is earmarked for class relief, with the remainder covering legal fees and administration. DaVita settled with no admission of liability, and the final approval hearing is expected in February 2027.

For device makers this is the going rate. Courts are clearing healthcare breach settlements in the low tens of millions, and DaVita reached this one without admitting liability. A product organization holding patient telemetry in the cloud should budget for breach litigation the way it budgets for a recall.