More than a year after a ransomware attack exposed sensitive information belonging to nearly 2.4 million people, dialysis provider DaVita has agreed to a proposed class action settlement worth up to $15 million.

 

What happened

The agreement received preliminary approval from the US District Court for the District of Colorado on August 21, 2026, but still requires final approval. DaVita discovered the attack on April 12, 2025, after the Interlock ransomware group gained access to its network, removed data, and encrypted some systems. The company implemented containment measures and continued providing patient care, although billing, new-patient admissions, revenue collection, and other operations were disrupted.

According to the settlement documents, the class contains approximately 2.4 million US residents whose information may have been accessed. Compromised data potentially included names, addresses, dates of birth, Social Security numbers, health insurance details, clinical and treatment information, dialysis laboratory results, tax identification numbers, and images of checks. The settlement establishes a $10 million non-reversionary fund and provides for up to $5 million in supplemental payments.

 

In the know

The settlement document notes, “On or around April 12, 2025, DaVita discovered that the ransomware gang Interlock perpetrated the Ransomware Attack on its systems.” Interlock is a financially motivated ransomware group that federal agencies say emerged in September 2024 and targets organizations across North America and Europe based on opportunity. The group uses double extortion, meaning it removes sensitive data before encrypting systems and then threatens to publish the stolen information unless the victim pays. Interlock actors have gained access through compromised websites, fake browser updates, malicious downloads, and ClickFix prompts that persuade users to run harmful commands.

The group operates ransomware capable of encrypting Windows and Linux systems, including virtual machines. DaVita was not its only recent healthcare target. In May 2025, Interlock attacked Kettering Health, causing an outage across 14 hospitals and more than 120 outpatient facilities. The incident compromised information belonging to approximately 1.7 million people and forced staff to use paper records while hundreds of applications were unavailable. Interlock also claimed to have stolen 941 gigabytes of Kettering data before publishing it.

 

Why it matters

Paubox reported that Norton Healthcare agreed to an $11 million settlement after a 2023 BlackCat ransomware attack exposed data belonging to approximately 2.5 million people. Both matters involved allegations that the organizations failed to protect sensitive patient information, while DaVita denied wrongdoing and liability under its agreement. McLaren Health Care separately agreed to a $14 million settlement after ransomware attacks in 2023 and 2024 compromised information belonging to millions of patients and employees. These cases show how one cyber incident can generate years of notification, remediation, and litigation costs after systems are restored. A cohort study published in JAMA Network found that “From January 2016 to December 2021, 374 ransomware attacks on US health care delivery organizations exposed the PHI of nearly 42 million patients.” These are a reflection of the ongoing financial and legal consequences of the pattern across the US healthcare sector.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQs

Is changing the password enough after an email account is compromised?

No, the organization should also revoke active sessions, remove unauthorized forwarding rules, review connected applications, reset MFA methods, and examine account activity.

 

How can an attacker retain access after the password is changed?

Attackers may use stolen session tokens, malicious inbox rules, unauthorized recovery details, delegated permissions, or approved third-party applications to remain connected.

 

What is the difference between email spoofing and account compromise?

Spoofing imitates an email address, while account compromise allows an attacker to operate from the user’s genuine mailbox.