Subscribe To Our Newsletter
Dialysis giant DaVita Inc. has agreed to a class action settlement valued at up to $15 million following a massive April 2025 cyberattack that exposed personal and protected health information.
DaVita Inc., one of the nation’s largest providers of kidney dialysis services, has agreed to a class action settlement worth up to $15 million to resolve claims stemming from an April 2025 ransomware attack that compromised sensitive patient and consumer data.
The settlement addresses consolidated litigation asserting that DaVita failed to maintain adequate cybersecurity measures to protect private records entrusted to its care. According to lawsuit filings, unauthorized cybercriminals breached DaVita’s network systems, encrypting files and exfiltrating highly confidential personally identifiable information (PII) and protected health information (PHI).
Under the preliminarily approved deal, affected current and former DaVita patients may be eligible to receive cash compensation for documented out-of-pocket losses, reimbursement for lost time, and free credit monitoring services.
At ClassActionU.org, our mission is to empower everyday people and hold corporate entities accountable when security lapses put personal privacy at risk. When healthcare institutions handle sensitive patient files, consumers deserve full protection under federal and state privacy statutes. Below is a complete breakdown of the lawsuit, what data was exposed, who is eligible for benefits, and how you can protect your rights.
The legal action originated following an intrusive cyberattack detected by DaVita on or around April 12, 2025. According to public disclosures and filings submitted to the U.S. Securities and Exchange Commission (SEC), an unauthorized third party deployed ransomware that encrypted portions of the company’s internal computer network.
Subsequent investigations revealed that bad actors exfiltrated sensitive databases containing private patient and administrative files before encrypting the servers. A notorious ransomware group later claimed responsibility for the security breach and began publishing portions of the stolen data on the dark web.
Plaintiffs filed class action lawsuits alleging that DaVita ignored industry-standard security protocols, maintained unencrypted patient databases, and failed to detect the unauthorized intrusion in a timely manner. The lawsuit asserted that had DaVita implemented proper digital safeguards and access controls, the cyberattack could have been prevented or mitigated.
Healthcare data breaches are particularly damaging because medical records contain permanent, unchangeable identifying information. While the exact scope of data varied by individual, court documents state that the compromised DaVita files included a combination of sensitive personal and medical records:
Full Names and Contact Details: Home addresses, phone numbers, and email addresses.
Government Identifiers: Social Security numbers, driver’s license numbers, and state identification data.
Demographic and Financial Records: Dates of birth, financial account details, and payment information.
Protected Health Information (PHI): Medical history details, dialysis treatment notes, health insurance policy numbers, physician names, and internal patient tracking IDs.
The exposure of Social Security numbers and health insurance data significantly increases the risk of financial identity theft, medical identity fraud, and targeted phishing scams against vulnerable patients.
When healthcare providers collect personal records, they are bound by federal and state regulations designed to ensure confidentiality and data security. The DaVita class action litigation was grounded in several core legal protections:
Health Insurance Portability and Accountability Act (HIPAA): Establishes national standards to protect sensitive patient health information from being disclosed without patient consent or knowledge.
State Data Privacy Statutes: Laws such as the California Confidentiality of Medical Information Act (CMIA) and state consumer protection acts mandate that companies implement reasonable security procedures to protect consumer records.
Common Law Negligence and Breach of Contract: Allegations that companies fail to exercise due care in safeguarding private data despite express or implied promises made to patients in privacy policy notices.
While DaVita maintains that it acted responsibly and denies all allegations of legal wrongdoing, it agreed to establish the $15 million settlement fund to avoid the distraction, uncertainty, and escalating expense of prolonged courtroom litigation.
You may be eligible to participate in the settlement and receive benefits if you meet the following criteria established by the court:
You are a living individual residing in the United States; and
You were a current or former patient of DaVita, or an individual whose personal or health information was stored on DaVita’s network systems; and
You received a formal data breach notice or letter from DaVita regarding the April 2025 security incident.
The settlement class encompasses hundreds of thousands of current and former patients treated across DaVita’s extensive network of outpatient dialysis clinics nationwide.
The proposed $15 million settlement fund will provide comprehensive financial relief and protective services to class members:
Reimbursement for Out-of-Pocket Expenses: Claimants can receive cash compensation for documented financial losses directly resulting from the breach (such as fraudulent bank charges, credit freeze fees, or identity restoration expenses).
Payment for Lost Time: Class members may claim compensation for personal time spent dealing with the administrative fallout of the data breach.
Pro-Rata Cash Distributions: Remaining funds after administrative expenses, service awards, and expense reimbursements will be distributed among valid claimants as a pro-rata cash payout.
Free Credit and Identity Monitoring Services: Claimants will be offered multi-year credit monitoring and identity theft protection services, including credit bureau alerts and identity restoration insurance.
If you received notice that your data was impacted in the DaVita security breach, it is critical to stay informed about procedural deadlines set by the court:
| Action / Choice | Description | Statutory Timeline |
| Submit a Claim Form | File an online or paper claim to receive cash compensation and credit monitoring benefits. | Deadline to be Announced |
| Opt Out (Exclude Yourself) | Submit a written opt-out request if you wish to retain your right to sue DaVita separately. | Court Cutoff Applies |
| Submit an Objection | File written comments with the court if you disagree with any terms of the proposed settlement. | Court Cutoff Applies |
| Final Approval Hearing | The court holds a formal hearing to review and determine final approval of the settlement terms. | Scheduled by Court |
| Do Nothing | Receive no cash benefits or credit monitoring and waive your legal rights regarding this security incident. | N/A |
Official claim forms and specific deadline dates will be provided once the settlement administrator opens the official claims portal and dispatches formal class notices.
New cases and investigations, settlement deadlines, and news straight to your inbox.