// 1 CRITICAL · 3 ZERO-DAY · 6 CVE · 6 EXPLOIT · 1 ADVISORY IN THE LAST 24H
A Colorado federal court has granted preliminary approval to a settlement of up to $15 million to resolve a class action stemming from the April 2025 ransomware attack by the Interlock gang that exposed over 2.4 million patients. DaVita has already incurred $25 million in operational costs from the incident, nearly double the civil settlement cap.

The Colorado federal court granted preliminary approval on August 21, 2026, to a settlement of up to $15 million to resolve the class action Julian Jenkins, et al v. DaVita Inc., Case No. 1:25-cv-01358. The lawsuit arises from the April 12, 2025 ransomware attack when the Interlock group compromised the systems of the second-largest U.S. dialysis operator. The numbers reveal a stark gap between compensatory justice and actual economic costs: the company has already incurred $25 million in operational expenses for the incident, nearly double the civil settlement cap.

Key Takeaways
  • The settlement fund is set at $15 million with a non-reversionary structure; approximately $10 million remains for direct payments after legal and administrative costs.
  • The class comprises approximately 2.4 million individuals, against the 2,689,826 individuals originally notified by DaVita.
  • Interlock exfiltrated over 20 terabytes of data and published approximately 1.5 terabytes on its leak site after the ransom went unpaid.
  • Class members receive up to $2,500 for documented losses or approximately $50 pro rata without proof of harm, plus three years of single-bureau credit monitoring.

The Scale of Damage: When the Leak Exceeds the Unpaid Ransom

The April 12, 2025 attack followed the double-extortion model: massive exfiltration before system encryption. According to HIPAA Journal's analysis, based on forensic investigation data, Interlock stole over 20 terabytes of information from DaVita. When payment did not occur — the source does not specify whether the company refused, negotiated, or simply ignored the demand — the group published approximately 1.5 terabytes on its leak site. The discrepancy between the volume stolen and the volume made public suggests a residual tranche of data remains in the actor's hands, with potential for deferred extortion or undocumented secondary sale.

The exposed data, detailed in notifications and settlement documents, includes: names, addresses, Social Security numbers, health insurance information, clinical data such as diagnoses, treatment histories, and lab results, tax information, and in some cases, photographs of checks. Together, these constitute a complete identity profile of a chronic population — dialysis patients — characterized by high medical vulnerability and structural dependence on information systems for survival. Unlike a credit card, this information cannot be cancelled or replaced.

The Settlement Structure: Non-Reversionary and Pro Rata

The agreement establishes a $15 million fund with a non-reversionary clause: unclaimed amounts do not revert to DaVita but are redistributed or directed to collateral benefits per mechanisms typical of data-breach class actions. After deducting legal and administrative costs, approximately $10 million remains for direct payments.

Distribution follows a two-tier structure. Class members who document concrete losses — fraud expenses, resolution time, uncovered credit-protection costs — may claim up to $2,500 each. Those who submit no documentation receive approximately $50 pro rata, with the actual figure varying based on the participation rate. Both categories are offered three years of credit monitoring at a single bureau. The source does not specify which bureau or whether the offer is extensible to multiple credit agencies.

"Interlock claimed to have exfiltrated more than 20 terabytes of data and proceeded to leak around 1.5 terabytes of that data on its web data leak site when the ransom was not paid." — HIPAA Journal

The Gap Between Civil Justice and Business Cost

MedTech Dive reports the ransomware attack cost DaVita $25 million in 2025 alone. The figure, isolated to this source and not replicated in other dossiers, likely includes incident response, system recovery, forensic consulting, regulatory notifications, and possible infrastructure hardening. The contrast with the $15 million civil settlement is sharp: compensatory justice covers at most 60 percent of operational costs already incurred, and none of the intangible damages suffered by patients.

DaVita, through a spokesperson cited by MedTech Dive, stated: "We understand the importance of safeguarding personal information... We responded promptly to this attack and remain focused on strengthening our cybersecurity defenses." The company admits no liability or wrongdoing: the settlement terms, cited by HIPAA Journal, explicitly state "no admission of liability or wrongdoing by DaVita." This formula is standard in U.S. civil settlements, but raises the question of whether the lack of admission precludes structural changes in risk management.

Why It Matters

The DaVita case fits a recurring pattern: dialysis providers are privileged ransomware targets due to the combination of high-value health data, IT infrastructure essential to treatment, and a patient population with limited market mobility. The Interlock group, identified as a financially motivated actor with an H-ISAC reference in MedTech Dive, struck a sector where system interruption is not an administrative inconvenience but a vital risk.

No infrastructure overlaps currently emerge linking this specific attack to nation-state campaigns or sanctioned groups. The dossier does not document parallel investigations by HHS OCR or other federal regulators, nor HIPAA administrative sanctions. The absence of confirmed regulatory enforcement leaves questions about what real deterrence operates beyond civil compensation.

The date for the final approval hearing is not set: sources indicate February 2027 or later. Until then, class members may submit claims or opt out of the settlement. The brief does not specify how many individual suits were consolidated into the class action: MedTech Dive mentions "10 or more," but the figure is unverified in other sources.

For patients, the exposure of non-cancellable health data entails a lasting risk of identity theft and medical fraud that no pro rata payment can compensate. For the sector, the message is that ransomware costs systematically exceed class-action caps, turning the settlement into an insurance line item rather than a signal of change.

Frequently Asked Questions

When will the settlement be paid?

The final approval hearing is expected no earlier than 2027. Only after final approval will the claims submission and fund distribution process begin.

Can I receive more than $50 without documenting losses?

No. Pro rata payments without proof of harm are estimated around $50 and vary based on the actual number of participants. The amount is not guaranteed.

Did DaVita pay the ransom?

The dossier neither confirms nor denies that DaVita paid the ransom. It is known that Interlock published data on its leak site, which typically occurs in case of non-payment, but the specific circumstances are not documented.

Sources

Information has been verified against cited sources and is current as of publication.

Sources


Sources and references
  1. tech-insider.org
  2. harmreport.com
  3. hipaajournal.com
  4. classaction.org
  5. medtechdive.com