Skip to main content
Dialysis Giant's $15M Ransomware Settlement: What Failed and What You Can FixBreach & Risk Assessment
4 min readFor Legal and Compliance Teams

Dialysis Giant's $15M Ransomware Settlement: What Failed and What You Can Fix

DaVita, operating over 3,000 kidney dialysis centers across the U.S. and 14 other countries, agreed to pay $15 million to settle class action litigation from a 2025 ransomware attack by the Interlock gang. Nearly 2.7 million people were affected. This isn't about bad luck; it's about specific control failures that turned a security incident into a costly legal issue.

What Happened

In 2025, the Interlock ransomware gang breached DaVita's systems, accessing protected health information (PHI) for about 2.7 million individuals. The attack led to class action litigation over unsecured PHI. DaVita settled for $15 million in 2026. The key issue: unsecured PHI, highlighting where the control framework failed.

Timeline

While the public record lacks detailed intrusion timelines, the pattern aligns with typical ransomware operations:

  • Initial compromise: Interlock accessed DaVita's network.
  • Lateral movement and data staging: Attackers identified and exfiltrated PHI before deploying ransomware.
  • Discovery and disclosure: DaVita identified the breach and began notification processes.
  • Legal action: Affected individuals filed class action litigation.
  • Settlement: DaVita agreed to a $15 million payment in 2026.

The time between the attack and settlement involved months of legal exposure and regulatory scrutiny. Your compliance and legal teams should factor this into breach impact models.

Which Controls Failed or Were Missing

The phrase "unsecured protected health information" indicates specific HIPAA Security Rule failures:

Encryption at rest was absent or incomplete. If the PHI had been encrypted and the keys secure, it would be considered secured under HIPAA's breach notification safe harbor. The settlement suggests it wasn't.

Access controls failed to prevent unauthorized access. Interlock moved laterally to reach PHI repositories, indicating failures in network segmentation or privilege management.

Detection and response capabilities didn't stop exfiltration. The gang had time to identify, stage, and extract PHI. Your monitoring should flag unusual data access patterns and large transfers to external destinations.

Vendor or third-party controls may have been the entry point. Ransomware gangs often breach healthcare organizations through vendors with weaker security. If DaVita's perimeter wasn't directly breached, assume the supply chain was the vector until proven otherwise.

What the Relevant Standard Requires

HIPAA's Security Rule at 45 CFR § 164.312(a)(2)(iv) requires encryption of electronic PHI. It's "addressable," meaning you must implement it or document why it's not reasonable and appropriate, along with alternative measures.

The Breach Notification Rule at 45 CFR § 164.402 defines a breach as unauthorized acquisition, access, use, or disclosure of PHI compromising its security or privacy. If PHI is encrypted per NIST guidance and the key isn't compromised, it's not a breach requiring notification.

That safe harbor could have saved DaVita $15 million.

The Security Rule's administrative safeguards at 45 CFR § 164.308 require risk analysis, risk management, and a sanction policy. If your risk analysis identified ransomware as a threat but you didn't encrypt PHI, you've documented your own non-compliance.

Technical safeguards at 45 CFR § 164.312 require access controls, audit controls, integrity controls, and transmission security. Interlock's success suggests gaps in all four areas.

If a business associate was involved, the Business Associate Agreement requirements at 45 CFR § 164.504(e) obligate you to ensure they implement appropriate safeguards. Your contract doesn't transfer your liability; it just gives you someone to sue after the breach.

Lessons and Action Items for Your Team

Encrypt all PHI at rest, starting with high-risk repositories. Use NIST-validated encryption modules (FIPS 140-2 or 140-3). If legacy systems can't support encryption, that's your business case for replacement or isolation. Document your encryption and key management procedures to demonstrate compliance if breached.

Segment your network to prevent ransomware from moving to PHI. Place PHI repositories behind separate authentication boundaries. Require multi-factor authentication for any system accessing PHI. Disable lateral movement paths by restricting inter-system trust relationships.

Deploy behavioral monitoring to flag bulk PHI access. A user account downloading thousands of records in an hour isn't normal. Your SIEM or data loss prevention tools should alert on volume, velocity, and access patterns inconsistent with job function.

Audit business associate controls quarterly. Review their SOC 2 reports, penetration test results, and incident response capabilities. Verify they're encrypting your data. If not, add it as a contractual requirement or find a different vendor.

Model breach costs at $5.56 per record, then add settlement exposure. DaVita's settlement averages $5.56 per affected individual. That's before notification costs, credit monitoring, regulatory fines, and operational disruption. Use that figure to justify security investments. If encryption costs $500,000 and you're holding PHI for 1 million individuals, you're buying $5.56 million in risk reduction.

Prepare your breach response plan for class action litigation. Your 72-hour notification to the supervisory authority is just the start. Plaintiffs' firms will file class actions quickly. Retain breach counsel before you need them, establish privilege over your incident investigation, and separate your legal response from technical remediation to protect attorney-client communications.

Test backups against ransomware scenarios monthly. If you can't restore PHI from encrypted backups without paying ransom, your recovery plan is theoretical. Verify backup integrity, test restoration speed, and confirm backups are isolated from the production network to prevent ransomware encryption.

The $15 million settlement underscores the cost of unsecured PHI. The controls to prevent it cost far less. Your legal and compliance teams should assess whether your security posture could withstand the scrutiny DaVita faced. If not, start remediation now.

You Might Also Like