DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation

In 2025, the kidney dialysis giant DaVita experienced a ransomware attack that involved the theft of sensitive patient data. Some of the affected individuals took legal action in response to the data breach, which they claim has put them at risk of identity theft and fraud. Following extensive negotiations, a $15 million settlement has been proposed to bring the litigation to an end.

DaVita operates more than 3,000 kidney dialysis centers in the United States and 14 other countries. On April 12, 2025, the Interlock ransomware group accessed its network, exfiltrated data, and encrypted files, causing temporary disruption to operations. The forensic investigation determined that the electronic protected health information of 2,689,826 individuals was compromised in the incident, including names, contact information, Social Security numbers, health insurance information, clinical information, and tax information. Interlock claimed to have exfiltrated more than 20 terabytes of data and proceeded to leak around 1.5 terabytes of that data on its web data leak site when the ransom was not paid.

Multiple class action lawsuits were filed in response to the data breach that alleged that it occurred as a result of the defendant’s failure to implement reasonable and appropriate cybersecurity measures. The lawsuits were consolidated – Julian Jenkins, et al v. DaVita Inc. – in the United States District Court for the District of Colorado as they had overlapping claims.

The lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, invasion of privacy, and violations of state consumer protection statutes. The lawsuit alleged that the plaintiffs face a current, imminent, and ongoing risk of fraud and identity theft as a result of the theft of their personal and health information, and the publication of that information on the dark web. The defendant denies the claims and contentions in the lawsuit, including claims of negligence, fault, and liability.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All parties were able to negotiate a settlement to resolve the litigation, with no admission of liability or wrongdoing by DaVita. The proposed $15,000,000 settlement covers attorneys’ fees and expenses, settlement administration costs, service awards for the five class representatives, and a $10,000,000 non-revisionary settlement fund to pay relief to the class members.

Class members may submit a claim for up to $2,500 as reimbursement for documented, unreimbursed out-of-pocket losses due to the data breach. All class members, including those who submit a claim for reimbursement of losses, may claim a pro rata cash payment. The amount will depend on the number of valid claims received. The class consists of approximately 2.3 million individuals, and if everyone submits a claim, that would amount to around $4.17 per class member; however, based on the expected response rate, the cash payments are anticipated to be around $50 per class member.

The post DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation appeared first on The HIPAA Journal.

ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson

The healthcare giant McKesson recently disclosed a cyberattack in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC).  While the investigation is still in its early stages, McKesson has confirmed that data was exfiltrated, although the extent of data theft has yet to be determined.

McKesson is a large, publicly traded U.S. healthcare and pharmaceutical company that supplies hospitals, health systems, pharmacies, and physician offices with medications, medical-surgical equipment, and specialized oncology and prescription technology solutions. McKesson has not disclosed the name of the group behind the attack, but it appears to be the ShinyHunters extortion group. ShinyHunters added McKesson to its data leak site, and the listing claims that 284 million patient data records were exfiltrated. The claim of 284M patient records relates to rows of raw data, not unique patients. Even so, this is clearly a significant data breach.

McKesson announced the incident on August 28, 2026, explaining that an investigation had been launched following “a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data.” Incident response protocols were activated, and leading cybersecurity experts were engaged to assist with the company’s response. The McKesson cybersecurity team and third-party experts are working to minimize the impact on system availability, determine the nature and scope of the unauthorized activity, and the extent of data theft. Customers have been warned that there may be an impact on system availability and business operations, including intermittent service degradation.

McKesson said it does not believe that customers need to take any action, and that the company is not proactively disconnecting systems within its environment. In an August 29 update, McKesson said the company continues to serve customers across all lines of business, orders are being accepted, and its distribution centers remain open, with products continuing to be shipped across its distribution network.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Based on early investigation results, McKesson said the incident appears to involve data relating to a subset of customers of its Oncology & Multispecialty and Medical-Surgical business units. The initial actions to prevent further unauthorized access appear to have been successful, with no further unauthorized activity detected. According to the SEC filing, the cybersecurity incident was first detected on August 25, 2026. The company has yet to determine whether the incident is material and will have a material impact on the company, its financial condition, or the results of operations.

ShinyHunters is a prolific threat group that engages in data theft and extortion, typically gaining access to victims’ systems through voice phishing/vishing and social engineering. Previous healthcare victims include Medtronic, Abbott Laboratories, iRhythm, AdaptHealth, and DentaQuest. In the past few days, ShinyHunters also claimed responsibility for data theft incidents at Baxter International and Boston Scientific.

According to BleepingComputer, which has been in contact with the group, around 1 terabyte of data was exfiltrated between August 21 and August 25, 2026, and a ransom demand of more than $55 million was issued. ShinyHunters claims that the stolen data includes names, contact information, Social Security numbers, dates of birth, medical record numbers, Medicaid numbers, medication/allergy information, diagnoses, appointment information, and other sensitive data. The data appears to relate to its Salesforce environment and Snowflake.

The post ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson appeared first on The HIPAA Journal.