DaVita Breach: 2.7M Patients Exposed by Interlock Ransomware

DaVita confirms a ransomware attack by the Interlock group exposed 2.7 million patient records. The April 2025 breach cost $13.5 million and involved 20+ terabytes of stolen data. Learn about the scope, response, and healthcare cybersecurity implications.

DaVita Breach: 2.7M Patients Exposed by Interlock Ransomware
Share
Edition: EN

DaVita Inc., one of the largest kidney dialysis providers in the United States, has confirmed that a ransomware attack compromised the protected health information of approximately 2.7 million patients, making it the third-largest healthcare data breach reported in 2025. The Interlock ransomware group claimed responsibility for the April 2025 cyberattack, which saw threat actors exfiltrate more than 20 terabytes of sensitive data before encrypting network systems.

What Happened in the DaVita Ransomware Attack?

According to DaVita's SEC 8-K filing, the Denver-based company first detected unauthorized activity on April 12, 2025, when attackers encrypted certain elements of its network. A subsequent forensic investigation revealed that the initial compromise occurred on March 24, 2025, giving the threat actors nearly three weeks of undetected access. This extended dwell time allowed them to exfiltrate massive volumes of data, including over 200 million rows of patient and operational records.

Despite the severity of the intrusion, DaVita maintained that critical patient care continued throughout the incident, with facilities relying on paper backup systems while IT teams worked to contain and remediate the attack. The company activated its incident response protocols, engaged third-party cybersecurity experts, and notified federal law enforcement. This incident highlights the growing trend of healthcare ransomware attacks targeting organizations that hold vast repositories of sensitive data.

The Scope of the Data Breach

On August 1, 2025, DaVita reported the breach to the U.S. Department of Health and Human Services' Office for Civil Rights, disclosing that 2,689,826 individuals were affected. The compromised data may include:

  • Full names, addresses, and dates of birth
  • Social Security numbers
  • Clinical and treatment information, including dialysis lab results
  • Health insurance and billing details
  • In limited cases, tax identification numbers and check images

The Interlock ransomware group posted samples of the stolen data on its dark web leak site, claiming to have obtained 20+ terabytes of information. Screenshots reviewed by cybersecurity researchers reportedly showed patient bills, medical procedure details, and internal corporate documents. This breach underscores the critical importance of protected health information security in an increasingly digital healthcare ecosystem.

DaVita's Response and Financial Fallout

DaVita began mailing notification letters to affected individuals in early August 2025, offering complimentary credit monitoring and identity theft protection services through Experian IdentityWorks for 12 to 24 months. The company stated in regulatory filings that it had found no evidence of actual misuse of patient data, though such assurances are often preliminary in the early stages of post-breach investigation.

Financially, the attack has already proven costly. DaVita reported $13.5 million in breach-related expenses during the second quarter of 2025, a figure that excludes potential business interruption costs, regulatory fines, and litigation. The company's stock experienced modest volatility following the disclosure, though the long-term impact on its market position among the nation's 2,600 dialysis centers remains uncertain. This incident demonstrates how cyber incident response costs can escalate rapidly for healthcare organizations lacking robust preparedness frameworks.

The Interlock Ransomware Group: A Growing Threat

Interlock is a ransomware-as-a-service (RaaS) operation that first emerged in September 2024. According to threat intelligence platform Ransomware.live, the group has claimed over 119 victims across North America and Europe, with a particular focus on healthcare, education, government, and manufacturing sectors. The group employs a double-extortion model, encrypting victim networks while threatening to publish stolen data unless a ransom is paid.

Cybersecurity firm Quorum Cyber profiled Interlock's tactics, noting the group's use of legitimate remote access tools such as AnyDesk and ScreenConnect, alongside Cobalt Strike beacons, to move laterally within compromised networks. In July 2025, CISA and international partners issued a joint advisory warning of Interlock's operations, urging critical infrastructure entities to implement recommended mitigations.

What This Means for Healthcare Cybersecurity

The DaVita breach is part of a troubling pattern. According to Comparitech's 2025 roundup, 445 ransomware attacks targeted hospitals, clinics, and direct care providers in 2025 alone, with an additional 191 attacks on healthcare-adjacent businesses. Regulators are responding: the Department of Health and Human Services has proposed new cybersecurity performance goals for the sector, and Congress is considering legislation to mandate minimum security standards for healthcare entities.

"The DaVita incident demonstrates that even large, well-resourced healthcare organizations remain vulnerable to sophisticated ransomware groups," said a cybersecurity analyst familiar with the investigation. "The three-week dwell time before detection is particularly concerning and highlights gaps in network monitoring capabilities."

Industry experts recommend that healthcare organizations adopt a defense-in-depth strategy, including network segmentation, multi-factor authentication, regular data backups, and comprehensive incident response planning. The DaVita case serves as a stark reminder that the cost of prevention is invariably lower than the cost of recovery.

Frequently Asked Questions

What data was stolen in the DaVita ransomware attack?

The attackers accessed names, addresses, Social Security numbers, dates of birth, clinical and treatment information, health insurance details, and in some cases, tax IDs and check images. The Interlock group claims to have stolen over 20 terabytes of data.

How many people were affected by the DaVita breach?

DaVita confirmed that 2,689,826 individuals had their protected health information compromised, making it the third-largest healthcare breach of 2025.

Who is the Interlock ransomware group?

Interlock is a ransomware-as-a-service operation active since September 2024, targeting healthcare, education, government, and manufacturing sectors primarily in North America. The group uses double-extortion tactics, encrypting data and threatening to leak it.

What is DaVita doing to protect affected patients?

DaVita is offering 12 to 24 months of complimentary credit monitoring through Experian IdentityWorks and has implemented enhanced security controls to prevent future incidents.

How much did the DaVita breach cost?

DaVita reported $13.5 million in breach-related expenses in Q2 2025, excluding business interruption, regulatory fines, and potential litigation costs.

Closely related

ChipSoft: Stolen Patient Data Destroyed After Ransomware Hack
Technology
Technology
Closely related

ChipSoft: Stolen Patient Data Destroyed After Ransomware Hack

ChipSoft confirms stolen patient data from April 2026 ransomware attack has been destroyed and never published....

Cyberattack Guide: ChipSoft Patient Data Leak Explained | Healthcare Security
Health
Health
Closely related

Cyberattack Guide: ChipSoft Patient Data Leak Explained | Healthcare Security

Dutch hospitals face major patient data breach as ChipSoft ransomware attack potentially exposes 70% of medical...

ChipSoft Hack Explained: Patient Data Stolen in Dutch Healthcare Ransomware Attack
Health
Health
Closely related

ChipSoft Hack Explained: Patient Data Stolen in Dutch Healthcare Ransomware Attack

Dutch healthcare software provider ChipSoft confirms patient data stolen in April 2026 ransomware attack affecting...

Hackers Demand €1.1M Ransom to Prevent Medical Data Leak
Crime
Crime
Closely related

Hackers Demand €1.1M Ransom to Prevent Medical Data Leak

Hackers demand €1.1 million ransom from Clinical Diagnostics laboratory to prevent publication of stolen medical...

Healthcare Ransomware Crisis: Providers Face Rising Threats
Crime
Crime
Closely related

Healthcare Ransomware Crisis: Providers Face Rising Threats

Healthcare ransomware attacks surged in 2025 with 211 incidents in H1, costing organizations $479K average ransom....

Major Healthcare Ransomware Attack Disrupts Patient Care Nationwide
Crime
Crime
Closely related

Major Healthcare Ransomware Attack Disrupts Patient Care Nationwide

Healthcare faces record ransomware attacks in 2025, disrupting patient care and costing millions. Regulatory updates...