DAVITA INC.
bd_3622174d2cca4bd7 · schema v1 · pii pii-v1
Full breach record for DAVITA INC. →7 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Interlock on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
DaVita Inc. provides kidney dialysis services for patients suffering from chronic kidney failure in the United States. The company operates kidney dialysis centers and provides related lab services in outpatient dialysis centers. It also offers outpatient, hospital inpatient, and home-based hemodialysis services; operates clinical laboratories that provide routine laboratory tests for dialysis and other physician-prescribed laboratory tests for ESRD patients; and management and administrative services to outpatient dialysis centers. In addition, the company offers integrated care and disease management services to patients in risk-based and other integrated care arrangements; clinical research programs; physician services; and comprehensive kidney care services. Further, it engages in the provision of acute inpatient dialysis services and related laboratory services; and transplant software business.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Apr 12, 2025
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- SEC 8-Kbd_497d2fc88c2cbfe22025-04-14 · +2dVerified by operator
- Montana State AGbd_0dbf28f1535d38bc2025-08-01 · +111dVerified
- Nebraska State AGbd_3ea45d37c7fc59632025-08-01 · +111dVerified
- HHS OCRbd_481b17d7ad14233c2025-08-01 · +111dVerified by operator
Show 5 more filings ↓Show fewer ↑up to 114d gap
- South Carolina State AGbd_5facf976ddce74892025-08-01 · +111dVerified by operator
- Oregon State AGbd_7bfa0289228386bc2025-08-01 · +111dVerified
- Washington State AGbd_e1166f59c017b8252025-08-01 · +111dVerified by operator
- Massachusetts State AGbd_f2d4b9ddac21884f2025-08-01 · +111dVerified by operator
- Texas State AGbd_ebb844d725a949772025-08-04 · +114dVerified
Filing propagation · 10 filings · 8 states
View merged incident ↗Pattern: first filing Apr 12, last Aug 4 (TX) — a 114-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
interlock
According to ransomware.live, Interlock is a ransomware group first observed in September 2024 that targets critical infrastructure sectors including healthcare, government, education, and technology across North America and Europe using double-extortion, with 57+ claimed victims including a major US dialysis provider exposing over two million patient records.