HackingData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
DAVITA INC.
bd_5facf976ddce7489 · schema v1 · pii pii-v1
Full breach record for DAVITA INC. →DaVita Inc. reported a cybersecurity incident affecting its dialysis lab servers. The incident occurred from March 24, 2025, to April 12, 2025, involving unauthorized access to patient data including names, SSNs, DOBs, health insurance info, and clinical/dialysis records. DaVita engaged forensic experts, notified law enforcement, and enhanced security monitoring. No evidence of fraud was found at the time of notification.
Leak gap clock⏱ Leak >90d16 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by interlock about this victim predates this filing by 111 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e1166f59c017b825Washington State AGfiled 2025-08-01Candidate
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/ACTIVE_161128427_1_SC%20AG%20Consumer%20Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 1, 2025
- Raw hash
- 3ecb5c92c7e7ac8256dbd5c9f346a74a04bdb48fa0db647c6d1bee52e4443591
Reporting entity
- Name
- DAVITA INC.norm: davita
- Domain
- davita.com
Victim entity
- Name
- DAVITA INC.norm: davita
- Domain
- davita.com
Incident
- Discovered
- Apr 12, 2025
- Materiality determined
- —
- Notification sent
- Aug 5, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported the incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(111 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.