DisclosureLens
AccidentalHealthcareHealthcareMisdeliveryCustomer Data InvolvedPIIIdentity (basic)EmploymentHealth (basic)MetadataLocationLowResolved

DAVITA INC.

bd_c50ff32979cc8a42 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 17, 2024

Filed

Jul 3, 2024

To disclose

16 days

Affected

Not disclosed

Linked

3 filings

Confidence

64%
Full breach record for DAVITA INC.7 incidents on file

DaVita Inc. disclosed that online tracking technologies (pixels) on its health portal and mobile app may have transmitted personal information, including IP addresses, usernames, employment status, and patient classification, to third-party vendors. The incident was determined on June 17, 2024. The breach window listed on the CA AG form is December 14, 2023. DaVita removed/disabled non-compliant technologies and implemented new policies and training. No SSNs, financial data, or clinical records were involved.

California clockDiscovered Jun 17, 2024Notified Jul 2, 202415d CA 60-day OK16 days discovery → filing

Incident timeline

undetected · 186 days
discovery → filing · 16 days

Dec 14, 2023

Begins

Jun 17, 2024

Discovered

Jul 3, 2024

Filed

vs. sector median

9 wks faster

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Oregon State AGJul 3 · first
HHS OCRJul 3 · first
California State AGJul 3 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.