DAVITA INC.
ent_019df1afb0ac3995a96f6ab4d6557438
Disclosures
22
State AG · HHS OCR · SEC 8-K · Leak Site · 13 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
2,689,826
nationwide · HHS OCR CO
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- DAVITA INC.
- Normalized
- davita— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- M2XHYMU3TZNEZURC6H66
- SEC EDGAR CIK
- 0000927066
- Domain
- davita.com
Disclosure history (22)newest first
- Texas State AGas victim2025-08-04
DaVita Inc. based in Denver, Colorado, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-04-12 and reported on 2025-08-04. 81,740 Texas residents were affected. 915,952 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via Notice by publication in print media;Posted at company website or special website;U.S. Mail.
- Montana State AGas victim2025-08-01
DaVita Inc. notified Montana residents of a data breach affecting dialysis lab databases. Unauthorized access occurred March 24–April 12, 2025. Data exposed included PII (SSN, DOB, address), PHI (health conditions, lab results), and financial data. DaVita engaged forensic experts, notified law enforcement, and offered credit monitoring.
- Nebraska State AGas victim2025-08-01
DaVita Inc. notified Nebraska AG of a breach affecting dialysis lab records. Unauthorized access occurred March 24–April 12, 2025. Data included PII (SSN, DOB), PHI (clinical/dialysis data), and financial info. DaVita engaged forensic experts, notified law enforcement, and offered credit monitoring. Incident contained April 12, 2025.
- COLORADOHHS OCRas victim2025-08-01
DaVita Inc. reported to HHS on 2025-08-01 a Hacking/IT Incident affecting 2,689,826 individuals. Breached information located on Network Server.
- South Carolina State AGas victim2025-08-01
DaVita Inc. reported a cybersecurity incident affecting its dialysis lab servers. The incident occurred from March 24, 2025, to April 12, 2025, involving unauthorized access to patient data including names, SSNs, DOBs, health insurance info, and clinical/dialysis records. DaVita engaged forensic experts, notified law enforcement, and enhanced security monitoring. No evidence of fraud was found at the time of notification.
- Oregon State AGas victim2025-08-01
DaVita Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2025-08-01. The breach occurred during 3/24/2025 - 4/12/2025. The breach was discovered on 4/12/2025. 915,952 individuals were affected. Notice was sent on 8/1/2025.
- Washington State AGas victim2025-08-01
DaVita Inc. reported a ransomware incident affecting Washington residents. Unauthorized access occurred from March 24 to April 12, 2025. The breach exposed PHI, SSNs, and financial data for 13,404 individuals. DaVita engaged forensic experts, notified law enforcement, and offered credit monitoring.
- Massachusetts State AGas victim2025-08-01
DaVita Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-08-01. 7,829 Massachusetts residents were affected.
- FEDERALSEC 8-Kas victim2025-04-14
DaVita Inc. filed an 8-K on April 14, 2025, reporting a ransomware incident discovered on April 12, 2025. The attack encrypted certain elements of the company's network and is impacting some of its operations; DaVita states it continues to provide patient care. DaVita isolated systems, engaged third-party cybersecurity professionals, and notified law enforcement. The full scope and duration of disruption remain unknown.
- GLOBALLeak Siteas victim2025-04-12
DaVita Inc. provides kidney dialysis services for patients suffering from chronic kidney failure in the United States. The company operates kidney dialysis centers and provides related lab services in outpatient dialysis centers. It also offers outpatient, hospital inpatient, and home-based hemodialysis services; operates clinical laboratories that provide routine laboratory tests for dialysis and other physician-prescribed laboratory tests for ESRD patients; and management and administrative services to outpatient dialysis centers. In addition, the company offers integrated care and disease management services to patients in risk-based and other integrated care arrangements; clinical research programs; physician services; and comprehensive kidney care services. Further, it engages in the provision of acute inpatient dialysis services and related laboratory services; and transplant software business.
- Oregon State AGas victim2024-07-03
DaVita Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-07-03. The breach occurred during 11/20/2017 - 12/14/2023. The breach was discovered on 6/17/2024. Notice was sent on 7/3/2024.
- COLORADOHHS OCRas victim2024-07-03
DaVita Inc. reported to HHS on 2024-07-03 a Unauthorized Access/Disclosure affecting 67,443 individuals. Breached information located on Network Server. The breach involved the disclosure of protected health information (PHI) through web tracking applications on health portal websites and mobile applications. The PHI included clinical and demographic information. DaVita implemented additional safeguards and retrained workforce members.
- California State AGas victim2024-07-03
DaVita Inc. disclosed that online tracking technologies (pixels) on its health portal and mobile app may have transmitted personal information, including IP addresses, usernames, employment status, and patient classification, to third-party vendors. The incident was determined on June 17, 2024. The breach window listed on the CA AG form is December 14, 2023. DaVita removed/disabled non-compliant technologies and implemented new policies and training. No SSNs, financial data, or clinical records were involved.
- COLORADOHHS OCRas victim2022-09-06
DaVita Inc. (CO) reported to HHS on 2022-09-06 a Hacking/IT Incident (email phishing attack) affecting 1,092 individuals. An employee was the victim of a phishing attack compromising PHI including names, Social Security numbers, addresses, dates of birth, diagnoses, lab results, and other treatment information. Breached information located on Network Server. DaVita notified HHS, affected individuals, and the media; provided credit monitoring; implemented additional technical safeguards; and retrained workforce members.
- Massachusetts State AGas victim2016-04-22
DaVita HealthCare Partners Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-04-22. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2013-11-12
DaVita HealthCare Partners reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2013-11-12. 16 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2013-11-05
DaVita reported the theft of an unencrypted laptop from an employee's vehicle on September 6, 2013. The device contained patient health information, including diagnoses, insurance details, and Social Security numbers. DaVita notified affected patients on November 5, 2013, and offered one year of complimentary credit monitoring. The company reviewed encryption practices and implemented additional safeguards.
- CALIFORNIAHHS OCRas victim2013-11-05
DaVita reported to HHS on 2013-11-05 a Theft affecting 11500 individuals. Breached information located on Laptop. An employee's unencrypted laptop containing patient ePHI (diagnosis, insurance, SSN) was stolen from a locked car on September 6, 2013.
- Delaware State AGas victim2013-11-05
DaVita Healthcare Partners reported a data breach to the Delaware Attorney General. The breach occurred on 2013-09-01. Notice was filed on 2013-11-05. Information involved: health basic, identity government.
- Massachusetts State AGas victim2009-10-26
DaVita reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2009-10-26. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2008-11-17
DaVita, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2008-11-17. 25 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas reporting2008-03-03
DaVita Inc. (via subsidiary OVA Renal Healthcare, Inc.) notified New Hampshire authorities on March 3, 2008, of a data breach affecting 9 residents. A password-protected laptop containing patient PII (SSNs, medical insurance info) was stolen from an employee's vehicle around February 4, 2008. Law enforcement was notified, and individual letters were sent on February 21, 2008.
Subsidiary disclosures (3)filed by group companies
◈ These filings were made by or about subsidiaries of DAVITA INC. — not by DAVITA INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- FLORIDAHHS OCRvia Physicians Dialysis2021-06-25
Physicians Dialysis reported to HHS on 2021-06-25 a Hacking/IT Incident affecting 1998 individuals. Breached information located on Network Server. The incident involved a ransomware attack exposing ePHI including names, addresses, DOB, SSNs, diagnoses, and insurance info. Response included password resets and technical safeguards.
- Massachusetts State AGvia Renal Treatment Centers Southeast, LP2009-08-31
Renal Treatment Centers - Southeast, LP reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2009-08-31. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGvia Renal Treatment Centers Southeast, LP2009-08-25
Renal Treatment Centers Southeast, LP (affiliate of DaVita Inc.) reported the theft of password-protected desktop computers from a Dallas facility on May 21, 2009. The theft potentially exposed personal and health information, including SSNs, for one New Hampshire resident. Notifications were sent on August 21, 2009.