DAVITA INC.
ent_019df1afb0ac3995a96f6ab4d6557438
Disclosures
14
State AG · HHS OCR · SEC 8-K · Leak Site · 9 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
2,689,826
nationwide · HHS OCR CO
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- DAVITA INC.
- Normalized
- davita— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- M2XHYMU3TZNEZURC6H66
- SEC EDGAR CIK
- 0000927066
- Domain
- davita.com
Disclosure history (14)newest first
- ⭐Texas State AGas victim2025-08-04
DaVita Inc. based in Denver, Colorado, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-04-12 and reported on 2025-08-04. 81,740 Texas residents were affected. 915,952 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via Notice by publication in print media;Posted at company website or special website;U.S. Mail.
- 🦬Montana State AGas victim2025-08-01
DaVita Inc reported a data breach to the Montana Attorney General. The breach was reported on 2025-08-01. The breach occurred from 03/24/2025 to 04/12/2025. 761 Montana residents were affected.
- COHHS OCRas victim2025-08-01
DaVita Inc. reported to HHS on 2025-08-01 a Hacking/IT Incident affecting 2,689,826 individuals. Breached information located on Network Server.
- 🌴South Carolina State AGas victim2025-08-01
DaVita Inc. reported a cybersecurity incident affecting its dialysis lab servers. The incident occurred from March 24, 2025, to April 12, 2025, involving unauthorized access to patient data including names, SSNs, DOBs, health insurance info, and clinical/dialysis records. DaVita engaged forensic experts, notified law enforcement, and enhanced security monitoring. No evidence of fraud was found at the time of notification.
- 🦫Oregon State AGas victim2025-08-01
DaVita Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2025-08-01. The breach occurred during 3/24/2025 - 4/12/2025. The breach was discovered on 4/12/2025. 915,952 individuals were affected. Notice was sent on 8/1/2025.
- 🌲Washington State AGas victim2025-08-01
DaVita Inc., a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2025-04-12 and filed notice on 2025-08-01. 13,404 Washington residents were affected. 111 days elapsed between awareness and notification. 19 days to identify the breach. 0 days to contain the breach.
- FEDERALSEC 8-Kas victim2025-04-14
DaVita Inc. filed an 8-K on April 14, 2025, reporting a ransomware incident discovered on April 12, 2025. The attack encrypted network elements, impacting operations and patient care functions. DaVita isolated systems, engaged third-party cybersecurity professionals, and notified law enforcement. The full scope and duration of disruption remain unknown.
- GLOBALLeak Siteas victim2025-04-12
DaVita Inc. provides kidney dialysis services for patients suffering from chronic kidney failure in the United States. The company operates kidney dialysis centers and provides related lab services in outpatient dialysis centers. It also offers outpatient, hospital inpatient, and home-based hemodialysis services; operates clinical laboratories that provide routine laboratory tests for dialysis and other physician-prescribed laboratory tests for ESRD patients; and management and administrative services to outpatient dialysis centers. In addition, the company offers integrated care and disease management services to patients in risk-based and other integrated care arrangements; clinical research programs; physician services; and comprehensive kidney care services. Further, it engages in the provision of acute inpatient dialysis services and related laboratory services; and transplant software business.
- 🦫Oregon State AGas victim2024-07-03
DaVita Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-07-03. The breach occurred during 11/20/2017 - 12/14/2023. The breach was discovered on 6/17/2024. Notice was sent on 7/3/2024.
- COHHS OCRas victim2024-07-03
DaVita Inc. reported to HHS on 2024-07-03 a Unauthorized Access/Disclosure affecting 67,443 individuals. Breached information located on Network Server. The breach involved the disclosure of protected health information (PHI) through web tracking applications on health portal websites and mobile applications. The PHI included clinical and demographic information. DaVita implemented additional safeguards and retrained workforce members.
- 🐻California State AGas victim2024-07-03
DaVita Inc. disclosed that online tracking technologies (pixels) on its health portal and mobile app may have transmitted personal information, including IP addresses, usernames, employment status, and patient classification, to third-party vendors. The incident was determined on June 17, 2024. The breach window listed on the CA AG form is December 14, 2023. DaVita removed/disabled non-compliant technologies and implemented new policies and training. No SSNs, financial data, or clinical records were involved.
- COHHS OCRas victim2022-09-06
DaVita Inc. (CO) reported to HHS on 2022-09-06 a Hacking/IT Incident (email phishing attack) affecting 1,092 individuals. An employee was the victim of a phishing attack compromising PHI including names, Social Security numbers, addresses, dates of birth, diagnoses, lab results, and other treatment information. Breached information located on Network Server. DaVita notified HHS, affected individuals, and the media; provided credit monitoring; implemented additional technical safeguards; and retrained workforce members.
- 🐻California State AGas victim2013-11-05
DaVita reported the theft of an unencrypted laptop from an employee's vehicle on September 6, 2013. The device contained patient health information, including diagnoses, insurance details, and Social Security numbers. DaVita notified affected patients on November 5, 2013, and offered one year of complimentary credit monitoring. The company reviewed encryption practices and implemented additional safeguards.
- CALIFORNIAHHS OCRas victim2013-11-05
DaVita reported to HHS on 2013-11-05 a Theft affecting 11500 individuals. Breached information located on Laptop. An employee's unencrypted laptop containing patient ePHI (diagnosis, insurance, SSN) was stolen from a locked car on September 6, 2013.