Desk live·
ForensicPost
Ransomware/Healthcare/File 25-0412

Interlock Held DaVita for 19 Days and Took Records on 2.7 Million People

Interlock held access to DaVita from 24 March to 12 April 2025 and took a laboratory database covering 2,689,826 people. Critical dialysis care continued throughout.

Constructed geometry · not a chart of case data
JurisdictionUSADenver, Coloradothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetDaVita
ActorInterlock
D. Kennedy12 min readConfidence: high2 sources reviewed

The Interlock ransomware group had access to systems at the kidney dialysis provider DaVita from 24 March to 12 April 2025 — nineteen days. It reached a laboratory database holding protected health information for 2,689,826 individuals. Reporting indicates critical care delivered to patients across the United States was not affected.

Dialysis Is The Hardest Possible Continuity Test

A patient on maintenance haemodialysis typically requires treatment three times a week. Missing sessions is not an inconvenience; it produces fluid overload and electrolyte derangement on a timescale of days.

There is no version of "we will reschedule when systems are back" that works. Whatever DaVita had in place to keep treatment running through a nineteen-day intrusion is the most consequential fact in this file, and it is the part that received the least coverage.

The Laboratory Database Was The Loss

The compromised system held laboratory data — which for a dialysis population is a detailed longitudinal clinical record: kidney function over time, comorbidities, medication response.

That is a more revealing dataset than a typical patient index. It is the ambulatory-monitoring problem this desk filed at 26-0617 in a different form: continuous clinical measurement is a more intimate record than an episodic one.

Nineteen Days Is Short, And It Was Enough

Against the dwell times in this database — 304 days at Estée Lauder in 26-0620, five months at Salesloft in 25-0820 — nineteen days indicates reasonably effective detection.

It was still sufficient to locate and exfiltrate a database covering 2.7 million people. Detection speed bounds the damage; it does not prevent it, which is the argument this desk made from the other direction at 26-0630.

How we reported this

Compiled from public reporting, listed below. The access window and affected figure are as reported. We have not reviewed clinical outcomes and are not asserting patient harm. Corrections: corrections@forensicpost.com.

Sources
  1. Largest healthcare data breaches of 2025HIPAA Journal
  2. These are the biggest health data breaches in the first half of 2025Chief Healthcare Executive
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary