Mary Bird Perkins Cancer Center, a nonprofit cancer care organization based in Baton Rouge, Louisiana, recently notified patients that their personal and health information may have been exposed in a data breach at one of its technology vendors.
Health care organizations and the vendors that support them have a responsibility to protect the sensitive medical and financial information entrusted to them, and when that responsibility isn’t met, patients are left to deal with the consequences.
Mary Bird Perkins Cancer Center’s Data Breach Investigation
Mary Bird Perkins Cancer Center disclosed that the breach did not originate within its own systems, but instead occurred at Unlimited Technology Systems LLC, a company that provides practice management software to health care organizations, including Mary Bird Perkins. On October 19, 2025, Unlimited Technology Systems discovered unauthorized activity within its commercial datacenter. A subsequent investigation determined that an unauthorized party had gained access to the system between October 5 and October 10, 2025, and obtained certain personal information and protected health information belonging to patients and related individuals connected to Mary Bird Perkins Cancer Center.
According to the notice, the information involved varied by individual and could include names combined with one or more of the following categories: health insurance and patient balance information, such as insurance policy numbers or claims and benefits details; medical information, including medical record numbers, dates of service, and diagnosis information; scanned documents, such as driver’s licenses or other government identification, insurance cards, and intake forms; Social Security numbers; and other personal details such as date of birth, email address, physical address, phone number, or demographic information. The notice specifies that the breach did not include full patient medical records, medical imaging, or financial account numbers such as credit card or bank account information.
Mary Bird Perkins Cancer Center posted a substitute notice on its website and began mailing consumer notifications on or around July 20, 2026, roughly nine months after Unlimited Technology Systems first discovered the intrusion. This kind of lag between when a vendor detects a breach and when the affected patients of its downstream customers actually learn about it is common in vendor-based breaches, since the vendor typically has to complete its own forensic investigation, identify every affected client organization, and then work with each of those organizations to determine who specifically needs to be notified before any notice goes out.
Vendor breaches like this one are becoming an increasingly common way for patient data to be exposed. Health care organizations frequently rely on third-party software providers to manage scheduling, billing, insurance claims, and other administrative functions, which means a single vulnerability at one vendor can expose the records of patients from many unrelated medical practices and health systems at once. This particular incident illustrates that risk: patients of Mary Bird Perkins Cancer Center were affected not because of anything that happened on the cancer center’s own network, but because of a security failure at a company it contracted with for administrative software.
The combination of data reportedly involved in this breach, including Social Security numbers, medical record information, and scanned government identification, is especially valuable to identity thieves because it can be used to commit both traditional identity theft and medical identity fraud. Medical identity fraud occurs when someone uses a victim’s stolen information to obtain medical services, prescription medications, or durable medical equipment in that person’s name, which can not only result in financial harm but can also corrupt the victim’s own medical records with someone else’s treatment history, a problem that can be difficult and time-consuming to fully untangle.
To help affected individuals, Unlimited Technology Systems has arranged complimentary identity monitoring services through Kroll, and has established a dedicated call center to answer questions and assist with enrollment. Affected individuals who are unsure whether their information was involved, or who have questions about the scope of the incident, are encouraged to review any notice they received directly and to contact the call center listed in that notice.
Vendor-based breaches like this one also raise a practical challenge for affected patients: many people may not immediately recognize the name of the company that actually experienced the security incident, since Unlimited Technology Systems operates behind the scenes as a software provider rather than interacting directly with patients. This can make it harder for individuals to recognize that a notice referencing an unfamiliar vendor name is, in fact, relevant to their own care at a hospital or clinic they know well, which is one reason it’s important to read any breach notification letter carefully rather than assuming it doesn’t apply to you.
When Did This Breach Occur?
Unlimited Technology Systems discovered unauthorized activity within its datacenter on October 19, 2025. Its investigation determined that the unauthorized access itself occurred between October 5 and October 10, 2025. It then took several more months to determine that personal information was involved, complete a review of the affected files, and identify and validate contact information for potentially impacted individuals. Mary Bird Perkins Cancer Center began mailing notification letters to affected patients on or around July 20, 2026, and posted a substitute notice online for individuals whose contact information could not be located.
What Information Was Breached?
The information involved in this breach varied by individual but could include names along with health insurance and patient balance information, medical information such as medical record numbers, dates of service, and diagnosis details, scanned documents like driver’s licenses, other government identification, insurance cards, and intake forms, Social Security numbers, and additional personal details such as date of birth, email address, physical address, phone number, or demographic information. The notice states that full patient medical records, medical imaging, and financial account numbers such as credit card or bank account information were not involved.
What You Can Do
If you received notice that your information was involved in this breach, consider taking the following steps:
- Review your notice letter carefully for instructions specific to your situation.
- Enroll in the complimentary identity monitoring services offered through Kroll, if eligible.
- Review your medical records and health insurance Explanation of Benefits statements for services you don’t recognize.
- Monitor your credit report and financial accounts for unfamiliar activity.
- Consider placing a fraud alert or credit freeze with the major credit bureaus.
- Contact the dedicated call center at 844-576-3063 with questions about your specific notice.
File a Data Breach Lawsuit Against Mary Bird Perkins Cancer Center
If your Social Security number, medical information, or other personal data was exposed because of this vendor breach, you may be entitled to compensation. Health care organizations and the vendors they rely on are expected to protect patients’ sensitive information, and when a security failure like this one exposes that data, affected patients often have legal options.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.