Were you recently affected by a data breach?

Mary Bird Perkins Cancer Center Data Breach

Mary Bird Perkins Cancer Center has notified patients that a breach at its software vendor, Unlimited Technology Systems, exposed personal and health information. If you received a notice, contact us to learn about your legal options.

Mary Bird Perkins Cancer Center
Date of Breach: Unauthorized access: October 5-10, 2025 (vendor: Unlimited Technology Systems)
CAU logo

Who was affected:

Clients of Mary Bird Perkins Cancer Center

Impacted Data:

Names, Social Security numbers, medical record numbers, health insurance and patient balance information, dates of service, diagnosis information, scanned identification documents, dates of birth, addresses

Mary Bird Perkins Cancer Center, a nonprofit cancer care organization based in Baton Rouge, Louisiana, recently notified patients that their personal and health information may have been exposed in a data breach at one of its technology vendors.

Health care organizations and the vendors that support them have a responsibility to protect the sensitive medical and financial information entrusted to them, and when that responsibility isn’t met, patients are left to deal with the consequences.

Mary Bird Perkins Cancer Center’s Data Breach Investigation

Mary Bird Perkins Cancer Center disclosed that the breach did not originate within its own systems, but instead occurred at Unlimited Technology Systems LLC, a company that provides practice management software to health care organizations, including Mary Bird Perkins. On October 19, 2025, Unlimited Technology Systems discovered unauthorized activity within its commercial datacenter. A subsequent investigation determined that an unauthorized party had gained access to the system between October 5 and October 10, 2025, and obtained certain personal information and protected health information belonging to patients and related individuals connected to Mary Bird Perkins Cancer Center.

According to the notice, the information involved varied by individual and could include names combined with one or more of the following categories: health insurance and patient balance information, such as insurance policy numbers or claims and benefits details; medical information, including medical record numbers, dates of service, and diagnosis information; scanned documents, such as driver’s licenses or other government identification, insurance cards, and intake forms; Social Security numbers; and other personal details such as date of birth, email address, physical address, phone number, or demographic information. The notice specifies that the breach did not include full patient medical records, medical imaging, or financial account numbers such as credit card or bank account information.

Mary Bird Perkins Cancer Center posted a substitute notice on its website and began mailing consumer notifications on or around July 20, 2026, roughly nine months after Unlimited Technology Systems first discovered the intrusion. This kind of lag between when a vendor detects a breach and when the affected patients of its downstream customers actually learn about it is common in vendor-based breaches, since the vendor typically has to complete its own forensic investigation, identify every affected client organization, and then work with each of those organizations to determine who specifically needs to be notified before any notice goes out.

Vendor breaches like this one are becoming an increasingly common way for patient data to be exposed. Health care organizations frequently rely on third-party software providers to manage scheduling, billing, insurance claims, and other administrative functions, which means a single vulnerability at one vendor can expose the records of patients from many unrelated medical practices and health systems at once. This particular incident illustrates that risk: patients of Mary Bird Perkins Cancer Center were affected not because of anything that happened on the cancer center’s own network, but because of a security failure at a company it contracted with for administrative software.

The combination of data reportedly involved in this breach, including Social Security numbers, medical record information, and scanned government identification, is especially valuable to identity thieves because it can be used to commit both traditional identity theft and medical identity fraud. Medical identity fraud occurs when someone uses a victim’s stolen information to obtain medical services, prescription medications, or durable medical equipment in that person’s name, which can not only result in financial harm but can also corrupt the victim’s own medical records with someone else’s treatment history, a problem that can be difficult and time-consuming to fully untangle.

To help affected individuals, Unlimited Technology Systems has arranged complimentary identity monitoring services through Kroll, and has established a dedicated call center to answer questions and assist with enrollment. Affected individuals who are unsure whether their information was involved, or who have questions about the scope of the incident, are encouraged to review any notice they received directly and to contact the call center listed in that notice.

Vendor-based breaches like this one also raise a practical challenge for affected patients: many people may not immediately recognize the name of the company that actually experienced the security incident, since Unlimited Technology Systems operates behind the scenes as a software provider rather than interacting directly with patients. This can make it harder for individuals to recognize that a notice referencing an unfamiliar vendor name is, in fact, relevant to their own care at a hospital or clinic they know well, which is one reason it’s important to read any breach notification letter carefully rather than assuming it doesn’t apply to you.

When Did This Breach Occur?

Unlimited Technology Systems discovered unauthorized activity within its datacenter on October 19, 2025. Its investigation determined that the unauthorized access itself occurred between October 5 and October 10, 2025. It then took several more months to determine that personal information was involved, complete a review of the affected files, and identify and validate contact information for potentially impacted individuals. Mary Bird Perkins Cancer Center began mailing notification letters to affected patients on or around July 20, 2026, and posted a substitute notice online for individuals whose contact information could not be located.

What Information Was Breached?

The information involved in this breach varied by individual but could include names along with health insurance and patient balance information, medical information such as medical record numbers, dates of service, and diagnosis details, scanned documents like driver’s licenses, other government identification, insurance cards, and intake forms, Social Security numbers, and additional personal details such as date of birth, email address, physical address, phone number, or demographic information. The notice states that full patient medical records, medical imaging, and financial account numbers such as credit card or bank account information were not involved.

What You Can Do

If you received notice that your information was involved in this breach, consider taking the following steps:

  • Review your notice letter carefully for instructions specific to your situation.
  • Enroll in the complimentary identity monitoring services offered through Kroll, if eligible.
  • Review your medical records and health insurance Explanation of Benefits statements for services you don’t recognize.
  • Monitor your credit report and financial accounts for unfamiliar activity.
  • Consider placing a fraud alert or credit freeze with the major credit bureaus.
  • Contact the dedicated call center at 844-576-3063 with questions about your specific notice.

File a Data Breach Lawsuit Against Mary Bird Perkins Cancer Center

If your Social Security number, medical information, or other personal data was exposed because of this vendor breach, you may be entitled to compensation. Health care organizations and the vendors they rely on are expected to protect patients’ sensitive information, and when a security failure like this one exposes that data, affected patients often have legal options.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Cybersecurity incident disclosed July 15, 2026; investigation ongoing, scope not yet confirmed
Date of Breach: Suspicious activity detected February 23, 2025; notifications completed July 22, 2026
Date of Breach: Unauthorized access: October 5-10, 2025 (vendor: Unlimited Technology Systems)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.