A cyberattack on Unimed, a third-party billing and receivables service provider for German hospitals, exposed data from tens of thousands of patients at multiple university medical centers, including facilities in Cologne, Freiburg, Heidelberg, Ulm, Tübingen, and Mannheim. The intrusion reportedly occurred in mid-April and affected administrative and billing records tied to privately insured patients, self-paying patients, and some international patients; hospitals said their own clinical systems were not breached and patient care was not disrupted.
Hospitals disclosed that the stolen information included personal details and, in some cases, highly sensitive medical and financial data such as diagnoses, treatment information, correspondence, and limited bank or payment details. Several affected institutions suspended data transfers to the provider, Heidelberg University Hospital filed a criminal complaint, and officials in Freiburg called for a full investigation, while some hospitals said they were considering legal action against Unimed. The attackers have not been identified and no group has publicly claimed responsibility.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Heidelberg University Hospital said it had filed a criminal complaint in response to the theft of patient data linked to the Unimed compromise. Other affected institutions said they were considering legal action and called for a full investigation.
Hospitals stated that their own medical systems were not compromised and patient care was not disrupted by the Unimed incident. Some also said they had stopped transferring data to the provider after learning of the breach.
By 2026-05-21, multiple hospitals including Cologne, Freiburg, Heidelberg, Ulm, Tübingen and Mannheim disclosed that patient and billing data had been stolen through the Unimed breach. Reported exposed information included personal details and, in some cases, diagnosis, treatment, communications, and limited bank or payment data.
In mid-April 2026, attackers compromised Unimed, a third-party billing and administrative service provider used by multiple German hospitals. The intrusion affected data held by the provider rather than hospitals' own clinical systems.
After the April 14 compromise, Unimed said it stopped further attacker activity before encryption occurred, disconnected customer data interfaces, notified authorities and police, and engaged external forensic experts to investigate the incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcetagesschau.de
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.