Mary Bird Perkins Cancer Center has disclosed a data breach involving one of its service providers that may have exposed patients’ personal and health information. If you received a notice, here is what was involved and what you can do next.
What Happened in the Mary Bird Perkins Data Breach
A vendor incident affecting cancer center patients
Mary Bird Perkins Cancer Center is a nonprofit cancer care organization based in Baton Rouge, Louisiana. According to the center’s disclosures, the incident involved one of its service providers, Unlimited Technology Systems LLC, which provides practice management software to healthcare organizations. According to reporting on the incident, the vendor determined that an unauthorized party may have accessed certain systems between October 5 and October 10, 2025, and discovered the unauthorized activity on October 19, 2025.
Following an investigation, the cancer center posted a notice on its website with details about the incident and resources for affected individuals. The vendor began mailing consumer notification letters on or around July 20, 2026, to individuals whose mailing addresses were sufficiently available, and posted a substitute notice on the Mary Bird Perkins website for those whose addresses were not available.
What Information Was Exposed in the Breach
The sensitive patient data involved
The incident involved a vendor that maintained data on behalf of the cancer center and its patients. According to reporting on the vendor’s notice, the information potentially involved may include names, addresses, dates of birth, Social Security numbers, medical record numbers, dates of service, diagnosis information, and health insurance information, as well as scanned identification documents such as driver’s licenses and insurance cards. Reporting indicates that full medical records, medical images, and financial account information were not involved. At the time of writing, the total number of individuals affected had not been publicly disclosed. The substitute and mailed notices were intended to reach individuals whose information may have been affected.
To help protect affected individuals, Unlimited Technology Systems arranged for complimentary identity monitoring services through Kroll, a widely used identity protection provider. Individuals who believe their information may have been affected can call the dedicated call center for more information about the incident and the monitoring services being offered. Enrolling promptly is a sensible precaution when health-related data may be involved.
Who Is Affected and Why It Matters
Understanding the scope for patients
Because the incident occurred at a third-party vendor that provided practice management software, affected individuals are primarily patients whose information the vendor maintained on behalf of Mary Bird Perkins Cancer Center. Vendor-related breaches like this one illustrate how patient data can be exposed through companies patients may never have dealt with directly.
For cancer patients, a data breach can feel especially invasive, because health information is deeply personal. If you are a current or former Mary Bird Perkins patient and received a notice, it is reasonable to treat it as a signal to take protective steps and to understand your options.
Steps to Take If You Were Notified
Protecting yourself after a healthcare data breach
Enroll in the complimentary identity monitoring through Kroll if it is offered in your notice, and keep the letter for your records. Monitor your financial accounts and review Explanations of Benefits from your health insurer for services you did not receive, which can indicate medical identity theft.
You may also consider placing a fraud alert or credit freeze and remaining alert to phishing attempts referencing the cancer center or the breach. Beyond self-protective steps, a legal professional can help you understand whether you may be entitled to compensation.
Frequently Asked Questions About the Mary Bird Perkins Data Breach
When did the Mary Bird Perkins data breach happen?
The vendor, Unlimited Technology Systems LLC, discovered unauthorized activity on October 19, 2025. The vendor began mailing notification letters on or around July 20, 2026.
Who was responsible for the data involved?
The incident occurred at a third-party service provider, Unlimited Technology Systems LLC, which provides practice management software to healthcare organizations including Mary Bird Perkins Cancer Center.
Is identity monitoring being offered?
Yes. Unlimited Technology Systems arranged for complimentary identity monitoring services through Kroll for affected individuals.
How do I know if I was affected?
If you received a notification letter, or if you are a current or former Mary Bird Perkins patient, your information may have been involved. A dedicated call center was established for questions.
Can I take legal action after the Mary Bird Perkins data breach?
You may have legal options if your information was exposed. A legal professional can review your situation during a free consultation.
What should I do first?
Keep your notice, enroll in any monitoring offered, and monitor your financial and insurance statements for unusual activity.
Contact Wilshire Law Firm About the Mary Bird Perkins Data Breach
If your personal or health information was exposed in the Mary Bird Perkins data breach, you may be entitled to compensation. Wilshire Law Firm’s nationally recognized, award-winning team can help you understand your rights.
We offer free consultations and free case reviews with a legal professional, and we are available 24/7. There are no fees unless you get paid.
Contact Wilshire Law Firm today to schedule your free case review regarding the Mary Bird Perkins data breach.

