Overview
- The attack on Unimed, which occurred in mid‑April, led to the exfiltration of patient records from dozens of university hospitals and large clinics and totals reported by hospitals run into the tens of thousands.
- Affected hospitals published specific counts that include about 30,000 records at University Hospital Cologne and more than 72,000 across Freiburg, Ulm, Heidelberg and Tübingen, with other clinics reporting thousands more.
- Stolen material ranges from names, birthdates and addresses to billing records that can reveal diagnoses, patient‑provider communications and a small number of bank details, creating risks of targeted phishing and identity fraud.
- Hospitals say clinical systems and patient care were never disrupted, transfers to Unimed were halted, patients are being notified by letter, several clinics have filed criminal complaints and authorities including the BSI and regional data‑protection offices are investigating.
- Unimed and hired forensics teams say attackers appear to have tried to deploy ransomware but were stopped after some data left a limited area, and the incident has highlighted the wider supply‑chain risk of centralised third‑party billing services and will likely draw regulatory scrutiny.