Cyber-attack on billing firm: patient data from dozens of clinics stolen
Unknown attackers targeted the billing service provider Unimed in mid-April and stole data on tens of thousands of patients. Clinics from Kiel to Freiburg are affected.

Attack on Unimed affects hospitals nationwide
According to Tagesschau, unknown attackers targeted the IT systems of the Saarland-based billing company Unimed in mid-April, stealing sensitive patient data from clinics across Germany. The full extent of the data breach was not established until 18 May – more than a month after the attack, according to SWR.
Unimed is a service provider that handles billing for hospitals in relation to patients. The company stated that the attack was thwarted after a short time and that it was now fully operational again. Together with external experts, the system had been secured following the incident.
Which clinics are affected?
The number of affected patients is considerable. Cologne University Hospital alone reported 30,000 affected individuals. The university hospitals of Freiburg, Ulm, Heidelberg and Tübingen reported more than 72,000 affected patients combined. Düsseldorf University Hospital reported more than 3,000 cases, whilst Hamburg's UKE reported more than 5,000. UKSH in Kiel and Mainz University Medicine, with a maximum of 2,764 affected individuals, are also among the damaged institutions. The Saarland University Hospital registered approximately 1,200 cases.
According to Unimed, only data from private patients and self-payers was accessed. However, Petra Olschowski (Greens), Baden-Württemberg's science minister, pointed out that statutorily insured patients could also be affected if they have taken out supplementary insurance for certain services.
What data was stolen?
Saarland University Hospital stated that the attackers had been able to access master data such as name, address and date of birth. In some cases, they had also managed to access billing documents and thus steal information about illnesses. Similar data was also accessed from hundreds of UKE patients, according to the clinic.
Unimed assumes that the attackers had originally planned a complete encryption of the systems. This objective could not be achieved; however, data had already leaked before the attack was repelled.
The responsible data protection authority and the Federal Office for Information Security (BSI) were informed on 16 April 2026, according to Freiburg University Hospital.
What do experts advise those affected?
The BSI recommends that affected patients critically examine emails, calls and other contact attempts. Criminals frequently attempted to pressure their victims and provoke hasty action. In case of doubt, the treating clinic should be contacted directly.
Sebastian Schinzel, professor of electrical engineering and computer science at Münster University of Applied Sciences, warned that cybercriminals frequently sell stolen data on the darknet. The BSI also emphasised that the stolen information could be used for highly targeted phishing emails or extortion attempts.
Source: Tagesschau