A revenue cycle management software vendor most health plans have never heard of is now the largest reported US healthcare breach of 2026. Unlimited Technology Systems, LLC (UTS), a Montgomery, Ohio-based practice management and revenue cycle software provider, detected unauthorized activity in one of its commercial data centers on October 19, 2025. Its forensic investigation concluded that an unauthorized actor accessed and may have copied files between October 5 and October 10, 2025. The US Department of Health and Human Services breach portal now lists the incident at 3,803,750 individuals, a figure carried consistently by BleepingComputer, The Register, and Insurance Business. No threat actor has claimed the intrusion, no ransomware or extortion brand has been named, and UTS has not publicly explained the initial access vector nearly ten months after the fact.
What Happened
The confirmed timeline is short on the intrusion side and very long on the disclosure side. UTS says it detected the unauthorized activity on October 19, 2025, engaged a cybersecurity forensic firm, notified law enforcement, and began file-level review to determine what the intruder touched. The company's own account, as reflected in its July 20, 2026 disclosure and in the notification letter filed with the Iowa Attorney General, places the access and possible copying window at October 5 to October 10, 2025, a five-day period.
Accounts differ slightly on dwell time. BleepingComputer and The Register both describe a five-day access window ending nine days before detection. Insurance Business characterises it as hackers having "already been inside the system for nearly two weeks" before discovery, which appears to stretch the start of the exfiltration window to the detection date rather than describing a separately established intrusion start. The company-attributed figure is the five-day October 5 to 10 window; anything earlier is inference, not confirmed fact.
Disclosure milestones also vary by reporting. BleepingComputer says UTS submitted breach notification samples to authorities on July 1, 2026 without stating a victim count, and disclosed publicly on July 20, 2026. Insurance Business reports the HHS notification landed in late July 2026, with the portal entry appearing August 6, 2026. Either way, the gap between the October 2025 intrusion and a public victim count is roughly nine to ten months.
Scale context matters here. Per its own website, cited by BleepingComputer, UTS serves 4,500 clinics and 6,500 specialty healthcare providers across the United States and processes more than $70 billion in net healthcare charges annually. The Register calls it the largest healthcare breach reported to US regulators so far this year.
What Was Taken
The exposed data set is unusually well suited to insurance fraud and synthetic identity work, even though it is not a classic clinical records dump. Drawing on the Iowa AG notification letter as reported by The Register and Insurance Business, and the field list published by BleepingComputer, the potentially compromised categories include:
- Full names, dates of birth, home and email addresses, phone numbers, and demographic information
- Social Security numbers
- Health insurance policy numbers, claims and benefits information, and patient balances
- Medical record numbers, dates of service, and diagnoses
- Scans of driver's licences and other government IDs, insurance cards, and patient intake forms
UTS has stated explicit limits on the exposure. The Register reports the company's position that the affected files did not contain complete medical records, medical images, credit card numbers, or bank account details. Insurance Business makes the same point, noting UTS does not hold full patient medical records or imaging.
That limitation is less reassuring than it sounds. The combination of an SSN, a date of birth, an insurance policy number, benefits detail, and a scanned government ID is a more complete fraud kit than a clinical chart. It supports claims fraud, benefits impersonation, and account takeover against payers and providers alike, and none of those elements can be reissued the way a card number can.
Why It Matters
This is a supply chain compromise wearing a healthcare label. The victim organisation has no consumer-facing brand, and the 3.8 million affected people are patients of the providers UTS serves, not customers of UTS. That structure means most affected individuals had no way to assess or accept the risk, and most plan sponsors and brokers had no visibility into UTS sitting several layers down their vendor chain.
The pattern is not isolated. In the same reporting window, three other healthcare technology suppliers were dealing with intrusions of their own. TechCrunch and SecurityWeek report that New Jersey-based CareCloud, which stores patient records for more than 45,000 providers, is notifying at least 345,000 to 350,000 people after hackers accessed one of its AWS-hosted electronic health record data stores between March 10 and March 16, 2026; CareCloud has not published a total, and TechCrunch notes no extortion group has publicly claimed it. TechCrunch separately reports that UK-based billing software maker Craneware told the London Stock Exchange in July 2026 that attackers exfiltrated a "significant volume" of employee, customer, and partner data. And BleepingComputer reports Abbott Laboratories investigating two incidents, including one where ShinyHunters claimed initial access via vishing against employees and compromise of a Microsoft Entra SSO account.
One source in this set warrants a caveat. The HealthStream Form 8-K filed with the SEC on July 29, 2026 is included as a primary document, but the available text is limited to cover-page and registrant information and contains no incident detail. It should not be read as corroborating anything about the UTS breach.
The strategic read: attackers have worked out that billing, clearinghouse, and revenue cycle intermediaries aggregate payer-grade identity data across thousands of providers, with a fraction of the security investment a large hospital system or payer would carry. One intrusion at that layer yields millions of records.
The Attack Technique
There is no confirmed technique. UTS has not named a threat actor and has not explained how the intruder reached its commercial data center, a gap The Register calls out directly. No ransomware or extortion group has listed the company. The only technical facts on the record are the location (a commercial data center rather than a cloud tenant), the file-access nature of the activity, and the October 5 to 10 copy window.
For comparison, the adjacent incidents in this reporting cycle do have partial technique detail: CareCloud's intrusion involved an AWS-hosted data store, with the company noting a hacker "claimed to have exfiltrated data from databases," per TechCrunch; and ShinyHunters told BleepingComputer it reached Abbott's Exact Sciences legacy systems through vishing and an Entra SSO account compromise. Neither is evidence about UTS. Treat any attempt to map identity-provider social engineering onto this incident as an unsupported hypothesis until UTS says otherwise.
The one behavioural signal worth logging: a nine-day gap between the end of data staging and detection, followed by a nine-month gap to a public victim count, is itself the finding. Detection latency inside the data center was measured in days. Notification latency to affected patients was measured in quarters.
What Organizations Should Do
- Inventory the fourth party, not just the third. Payers, plan sponsors, and provider groups should map which revenue cycle vendors, clearinghouses, and billing intermediaries their contracted partners use, and require that those downstream processors be named in business associate agreements. UTS-class vendors do not appear on most vendor risk registers.
- Treat policy numbers and benefits data as identity data. Apply the same monitoring, encryption at rest, and access logging you apply to SSNs. This breach demonstrates that claims and benefits fields are the payload, not metadata around one.
- Instrument for bulk file read and egress, not just malware. The confirmed activity was file access and copying over a five-day window. Alert on anomalous volume of reads against document and scan repositories, especially in colocated or commercial data center environments where EDR coverage tends to be thinner than in cloud estates.
- Contractually bind notification clocks. Negotiate defined maximum intervals from vendor detection to customer notification, with a victim-count deadline attached. A ten-month lag between intrusion and count, as seen here, denies downstream organisations any chance at timely member communication.
- Harden the identity layer against voice-based social engineering. Given ShinyHunters' reported vishing-to-Entra-SSO path at Abbott, enforce phishing-resistant MFA, restrict help desk credential and MFA reset authority, and require out-of-band verification for those requests.
- Prepare for insurance fraud, not just credit fraud. Credit monitoring does not detect fraudulent claims filed against a member's policy. Payers should add anomaly detection on claims submitted under the affected policy numbers, and providers should tighten identity verification at intake for the affected patient population.
Sources: Health tech vendor breach hits 3.8 million patients' benefits data... | hstm202607298k.htm | CareCloud begins to notify hundreds of thousands after hackers stol... | Unlimited Technology Systems breach impacts 3.8 million people | Hackers stole 'significant' amount of data from tech firm relied on... | Intrusion at US healthcare software provider puts 3.8M people's dat... | CareCloud Data Breach Impacts Over 350,000 - SecurityWeek | Abbott probes two cyber incidents amid extortion claims