A revenue cycle management software vendor that almost no patient has ever heard of has become the year's largest reported US healthcare data breach. Unlimited Technology Systems, LLC (UTS) told the Department of Health and Human Services that an intrusion into one of its commercial data centers exposed the protected health information of 3,803,750 individuals, including insurance policy numbers, claims and benefits records, Social Security numbers, diagnoses and scanned identity documents. The intrusion window is dated October 5 to 10, 2025. HHS posted the figure to its breach portal on August 6, 2026, roughly ten months after the fact.
The core numbers are consistent across every source in this brief: SecurityWeek, The Register, HIPAA Journal, Becker's Hospital Review and Insurance Business all cite the same HHS-portal count of 3,803,750. Where accounts diverge is on attribution, on the company's home base, and on where the incident ranks among 2026 healthcare breaches.
What Happened
UTS detected unauthorized activity inside a commercial data center in October 2025. Per Insurance Business, the discovery date was October 19, 2025, meaning the intruder had been operating in the environment for roughly two weeks before detection. The company's forensic investigation concluded that an unauthorized actor accessed the network and copied data between October 5 and October 10, 2025.
Becker's Hospital Review adds a detail no other source in this set provides: the affected environment was a commercial data center hosting the vendor's g4-Centricity for Vector platform. Becker's also characterises the incident as a ransomware attack. That framing is not corroborated elsewhere and should be treated as single-source. SecurityWeek states flatly that UTS has not named a threat actor and that it has seen no known extortion or ransomware group claim the attack; HIPAA Journal reports the same, noting no threat group appears to have taken credit. The Register likewise says UTS has not publicly named an actor or explained the initial access vector. Accounts differ here, and the ransomware label is not established.
The response actions are consistent: UTS suspended access to the hosted systems, engaged an outside forensic security firm, and notified law enforcement. A company spokesperson told Becker's in July that the vendor had reviewed the involved data and directly notified all customers whose data was believed to be in scope, and that it has no evidence of misuse.
The disclosure timeline is slow by any reading. The breach occurred in early October 2025. UTS publicly disclosed in July 2026 without an initial victim count. It reported the count to the HHS Office for Civil Rights on July 21, 2026 according to Becker's, which other sources describe more loosely as "late July." The notification letter detailing the data categories was filed with the Iowa Attorney General's Office in July 2026. HHS published on August 6, 2026.
Company location also varies by source. SecurityWeek and Insurance Business place UTS in Montgomery, Ohio; HIPAA Journal describes it as Cincinnati-based. Montgomery is a Cincinnati suburb, so this is likely a difference in granularity rather than a factual conflict.
What Was Taken
The notification letter filed with Iowa describes an unusually complete identity and insurance dossier. Across SecurityWeek's and The Register's readings of that filing, the exposed fields may include, depending on the individual:
- Names, home addresses, email addresses, phone numbers, dates of birth and other demographic data
- Social Security numbers
- Medical record numbers
- Diagnoses and dates of service
- Insurance policy numbers, claims and benefits information, and patient balances
- Scanned driver's licenses, other government IDs, insurance cards and patient intake forms
UTS has been specific about the limits: the involved files did not contain complete patient medical records, medical imaging, credit card numbers or bank account details. That carve-out is real but narrower than it sounds. As Insurance Business argues, the combination actually taken is arguably more useful to a fraud operator than a clinical chart would be. A policy number plus a benefits profile plus a scanned insurance card plus a government ID image is a working kit for medical identity fraud, fraudulent claim submission and high-quality benefits-themed phishing against the member.
On scale ranking, the sources disagree. The Register calls it the largest healthcare breach reported to regulators so far this year. HIPAA Journal calls it the second largest year to date, ahead of a 3.4 million-record breach at Trizetto Provider Solutions but behind a 15 million-record breach at DentaQuest. Becker's says only that it ranks "among the largest." The discrepancy is most plausibly explained by publication timing against a moving HHS portal, but we are not going to resolve it for you: reports range from largest (The Register, August 7) to second-largest (HIPAA Journal).
UTS is offering affected individuals two years of credit monitoring, fraud consultation and identity theft restoration services.
Why It Matters
UTS is a business associate under HIPAA. Patients whose records were taken have no contractual relationship with the company and, in most cases, have never heard its name. SecurityWeek reports the vendor claims to work with more than 4,500 oncology offices and over 6,500 specialty providers, which is how a single data center intrusion converts into 3.8 million patient notifications across hundreds of unrelated practices.
This is now the dominant pattern in healthcare, not an outlier. HIPAA Journal reports that six of the top ten breaches disclosed this year occurred at business associates, and that business associates account for 50 percent of the largest healthcare breaches ever recorded. The other sources in this set independently reinforce it. Bleeping Computer and SecurityWeek both cover Medical Computer Business Services (MCBS), a Georgia-based billing and practice management firm breached over a four-day window from September 22 to 26, 2025, affecting 1,261,464 people across seven named covered entities. In that case the PEAR ransomware group claimed credit in late September 2025, alleging more than 3 TB of stolen files and publishing them for download. Separately, TechCrunch reported in July 2026 that UK-based healthcare billing software maker Craneware was responding to an intrusion in which a "significant volume" of employee, customer and partner data was exfiltrated, disclosed via a London Stock Exchange filing. Craneware's Sentry acquisition alone brought access to a claimed 147 million patient records.
Three separate billing and revenue cycle vendors, three separate incidents, one shared structural weakness: the money layer of healthcare aggregates as much identity and insurance data as the clinical layer, with far less scrutiny.
The regulatory backstop is not arriving soon. HIPAA Journal notes the proposed update to the HIPAA Security Rule includes measures specifically aimed at tightening business associate security and vendor oversight, but the final rule has slipped from a planned mid-2026 release to an OCR expectation of July 2027.
The Attack Technique
Initial access is unknown. UTS has not disclosed how the intruder reached the commercial data center, and neither The Register nor SecurityWeek was able to obtain that detail. No public technical indicators, malware family, or infrastructure has been released.
What can be reconstructed from the timeline is the shape of the operation. The actor was inside the environment for at least the October 5 to 10 window during which files were copied, and was not detected until approximately October 19, per Insurance Business. That is a bulk staging-and-exfiltration profile against a hosted multi-tenant application platform, with data-theft objectives rather than the encrypt-and-disrupt pattern that produces immediate operational outage and a public leak site listing.
Attribution remains open. No group has claimed the attack on any leak site that SecurityWeek or HIPAA Journal has observed. Becker's characterisation as ransomware is the only source pointing that direction, and the absence of any claim after ten months argues against a typical double-extortion operation. Treat this as unattributed until a primary source says otherwise.
What Organizations Should Do
Inventory your revenue cycle chain, not just your EHR. Health plans, provider groups and plan sponsors should enumerate every billing, coding, clearinghouse and RCM vendor holding member data, including subcontracted hosting. Most breach notifications in this category reach the covered entity secondhand, months late, because nobody mapped the relationship in advance.
Treat policy numbers and benefits data as tier-one sensitive. The UTS carve-out language ("no full medical records, no imaging, no financial account numbers") will be repeated by other vendors. Insurance policy numbers, subscriber IDs, benefits profiles and scanned insurance cards support fraudulent claims and member-targeted social engineering on their own. Classify and monitor them accordingly.
Contractually require detection and notification SLAs from business associates. Ten months from intrusion to individual count is legal in practice but operationally useless. Negotiate defined notification windows, forensic report sharing, and a right to the affected-record list rather than a summary.
Push egress monitoring into hosted third-party environments. The exfiltration window in both the UTS and MCBS incidents was four to six days of bulk data movement. Ask vendors specifically what data-loss and anomalous-egress controls exist in the hosted environment holding your patients' records, and what the mean time to detect was in their last tabletop.
Prepare for member-facing insurance fraud, not just credit fraud. Credit monitoring does not detect fraudulent claims filed against a member's policy. Advise affected populations to review explanation-of-benefits statements for services they did not receive, and route suspected medical identity theft to plan special investigations units.
Watch leak sites for delayed publication. With no claim after ten months, a late appearance on an extortion portal remains possible. Standing monitoring for your organization's name, your vendors' names, and your covered-entity affiliations should be in place regardless of who UTS eventually names.
Sources: Health tech vendor breach hits 3.8 million patients' benefits data... | Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycl... | Hackers stole 'significant' amount of data from tech firm relied on... | 3.8 Million Impacted by Unlimited Technology Systems Data Breach -... | Data breach at medical billing firm MCBS affects 1.26 million people | MCBS Data Breach Affects 1.2 Million Individuals - SecurityWeek | Intrusion at US healthcare software provider puts 3.8M people's dat... | Ransomware breach at health IT vendor tops 3.8 million patients - B...