Unlimited Technology Systems (UTS), a Montgomery, Ohio revenue cycle management and practice management software vendor, has confirmed that an unauthorized actor accessed and may have copied files containing patient personal and health information from its commercial datacenter. The US Department of Health and Human Services Office for Civil Rights breach portal lists the incident at 3,803,750 affected individuals, a figure carried consistently by The Register (7 August), BleepingComputer (7 August), HIPAA Journal (6 August), Kobaran and Rescana. At that count it is the largest healthcare breach reported to US regulators so far in 2026, surpassing the 3.4 million-record TriZetto Provider Solutions incident, per both sentinel.ht and Kobaran. The intrusion occurred between 5 and 10 October 2025 and was detected on 19 October 2025, but was not quantified publicly until roughly ten months later. No threat actor has been named and no extortion group has claimed the victim.
What Happened
UTS detected unauthorized activity inside its commercial datacenter on 19 October 2025 and engaged a third-party cybersecurity and digital forensics firm. That investigation traced the intrusion to a narrow five-day window between 5 and 10 October 2025, during which an unauthorized third party accessed files and may have obtained copies of personal information belonging to patients of the healthcare providers UTS serves. The company notified law enforcement and regulators and began the file review process that ultimately produced the individual notification list.
The public disclosure timeline is unusually stretched. Per BleepingComputer, UTS submitted breach notification samples to authorities on 1 July 2026 without stating how many people were affected, and issued its substantive disclosure on 20 July 2026; MedRisk reports individual notifications began 21 July 2026. The 3,803,750 figure only surfaced when the HHS OCR portal entry was updated in early August, roughly nine and a half months after detection.
The blast radius is a function of what UTS does rather than who its own customers are. BleepingComputer, citing the company's website, reports UTS serves 4,500 clinics and 6,500 specialty healthcare providers across the United States and processes more than $70 billion in net healthcare charges annually. As a HIPAA business associate, it holds records on patients who have never heard of it.
What Was Taken
Exposure varied by individual. Drawing on the Iowa attorney general notification letter cited by The Register and the notification content summarized by BleepingComputer, Rescana and MedRisk, the potentially affected data includes:
- Full names, dates of birth, home and email addresses, phone numbers, and demographic information
- Social Security numbers
- Scans of driver's licenses and other government-issued IDs
- Insurance card images and patient intake forms
- Health insurance policy numbers, claims and benefits information, and patient balances
- Medical record numbers, dates of service, and diagnosis information
UTS has stated limits on the exposure that all outlets report consistently: the affected files did not contain complete medical records, medical images, credit card numbers, or bank account details. MedRisk adds that the company says it has no evidence of misuse to date. Affected individuals are being offered 24 months of free credit monitoring and identity protection.
The document scans are the sharpest edge here. A driver's license image paired with a Social Security number, date of birth and address is a functionally complete identity kit, and unlike a payment card it cannot be reissued.
Where the Accounts Diverge
Accounts differ on one material point: whether this was a ransomware event.
The majority of reporting, including the OUTLET-tier coverage from The Register, BleepingComputer and HIPAA Journal, describes an intrusion with possible data exfiltration and explicitly notes that UTS has not named the attacker or explained the initial access vector. Kobaran and Rescana both state that no ransomware or extortion group has claimed responsibility and the actor remains unidentified.
MedRisk (2 August, OTHER tier, citing Becker's Hospital Review and ClaimDepot) is alone in characterising the incident as a ransomware attack, reporting that unauthorized actors encrypted systems within the commercial datacenter hosting the g4-Centricity for Vector platform. That claim is not corroborated by any primary or outlet-tier source in this set and should be treated as unconfirmed.
Record counts also differ, though less genuinely. MedRisk reported "at least 442,000 patients" on 2 August, built from state attorney general filings (roughly 162,000 Iowa residents and about 148,000 in South Carolina, with California, Massachusetts, Texas and Vermont also affected). That is a partial state-level tally published before the federal portal entry landed, not a competing national figure. The reconciled number is the HHS OCR count of 3,803,750, which every subsequent report uses.
Why It Matters
This is a business associate breach, and that is the whole story. A single compromise at one vendor propagated across dozens of unrelated provider organizations and millions of patients simultaneously. Both MedRisk and Kobaran make the same structural point: revenue cycle management aggregates the most sensitive data in healthcare (identity, insurance, diagnosis, billing) into environments that individual hospitals and physician practices do not control, cannot directly monitor, and often have not inventoried below the first tier.
The detection-to-disclosure gap deserves equal attention. Roughly nine months elapsed between UTS detecting the intrusion and the scale becoming public. For the downstream providers named as covered entities, that is nine months during which their own patients were exposed and their own breach obligations were running against facts they did not yet have.
Context matters for what may come next. Health-ISAC issued a 24 July 2026 advisory, reported by BleepingComputer, warning of a rise in successful ShinyHunters attacks against healthcare and medtech organizations. That advisory is sector-wide and there is no reporting linking ShinyHunters or any other named group to UTS. But it establishes the operating environment: capable, financially motivated actors are actively working the healthcare supply chain, and stolen identity and diagnosis data does not expire.
The Attack Technique
Initial access is unknown. UTS has not publicly explained how the intruder reached its commercial datacenter, and no source in this set offers a technical vector, malware family, or indicators of compromise. What is established is the shape of the operation: a five-day dwell window (5 to 10 October 2025), file-level access and probable staging or copying of data, and detection nine days after the window closed via unauthorized activity in the datacenter environment.
For a threat model in the absence of attribution, the Health-ISAC advisory describes the currently dominant pattern against this sector. Per BleepingComputer's summary of the 24 July advisory, ShinyHunters chains begin with voice phishing aimed at employees or helpdesk staff to force password resets, MFA method changes, or new device enrollments. Once inside a corporate SSO account, the actor pivots through the Okta, Entra or Google SSO dashboard, which enumerates every SaaS application the compromised user can reach: Salesforce, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, Google Drive. The group also runs supply chain attacks against third-party integration partners to harvest OAuth tokens for platforms like Salesforce and Snowflake. Again, this is sector context, not an attribution for UTS.
What Organizations Should Do
- Inventory your business associates, including the ones you inherited. If you outsource revenue cycle, billing, or practice management, map which vendors hold PHI, what categories they hold, and which of their subcontractors touch it. Providers whose patients are in this notification set frequently had no direct relationship with UTS.
- Put notification timing in the contract. Nine months from detection to a public number is a contractual failure as much as a security one. Require defined notification windows measured from detection, not from completion of file review, plus a commitment to share scope updates as forensics progresses.
- Harden the helpdesk and identity reset path. Per the Health-ISAC guidance, require verified callback, video verification, or manager approval before any password reset, MFA re-enrollment, or new device enrollment. Vishing against support staff is the current front door.
- Move to phishing-resistant MFA and audit SSO blast radius. Enforce FIDO2 or hardware-backed authenticators for anyone with access to PHI environments, and audit what each SSO dashboard actually exposes. Reduce standing application entitlements so one compromised identity does not enumerate the entire data estate.
- Instrument for bulk file access, not just intrusion. A five-day exfiltration window that took nine days to detect is a monitoring gap. Alert on anomalous volume, unusual access times, and mass reads of document repositories holding ID scans and intake forms.
- Minimise retained document scans. Driver's license images, insurance cards and intake forms drove the severity of this breach. Set aggressive retention limits, encrypt at rest with separated key custody, and delete on schedule rather than keeping them indefinitely for convenience.
- Pressure-test hosted platforms against your own standards. If a vendor hosts your data in its commercial datacenter, ask for its segmentation model, EDR coverage, log retention, and its most recent independent assessment. Treat non-answers as findings.
Sources: UTS Breach Exposes 3.8 Million Health Records | Unlimited Technology Systems breach impacts 3.8 million people | Intrusion at US healthcare software provider puts 3.8M people's dat... | Unlimited Technology Systems Data Breach Affects 3.8 Million Patients | Health-ISAC warns of rising ShinyHunters data theft attacks on heal... | Ransomware at Ohio vendor triggers notices for 442,000 patients – M... | Data Breach at Unlimited Technology Systems Exposes 3.8 Million ... | Unlimited Technology Systems Data Breach Exposes 3.8 Million Health...