August 6, 2026: HHS’s Office for Civil Rights portal now lists 3,803,750 individuals for the Unlimited Technology Systems breach — the largest US healthcare data breach of 2026 year-to-date, ahead of TriZetto Provider Solutions’ ~3.4 million. The Ohio revenue-cycle firm’s October 2025 datacenter intrusion is no longer a “count unpublished” story.
If a clinic, billing company or specialty practice used UTS for revenue cycle or practice-management software, your patients may be in that census even if you never heard UTS’s name in a waiting room.
What happened
Unlimited Technology Systems LLC (UTS), based in Montgomery, Ohio, provides revenue cycle management and practice-management software to healthcare providers. On October 19, 2025 it identified unauthorized activity in a commercial data center that held personal and protected health information for patients of those clients.
With outside forensics, UTS determined an unauthorized party may have obtained copies of files between October 5 and October 10, 2025. Notifications and press coverage followed in 2026 as the company finished reviewing which fields were in the copied files. HIPAA Journal’s July coverage still lacked a public headcount. The August update is the OCR portal figure: 3,803,750.
No ransomware group has publicly claimed the attack. That absence does not make the data safer — it just means there was no leak-site countdown for journalists to watch.
What data was involved
Per UTS’s notification letter as summarized by HIPAA Journal, involved information may include:
- Name, address, email, phone
- Date of birth
- Health insurance information
- Patient balance information
- Social Security number
- Medical information including diagnosis
- Scanned driver’s license or other government ID
UTS said full medical records, medical images and financial account information were not involved. That boundary matters clinically and still leaves a powerful identity-theft kit: SSN + DOB + address + insurance + diagnosis is enough for medical and financial fraud without a complete chart.
Why business associates keep topping the charts
HIPAA Journal notes that six of the top ten breaches reported in 2026 hit business associates, and that half of the largest healthcare breaches of all time involve vendors. RCM platforms are concentrated risk: one datacenter holds many providers’ billing extracts.
Patients experience this as a letter from a company they do not recognise. Providers experience it as a contractual nightmare — BAAs, patient notification cost-sharing, and the question of whether their own EHR was ever touched (often it was not; the billing side copy was enough).
Regulators have been trying to harden BA security through a proposed HIPAA Security Rule update; that final rule has slipped toward 2027 in recent reporting. Meanwhile the OCR portal keeps filling with seven-figure BA incidents.
Who is at risk
Patients of UTS client providers — anyone whose billing or practice-management data sat in that datacenter during the October window. You may learn via a letter from UTS, a provider, or a state AG posting.
Providers who contracted UTS — you may owe downstream notices and should preserve logs, contracts and forensics timelines.
People who reused passwords or shared SSNs widely — the dump’s SSN and government-ID fields make tax and credit fraud easier for years.
What you should do
- If you receive a UTS or provider letter: keep it. Enrol in the offered credit monitoring if you choose, but do not stop at monitoring.
- Freeze credit at Equifax, Experian and TransUnion — free and reversible. SSN exposure makes this non-optional for most adults in the census.
- Watch IRS / tax transcripts and Explanation of Benefits for accounts or care you did not open.
- Treat medical-billing calls as hostile until you call the provider on a number from a prior statement.
- Replace driver’s licenses if your letter says a scan was involved and your state advises it.
- Providers: confirm whether your patients are in scope, align scripts for front-desk questions, and review other BA datacenter arrangements for the same failure mode.
How this compares to other 2026 health mega-breaches
TriZetto Provider Solutions’ multi-million incident set the early bar. UTS’s OCR listing overtakes it on raw headcount. Exact Sciences / Abbott’s ShinyHunters publication hit a different shape — diagnostics customers and providers in a dump indexed by Have I Been Pwned — while CareCloud’s AWS EHR breach notified on the order of 350,000. Different architectures, same theme: health-adjacent data concentrates in vendors.
UTS is a reminder that “we don’t store complete charts” is not the same as “low harm.” Diagnosis plus SSN is already a life-admin problem for the people in the file.
OCR listings vs state letters — why the number moved
Healthcare breaches often appear in the press twice: once when a vendor admits something happened, and again when OCR or a state AG posts a number. UTS followed that arc. Early BreachHistory coverage correctly carried recordsAffected 0 because no attested census existed. The August HIPAA Journal report citing OCR’s 3,803,750 is the census that upgrades the catalog.
Patients should not wait for OCR to protect themselves if a letter already lists SSN. The portal is for accountability and statistics; freezes and vigilance are for households.
Medical identity theft after an RCM dump
Fraudsters use stolen demographics to open care in your name, divert refunds, or build synthetic identities. The early warning is often an EOB for a provider you never saw, a collections call for a balance you do not recognise, or a rejected pharmacy claim because “your” plan already covered something elsewhere. Call the insurer’s number on your card — not the number in the suspicious letter.
If a scanned driver’s license was included, consider a state replacement and a fraud alert with the DMV where available. Physical ID scans are catnip for document forgery kits sold alongside SSN lists.
TriZetto, CareCloud and the 2026 BA leaderboard
TriZetto Provider Solutions’ multi-million incident and CareCloud’s ~350,000 AWS EHR notifications are part of the same year, not the same attack. What they share with UTS is concentration: payers and providers outsource claims and billing into platforms that become national privacy events when one datacenter or cloud account fails. Boards that still treat “vendor risk” as a questionnaire exercise are updating those slides with body counts now.
For patients, the brand on the letter matters less than the fields. SSN + diagnosis is the action trigger whether the logo says UTS, CareCloud or a hospital you love.
What providers should tell patients at the desk
Front-desk staff will get calls from people who received a UTS letter and people who only saw a headline. A short script helps: yes, a billing vendor reported a breach; no, that does not automatically mean our EHR was hacked; here is how to confirm whether you are in scope; here is the credit-freeze recommendation if SSN was listed. Panic and shrug are both wrong.
Publish a FAQ on the practice site even if only a subset of patients is affected. Silence pushes people toward Facebook comment threads where scammers harvest who is worried.
The long tail of a 3.8 million-person BA breach
Credit freezes stay useful for years. Tax fraud spikes around filing season. Medical identity theft may surface the next time someone visits an ER. UTS’s OCR listing is a 2026 headline built on a 2025 intrusion — a reminder that notification delay does not delay criminal reuse of the files.
BreachHistory will keep the UTS record pointed at the OCR figure unless a later amendment changes it. If you are a researcher comparing 2026 healthcare mega-breaches, use 3,803,750 as the attested scale and October 5–10, 2025 as the access window.
Households that already froze credit after an earlier 2026 healthcare letter should still open the UTS notice. Different vendors leak different field sets; a freeze you set in March still helps, but the new letter may add a diagnosis or ID-scan detail that changes whether you replace a driver’s license. Read the field list every time. If nothing in the letter lists SSN and you already froze credit for another breach, keep the freeze and file the letter with your records.
Attorneys general will keep posting state-level tallies that slice the 3.8 million by residence. Those slices help local reporters; they do not change the national OCR total BreachHistory uses for recordsAffected. When a state posts a sample notice PDF, we prefer linking it alongside HIPAA Journal and the OCR summary so patients can see the exact wording UTS used.
Finally, other RCM and practice-management vendors should assume journalists will ask “are you next?” this week. The useful answer is not a marketing soft-pedal — it is whether patient files in commercial datacenters have the same detection gap UTS described between October 5 and October 19. Twelve days of possible file copy is the operational fact patients hear, not the brand slogan on a booth.
Timeline patients can keep straight
- October 5–10, 2025 — Unauthorized party may have copied files from the commercial datacenter.
- October 19, 2025 — UTS identifies unauthorized activity and brings in forensics.
- 2026 (first half) — Data review, patient/provider notifications begin as fields are classified.
- July 23, 2026 — HIPAA Journal covers the incident while headcount is still unpublished.
- August 6, 2026 — Reporting confirms HHS OCR lists 3,803,750 individuals.
That stretch from October access to August OCR scale is why people feel blindsided. It is also why “I would have heard if I were affected” is unreliable — letters travel on legal clocks, not news clocks.
Synthetic identity and the government-ID scan problem
When a breach includes both SSN and a scanned driver’s license, criminals can assemble packets that look legitimate to fake employers, fraudulent credit applications and mule-account onboarding. Parents should check whether a child’s information appeared on a family claim statement handled by a UTS client. Minors’ SSNs are prized precisely because they stay unused for years.
If your letter is silent on ID scans, do not invent that field — but if it is present, prioritise document replacement and watch for unexpected DMV or change-of-address mail.
Researchers comparing vendor breaches should also note what UTS says was not taken: full charts, images, and financial accounts. That exclusion belongs in every accurate headline. Inflating the incident into “complete medical records of 3.8 million people” helps nobody and muddies the specific fraud risks that actually follow SSNs, diagnoses and ID scans.
If you advise a clinic network, schedule a BA tabletop that starts from “datacenter file copy, twelve-day window, no ransomware note.” The playbooks built only for encrypting malware miss this path.
Keep the OCR number and the October dates together when you share this story. A headline that only says “3.8 million” without the 2025 access window makes the breach sound brand-new in a way that confuses patients who already shredded an earlier letter. Accuracy is part of harm reduction.
State consumer-protection offices may publish their own FAQs as AG tallies appear. Prefer those and CSV-style official pages over random “claim your settlement” ads — UTS is a healthcare OCR matter, not the CRA credential-stuffing settlement Canadians are filing this month.
Reading an RCM breach letter without panicking — or dismissing it
Letters from billing vendors are easy to ignore because the logo is unfamiliar. That is a mistake when SSNs are listed. Equally, panic that “my entire hospital chart is on the dark web” may overstate what UTS says left the datacenter. Stick to the field list in your notice. If it lists SSN and government ID, act on identity protections. If it lists diagnosis, watch for targeted medical phishing that name-drops a condition.
Children and dependents in family coverage can appear in RCM extracts even when the letter is addressed to a parent. Ask the plan or provider whether minors in your household are included.
For security and compliance teams at provider groups
Inventory every BA that stores eligibility, claims, statements or scanned IDs outside your EHR. Ask where the files physically and logically live — “AWS” is not an answer; region, account, encryption keys and admin paths are. Require evidence of offline or immutable backups that do not share the same control plane as production file shares. Tabletop a BA breach: who calls patients, who pays for monitoring, who talks to OCR.
UTS’s timeline — October intrusion, late detection, months of review, mid-2026 OCR scale — is normal for large BA events and agonising for patients waiting on certainty. Faster field classification is a competitive and ethical advantage for vendors that can afford mature data maps.
Why 3.8 million is a national story, not an Ohio story
Montgomery, Ohio is where UTS sits. The patients are wherever its client providers operate. Multi-state AG notices and OCR listings exist precisely because healthcare billing is interstate. If you live far from Ohio and get a letter, it is still your SSN.
Journalists should keep UTS distinct from hospital ransomware that cancels surgeries. This was a quiet file-copy incident with a loud privacy outcome. Both categories harm patients; only one makes the local news when the ER diverts.
Canonical record
Unlimited Technology Systems 2025/26 on BreachHistory — OCR-attested 3,803,750; Oct 5–10, 2025 datacenter file copy; RCM business associate.
Sources: HIPAA Journal, DataBreaches.net, HHS OCR breach portal summary as reported therein.
Published 2026-08-08. Updated when OCR headcount became public; earlier BreachHistory coverage carried recordsAffected 0 pending this tally.