2025 Unlimited Technology Systems — RCM datacenter breach; HHS OCR 3,803,750 patients (PHI)
Data compromised
Name, address, email, phone, DOB, health insurance information, patient balance information, Social Security number, medical information including diagnosis, and scanned driver’s license or other government ID documents. UTS said full medical records, medical images, and financial account information were not involved.
Technical writeup
Verified business-associate breach with HHS OCR headcount — Unlimited Technology Systems LLC (UTS), a Montgomery, Ohio revenue-cycle management and practice-management software provider, identified unauthorized activity on October 19, 2025 in a commercial data center holding personal and protected health information of patients of its healthcare provider clients. With third-party forensics, UTS determined an unauthorized party may have obtained copies of files between October 5 and October 10, 2025. After completing its data review, UTS confirmed involved data may include name, address, email, phone, date of birth, health insurance information, patient balance information, Social Security number, medical information including diagnosis, and scanned government IDs; it said full medical records, medical images, and financial information were not involved, and offered complimentary credit monitoring. HIPAA Journal reported on August 6, 2026 that the HHS OCR breach portal lists 3,803,750 individuals — making this the largest US healthcare breach of 2026 year-to-date ahead of TriZetto Provider Solutions (~3.4M). No ransomware group publicly claimed the incident. recordsAffected updated from unpublished (0) to the OCR-attested 3,803,750.
Root cause
Unauthorized activity in a commercial data center holding UTS client PHI; unauthorized party may have obtained file copies October 5–10, 2025 (detected October 19, 2025).
References
- https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/
- https://www.hipaajournal.com/patient-data-exposed-ohio-revenue-cycle-management-company/
- https://databreaches.net/2026/08/07/unlimited-technology-systems-data-breach-affects-3-8-million-patients/
- https://www.theregister.com/cyber-crime/2026/08/07/intrusion-at-us-healthcare-software-provider-puts-38m-peoples-data-at-risk/5284609
- https://www.bankinfosecurity.com/practice-management-firm-notifies-38m-2025-breach-a-32477
- https://cyberinsider.com/unlimited-technology-systems-data-breach-impacts-3-8-million-people/
- https://www.securityaffairs.com/196843/data-breach/unlimited-technology-systems-data-breach-exposes-data-of-3-8-million-healthcare-patients.html