Healthcare technology provider Unlimited Technology Systems (UTS) has disclosed that a data breach first detected in October 2025 affected 3,803,750 individuals, according to an updated filing with the U.S. Department of Health and Human Services (HHS).
The company initially began notifying regulators and affected individuals earlier this year after investigating unauthorized activity within its commercial data center. While the original notification did not disclose the total number of impacted people, the HHS breach portal now lists more than 3.8 million affected individuals.
Attack traced to October 2025 intrusion
According to the company’s breach notification, UTS detected suspicious activity on October 19, 2025, and launched an investigation with assistance from an external digital forensics firm. Investigators determined that an unauthorized party had access to certain systems between October 5 and October 10, 2025, and may have copied files containing patient information.
Unlimited Technology Systems develops financial and revenue cycle management software for specialty healthcare providers. The company says it supports approximately 4,500 clinics and 6,500 specialty healthcare providers across the United States, processing more than $70 billion in annual healthcare charges.
Sensitive patient information exposed
The company said the compromised files may have contained a broad range of personal and protected health information depending on the individual. The potentially exposed data includes:
- Full names
- Social Security numbers
- Dates of birth
- Email and mailing addresses
- Telephone numbers
- Government-issued identification documents
- Health insurance cards and policy information
- Medical record numbers
- Claims and benefits information
- Dates of service
- Diagnosis information
- Patient intake forms
UTS stated that not every affected individual had every category of information exposed, and the specific data involved varies by person.
Patients notified months later
The company began notifying affected individuals on July 1, 2026, after completing its review of the impacted data. Because Unlimited Technology Systems provides services to healthcare organizations rather than directly to patients, many recipients may have received a notification from a company they did not recognize.
As part of its response, the company is offering complimentary identity monitoring and fraud protection services through Kroll to eligible individuals.
No threat actor identified
Unlimited Technology Systems said it notified law enforcement after discovering the incident and continues to investigate the breach. At the time of publication, the company had not identified the individuals responsible for the intrusion, and no ransomware or extortion group has publicly claimed responsibility.
Healthcare organizations and service providers continue to be frequent targets for cyberattacks due to the volume of sensitive personal and medical information they process, making incidents involving third-party vendors capable of affecting millions of patients across multiple healthcare providers.












