Unlimited Technology Systems Data Breach Affects 3.8 Million Patients
On July 23, 2026, the HIPAA Journal reported on a data breach at Unlimited Technology Systems, a Cincinnati, Ohio-based provider of revenue cycle management and practice management software. At the time, the scale of the data breach had yet to be made public, but it has recently been confirmed to be the second-largest healthcare data breach of the year to date, ahead of the 3.4 million-record data breach at Trizetto Provider Solutions, but behind the 15 million-record breach at DentaQuest.
According to the breach summary on the HHS’ Office for Civil Rights data breach portal, the Unlimited Technology Systems data breach involved the protected health information of 3,803,750 individuals. While the incident was confirmed in July, it was first identified in October 2025. The threat actor had access to its network between October 5 and October 10, 2025, and potentially exfiltrated files containing patient data (as detailed below). No threat group appears to have claimed responsibility for the cyberattack.
Business associates of healthcare organizations are attractive targets for cybercriminals. If their systems are compromised, hackers can gain access to highly sensitive patient data from many different healthcare companies. Six of the top ten data breaches reported this year occurred at business associates, as did 50% of the largest healthcare data breaches of all time. The proposed update to the HIPAA Security Rule includes several measures to tighten security at business associates and strengthen vendor oversight by HIPAA-covered entities. While planned for a mid-2026 release, the final rule has been delayed, with OCR now expecting to release the final rule by July 2027.
July 23, 2026: Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company
Unlimited Technology Systems LLC (UTS), a Cincinnati, Ohio-based revenue cycle management company and practice management software provider, has identified unauthorized activity within a commercial data center that contained the personal and protected health information of patients of its healthcare provider clients.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
According to its data breach notification letter, unauthorized activity was identified on October 19, 2025. Assisted by a third-party cybersecurity and digital forensics company, UTS determined that an unauthorized third party may have obtained a copy of files from that environment between October 5 and October 10, 2025.
The data review has recently been completed, and UTS has confirmed that the following types of information may have been involved: name, address, email address, phone number, date of birth, health insurance information, patient balance information, Social Security number, medical information including diagnosis, and scanned documents such as driver’s license or other government ID documents. UTS said full medical records, medical images, and financial information were not involved.
As a precaution against data misuse, the affected individuals have been offered complementary credit monitoring services for 24 months, and UTS has implemented enhanced security measures to prevent similar incidents in the future. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.


