Healthcare billing vendor breach exposes data of 3.8 million patients

Unlimited Technology Systems, an Ohio-based healthcare billing and revenue cycle management provider, has disclosed a data breach that exposed the personal and medical information of 3,803,750 patients — one of the largest healthcare data breaches reported in 2026.
What Happened
The company, headquartered in Montgomery, Ohio, provides financial, billing, and revenue cycle management services to more than 4,500 oncology practices and over 6,500 specialty healthcare providers across the United States. Unlimited Technology Systems discovered unauthorized activity inside one of its commercial data centers on October 19, 2025. A subsequent investigation determined that an unauthorized actor had accessed — and potentially copied — patient data between October 5 and October 10, 2025, meaning the breach went undetected for roughly two weeks before discovery, and took nearly a year to reach public disclosure and formal notification to regulators.
What Data Was Exposed
The compromised information spans both personally identifiable information and protected health information. Exposed PII includes patient names, Social Security numbers, dates of birth, home addresses, email addresses, phone numbers, and scanned identity documents such as driver's licenses and insurance cards. Exposed PHI includes health insurance policy numbers, medical record numbers, diagnoses, dates of service, and claims and benefits information. The company has stated the breach did not expose complete medical records, diagnostic imaging, or financial account details such as credit card or bank numbers.
As reported by BleepingComputer, Unlimited Technology Systems formally notified the U.S. Department of Health and Human Services that 3,803,750 individuals were affected, placing this breach among the largest disclosed under HHS's breach reporting requirements this year. The company is offering affected patients two years of complimentary credit monitoring, fraud consultation, and identity theft restoration services.
Why the Scope Matters
Because Unlimited Technology Systems operates as a back-end billing processor for thousands of oncology and specialty practices rather than a patient-facing brand, most affected individuals likely have no direct relationship with the company and may be unaware their data passed through its systems at all — a structural risk common to healthcare's billing and revenue cycle vendor ecosystem, where a single breach at one processor can cascade across the patient populations of hundreds of unrelated clinics.
The combination of Social Security numbers, medical diagnoses, and insurance policy details in a single exposure is particularly valuable to fraudsters, since it enables both traditional identity theft and healthcare-specific fraud, including fraudulent insurance claims filed using a victim's stolen policy information.
What Comes Next
At least one law firm, Edelson Lechtzin LLP, has already announced it is investigating potential class-action claims on behalf of affected patients, a near-certain outcome for a breach of this scale under U.S. healthcare privacy litigation patterns. Affected individuals should watch for official notification letters from Unlimited Technology Systems, enroll in the offered credit monitoring, and remain alert for phishing attempts or fraudulent insurance claims that reference their exposed medical details — a common follow-on tactic after healthcare data breaches of this size.
Originally reported by BleepingComputer. Read the original article for additional details.
View original source