Intrusion at US healthcare software provider puts 3.8M people's data at risk
Unlimited Technology Systems says names, Social Security numbers, diagnoses, and insurance details may have been swiped
security
Intrusion at US healthcare software provider puts 3.8M people's data at risk
Unlimited Technology Systems says names, Social Security numbers, diagnoses, and insurance details may have been swiped
A US healthcare software provider has admitted that hackers may have made off with sensitive data belonging to 3.8 million people, making it the largest healthcare breach reported to regulators so far this year.
The attack dates to last October, when Ohio-based medical software maker Unlimited Technology Systems (UTS) detected someone poking around its commercial datacenter. The company disclosed the breach in July but did not initially say how many people were affected.
The scale is now clearer. According to the US Department of Health and Human Services' breach portal, the incident affected the protected health information of 3,803,750 people.
In a notification letter filed with the Iowa attorney general, UTS said an unauthorized actor may have copied personal information from its systems between October 5 and 10, 2025. Depending on the individual, the haul may include names, Social Security numbers, dates of birth, home and email addresses, phone numbers, and other demographic information.
The potentially stolen files also contained medical and insurance data, including policy numbers, claims and benefits information, patient balances, medical record numbers, dates of service, and diagnoses. UTS said the stolen files may also have contained scans of driving licenses and other government IDs, insurance cards, and patient intake forms.
There were some limits to the exposure. UTS said the files did not contain complete medical records, medical images, credit card numbers, or bank account details.
After detecting the intrusion, UTS called in a forensic security firm, notified law enforcement, and began determining which files the intruder had accessed. It hasn't publicly named whoever was behind the attack or explained how they got into the datacenter in the first place.
The company said it is unaware of any attempted or actual misuse of the compromised information. Affected individuals are being offered 24 months of credit monitoring and identity protection services.
At 3.8 million people, UTS overtakes the 3.4 million-person TriZetto Provider Solutions incident as the largest healthcare data breach reported to HHS so far in 2026.
For an attacker looking to collect millions of healthcare records in one hit, it seems going after the companies that manage the data can be rather more efficient than knocking on hospital doors one at a time. ®
Originally published on The Register
