Intrusion at US healthcare software provider puts 3.8M people's data at risk
Unlimited Technology Systems says names, Social Security numbers, diagnoses, and insurance details may have been swiped
A healthcare software provider in the United States has acknowledged the potential theft of sensitive data belonging to 3.8 million individuals, marking the most substantial healthcare breach reported to regulators thus far in 2026. The security lapse transpired in October last year, when Ohio-based medical software company Unlimited Technology Systems (UTS) identified suspicious activity within its commercial data center.
The firm disclosed the breach in July, though it initially withheld the exact number of affected individuals. The latest figures, obtained from the US Department of Health and Human Services' breach portal, reveal that the incident impacted the protected health data of 3,803,750 people.
According to a notification letter submitted to the Iowa attorney general, an unauthorized party might have extracted personal information from UTS's systems between October 5 and 10, 2025. The extent of the data breach is extensive and includes names, Social Security numbers, dates of birth, residential and email addresses, phone numbers, and other demographic details.
Moreover, medical and insurance-related information—such as policy numbers, claims and benefits data, patient balances, medical record numbers, dates of service, and diagnoses—may have been compromised. The potentially stolen files also contain scans of driving licenses, other government IDs, insurance cards, and patient intake forms.
However, the breach is not without restrictions. UTS asserts that the extracted files do not contain complete medical records, medical images, credit card numbers, or bank account details. Post-detection, the company engaged a forensic security firm, notified law enforcement authorities, and commenced an investigation into which files the intruder had accessed.
UTS has not publicly identified the perpetrator or elucidated the method of infiltration into the data center. The company maintains it is unaware of any illicit use of the compromised information. Affected individuals are being provided with 24 months of credit monitoring and identity protection services.
With 3.8 million people affected, UTS surpasses the 3.4 million-person TriZetto Provider Solutions incident, securing the title of the largest healthcare data breach reported to HHS in 2026. For cybercriminals aiming to amass millions of healthcare records simultaneously, targeting the entities that manage such data appears more efficient than targeting individual hospitals.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.