Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-08 ยท updated: 2026-08-08 ยท tags: [incident, data-breach, healthcare, third-party-risk, supply-chain, sector-healthcare] ยท confidence: high ยท affected_sectors: [healthcare] ยท au_impact: true

Unlimited Technology Systems Data Breach Affects 3.8 Million Patients โ€” Largest US Healthcare Breach of 2026

Confirmed as the largest US healthcare data breach of 2026 to date, the Unlimited Technology Systems (UTS) breach โ€” a Montgomery, Ohio revenue-cycle-management provider โ€” exposed the PHI of 3,803,750 individuals.

Key Details

  • Source: HIPAA Journal
  • Date: 2026-08-06
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Entity: Unlimited Technology Systems (UTS), revenue-cycle-management provider
  • Records affected: 3,803,750 individuals

Summary

Unauthorised access occurred 5โ€“10 Oct 2025 (identified 19 Oct), potentially exfiltrating data including names, date of birth, health insurance, SSN, and medical diagnosis. It exceeds Trizetto Provider Solutions' 3.4 million-record breach this year and underscores the business-associate risk that now drives six of the top ten US healthcare breaches.

Analysis

Highly relevant to Australian health data given the prevalence of US-built revenue-cycle-management platforms and business associates in the healthcare supply chain, echoing APRA CPS 234 and OAIC NDB exposure. Also relevant to New Zealand health data under the Privacy Act 2020 and the Health Information Privacy Code.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-08