Unlimited Technology Systems Data Breach Affects 3.8 Million Patients โ Largest US Healthcare Breach of 2026
Confirmed as the largest US healthcare data breach of 2026 to date, the Unlimited Technology Systems (UTS) breach โ a Montgomery, Ohio revenue-cycle-management provider โ exposed the PHI of 3,803,750 individuals.
Key Details
- Source: HIPAA Journal
- Date: 2026-08-06
- Reliability: Tier 2/4 โ Established cyber journalism
- Entity: Unlimited Technology Systems (UTS), revenue-cycle-management provider
- Records affected: 3,803,750 individuals
Summary
Unauthorised access occurred 5โ10 Oct 2025 (identified 19 Oct), potentially exfiltrating data including names, date of birth, health insurance, SSN, and medical diagnosis. It exceeds Trizetto Provider Solutions' 3.4 million-record breach this year and underscores the business-associate risk that now drives six of the top ten US healthcare breaches.
Analysis
Highly relevant to Australian health data given the prevalence of US-built revenue-cycle-management platforms and business associates in the healthcare supply chain, echoing APRA CPS 234 and OAIC NDB exposure. Also relevant to New Zealand health data under the Privacy Act 2020 and the Health Information Privacy Code.
Related Pages
- Patient Data Exposed In Cybersecurity Incident At Ohio Revenue Cycle Management โ Earlier Ohio RCM incident coverage
- Revenue Cycle Management Group Mcbs Discloses Data Incident Affecting 1 26M Pati โ Related RCM breach
Sources: raw/digests/Cyber-Digest-2026-08-08