Unlimited Technology Systems, a health‑technology provider, reported a data breach that impacted approximately 3.8 million patients.
Based in Ohio, the company provides revenue‑cycle management and billing services to over 4,500 oncology practices and 6,500 specialty providers. According to the firm, unauthorized actors accessed its commercial data center from October 5‑10, and notification letters to the impacted patients were dispatched last month.
This breach ranks as the second‑largest healthcare data incident reported to HHS this year, surpassed only by an attack on business‑process outsourcer Conduent Business Services that exposed data belonging to over 62 million individuals.
These cases illustrate how a single compromised vendor can expose patient data even when those individuals have never directly engaged with the vendor, since thousands of provider organizations depend on Unlimited for billing and claims processing without playing any part in the breach.
Unlimited confirmed that the incident involved ransomware, though no group has claimed responsibility. The compromised data differed per patient but generally encompassed Social Security numbers, medical records, diagnoses, treatment information, and scanned insurance cards.
The company has not disclosed whether a ransom was paid or how the attackers initially infiltrated its systems. With the investigation ongoing, security researchers caution that the number of affected individuals may increase, as is typical in vendor‑related breaches.
The attack reflects a broader trend: vendors that handle claims, billing, and records for providers have been responsible for six of this year’s ten largest healthcare breaches, prompting HHS to propose stricter HIPAA Security Rule provisions for vendor oversight — though the rule has not yet been finalized.
The timing aligns with industry data indicating a 46 % increase in ransomware attacks on healthcare companies during July alone, per Comparitech’s monthly tracking, and a 20 % year‑to‑date rise in attacks targeting providers compared with the same period in 2025.
In a separate July incident, attackers claimed to have exfiltrated nearly a terabyte of data from Craneware Group, another medical‑billing software vendor.
If the 2026 trend continues, Unlimited’s breach may soon be eclipsed both in magnitude and corporate impact.
Photo: boonchai wedmakawand, Getty Images
Also Read
- HHS Seeks Public Input on Overhaul of Federal Vaccine Recommendation Categories
- Alfalfa Sprouts Implicated in 15-State Food Poisoning Outbreak
- California Weighs Penalties for Healthcare Providers That Don’t Rein In Costs
- Combating Ebola in Congo: Five Organizations Leading the Response Amid Ongoing Crisis


