Aug 7, 2026
Policy

Unlimited Technology Systems breach may affect 3.8 million people

A UTS datacenter intrusion may have exposed health, insurance and identity data; the company is offering two years of monitoring.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Unlimited Technology Systems breach may affect 3.8 million people
Photo: The Register

The Unlimited Technology Systems breach may involve the personal and health information of 3,803,750 people, according to reporting by The Register that cites the U.S. Department of Health and Human Services breach portal. The Ohio company, which provides practice-management software to healthcare organizations and providers, says an unauthorized actor may have copied data from its commercial datacenter during October 2025.

The count would make the incident the largest healthcare breach reported to HHS so far in 2026, The Register reported. The HHS record was not included in the available materials, so the figure is reported rather than independently verified here.

UTS discovered unauthorized activity in its datacenter on October 19, 2025, according to its notification letter filed with the Iowa attorney general. Its investigation concluded that an unauthorized actor may have obtained copies of some information between October 5 and October 10.

An affected healthcare provider said UTS began notifying people whose contact details were known on or about June 20, 2026. The provider said UTS had notified it of the incident on May 20.

What information may have been exposed in the Unlimited Technology Systems breach?

The data categories differed by individual. UTS said the affected files may have included names, Social Security numbers, dates of birth, email and street addresses, telephone numbers and other demographic information.

The company also listed health-insurance and patient-balance information, including policy numbers and claims or benefits data; medical record numbers, dates of service and diagnosis information; and scanned documents such as driver’s licenses and other government IDs, insurance cards and intake forms.

UTS said the incident did not involve full patient medical records, medical imaging, credit-card information or bank-account information. It said it was not aware of attempted or actual misuse when it issued the notice.

What UTS has disclosed, and what it has not

After detecting the activity, UTS said it hired a cybersecurity forensic firm, notified law enforcement and reviewed the data involved. It also said it had put enhanced security measures in place. The company has not publicly identified the intruder or explained how access to the datacenter was obtained, according to The Register.

UTS is offering two years of Kroll identity-monitoring services at no cost to eligible affected people. The services include credit monitoring, fraud consultation and identity-theft restoration.

The case is a reminder, based on the scale and data types reported here, that a software provider serving healthcare organizations can hold identity, insurance, billing and diagnosis information in one incident scope. It does not establish how UTS’s systems were accessed or whether data was removed.

People receiving a breach notice should review account statements and credit reports for unfamiliar activity. An affected provider’s notice also advises checking health-insurance statements and explanations of benefits, since the potentially involved information includes insurance and claims details.

For software operators, the episode is a practical test of whether an enterprise security program covers access controls, detection, investigation and communications across systems holding sensitive customer data.

This story draws on original reporting from The Register.

More from Policy

All Policy →