Unlimited Technology Systems Data Breach Confirmed as 2026’s Largest at 3.8 Million
A revenue cycle management vendor's breach discovered last October has grown into the largest healthcare data breach disclosed in 2026, affecting more than 3.8 million patients.
Unlimited Technology Systems, a revenue cycle management vendor that processes billing and insurance data for thousands of healthcare providers, is notifying more than 3.8 million people that their personal and medical information was stolen in a data breach discovered last October. The U.S. Department of Health and Human Services added the incident to its breach portal on August 6, 2026. SecurityWeek reported the confirmed total at 3,803,750 individuals, a figure that HIPAA Journal says makes it the largest healthcare data breach disclosed so far in 2026, ahead of the 3.4 million-record breach at Trizetto Provider Solutions reported earlier this year.
Table Of Content
What Happened
Unlimited, based in Montgomery, Ohio, says it discovered unauthorized activity inside one of its commercial data centers on October 19, 2025. Its investigation determined that an unauthorized party accessed, and likely copied, files from its systems during a five-day window between October 5 and October 10, 2025. The company did not begin notifying individuals until July 21, 2026, roughly nine months after the intrusion was first detected, after submitting a sample notification letter to the Iowa Attorney General’s Office on July 1, 2026.
Unlimited has not named a threat actor responsible for the intrusion, and SecurityWeek says it has not seen any ransomware or extortion group publicly claim the attack.
What Data Was Exposed
Unlimited says the stolen files included names, home addresses, phone numbers, email addresses, Social Security numbers, medical record numbers, diagnosis information, dates of service, health insurance policy numbers, and claims and benefits records. Scanned copies of driver’s licenses and other government-issued identification were included for some individuals as well. The company says the breach did not reach full patient medical records, medical imaging, or financial account details such as credit card or bank numbers, and that it is not aware of any attempted or actual misuse of the data to date.
A Billing Vendor, Not a Hospital
Unlimited does not treat patients directly. It sells practice management and revenue cycle software to healthcare organizations and says it works with more than 4,500 oncology offices and 6,500 specialty providers nationwide. That business model explains how the breach reached 3.8 million people: a single compromised technology vendor can expose records that originated at many unrelated clinics, none of which had any direct control over Unlimited’s own network security.
The pattern is a familiar one on this beat. Eleven days ago, sxz.io covered a similar breach at MCBS, a medical billing vendor whose incident, linked to the PEAR ransomware group, ultimately affected more than 1.2 million patients across seven unrelated healthcare practices. HIPAA Journal notes that six of the ten largest healthcare breaches disclosed in 2026 originated at business associates rather than hospitals or insurers, the same vendor role that both Unlimited and MCBS occupy.
What Affected Patients Can Do
Unlimited is offering two years of free credit monitoring, fraud consultation, and identity theft restoration services to affected individuals, along with contact information included in its mailed notification letters. Anyone who receives a notice should enroll in that monitoring and read the letter closely, since the exact services offered can vary by state. Security professionals also generally recommend watching for unfamiliar medical bills or insurance claims, a sign of medical identity theft that standard credit monitoring does not always catch, and considering a free credit freeze with the three major credit bureaus for longer-term protection: unlike a credit card number, a stolen Social Security number cannot simply be reissued.








No Comment! Be the first one.