All incidents

Unlimited Technology Systems data breach exposes 3.8 million patient records

breachopenAug 7, 2026 — Aug 7, 2026
Unlimited Technology Systems data breach exposes 3.8 million patient records

UNLIMITED Technology Systems has disclosed a breach that exposed the personal and health information of approximately 3.8 million individuals, the incident was first made public in early August 2026 after being confirmed on 23 July (HIPAA Journal).

According to notices filed with state regulators, the unauthorized access occurred between 5 and 10 October 2025 at one of the company’s commercial data centres, and no CVE identifier has been assigned to the intrusion (databreaches.net). Notification letters began going out to affected individuals in early August 2026.

The copied files contained names, addresses, phone numbers, email addresses, Social Security numbers, medical record numbers, diagnoses, service dates, insurance policy numbers and scanned documents (SecurityWeek). The company states that the stolen information does not include full medical histories or payment card details.

With 3.8 million affected individuals this incident surpasses the earlier Trizetto Provider Solutions breach and is currently the largest healthcare disclosure of the year, while no ransomware group has claimed responsibility, leaving open whether a payment was made or the data is being misused (Iowa Attorney General). Investigators have not identified any group or individual responsible for the incident.

Those whose data was exposed should take advantage of the two years of free credit monitoring offered by Unlimited Technology Systems (HIPAA Journal). They should also consider placing a fraud alert or credit freeze with the major bureaus and regularly review explanation of benefits statements for any unfamiliar claims.

Organisations that store similar datasets should review access controls on their production systems and ensure that privileged accounts are protected with multi‑factor authentication. They should also keep backups encrypted and stored offline, while testing intrusion detection logs for unusual data transfers, particularly outside normal business hours.

Intelligence briefing updated Aug 7, 2026

Root sourcewww.hipaajournal.com
Timeline Coverage

Swipe to explore timeline