Data Breach at Practice Management and Billing Software Vendor Affects 3.8 Million Patients

A data breach at the U.S. software company and billing vendor Unlimited Technology Systems has exposed the protected health information of more than 3.8 million patients. This is the second-largest healthcare data breach of the year to date, and involved unauthorized access to systems containing the electronic protected health information of 3,803,750 individuals.

The Cincinnati, Ohio-based company is unlikely to be familiar to most of the breach victims. The company is a business associate of healthcare organizations, providing practice management and revenue cycle management software to around 4,500 clinics and 6,500 specialty healthcare providers across the country. It is unclear how many of those clients have been affected by the incident.

While the data breach was reported to state attorneys general earlier this year, the scale of the data breach has only recently been confirmed. The HHS’ Office for Civil Rights was notified about the data breach on July 21, 2026, but has only listed the data breach in the past few days. This was a hacking incident that was first identified by the company on October 19, 2025, when suspicious activity was found in certain information systems within the commercial datacenter hosting its g4-Centricity for Vector platform.

The forensic investigation determined that a threat actor first accessed its systems on October 5, 2025, and between October 5 and October 10, 2025, data was exfiltrated from its systems. It has taken several months to review the affected data and determine the individuals affected and data types involved.

Information compromised in the incident varies from individual to individual and may include names in combination with addresses, phone numbers, dates of birth, Social Security numbers, medical record numbers, dates of service, diagnoses, health insurance information, patient balance information, scanned documents such as government IDs, insurance cards, driver’s license numbers, and intake forms. Full medical records, medical images, and financial account information were not involved.

The company confirmed that this was a ransomware attack; however, the name of the group has not been divulged, and no ransomware group appears to have claimed responsibility for the attack, which usually indicates that payment has been made.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

Patients are being notified by mail and have been offered two years of complimentary credit monitoring and identity theft protection services as a precaution against data misuse. The company said it is unaware of any actual or attempted data misuse at the point of issuing notifications.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/