3.8 Million Patient Records Exposed in Ohio Healthcare Software Breach
A healthcare software firm in Ohio has become the unwilling holder of a grim record: the largest healthcare data breach reported to US federal regulators so far this year. Unlimited Technology Systems (UTS) has confirmed that an unauthorised intruder may have walked off with sensitive data on 3,803,750 people after accessing its commercial datacenter last autumn.
The attack itself happened between October 5 and 10, 2025. UTS detected it at the time, brought in forensic investigators, and told law enforcement. What it didn't do promptly was tell the public how bad the damage was. The breach was disclosed in July, but the full scope only became apparent via the US Department of Health and Human Services breach portal.
The stolen data is about as comprehensive as it gets short of full medical records. Names, Social Security numbers, dates of birth, addresses, phone numbers, policy numbers, claims data, diagnoses, patient balances, medical record numbers — all potentially compromised. The files may also have included scans of driving licences, insurance cards, and patient intake forms. UTS has noted that complete medical records, medical images, credit card numbers, and bank account details were not in the exposed files, which is presumably the closest thing to good news available here.
UTS says it has no evidence the data has been misused. Affected individuals are being offered two years of credit monitoring and identity protection. Whether that feels adequate when your Social Security number and medical history are potentially floating around criminal forums is another question entirely.
The company has not named the attackers or explained how they got in. That particular silence is becoming a tiresome pattern in breach disclosures.
With this incident, UTS nudges past the 3.4 million-person TriZetto Provider Solutions breach to claim the top spot on this year's HHS breach leaderboard. It's the kind of record nobody wants.
The broader lesson here isn't subtle. Healthcare software vendors and data processors hold records for millions of patients across dozens of organisations. Compromising one of them beats targeting individual hospitals by a considerable margin. Until the security standards applied to these intermediaries match the sensitivity of the data they hold, expect this pattern to continue.