Health tech vendor Unlimited Technology Systems disclosed a data breach affecting about 3.8 million patients.
The Ohio-based revenue cycle management vendor processes billing for more than 4,500 oncology practices and 6,500 specialty providers. It said hackers accessed its commercial data center between October 5-10. Notification letters began going out to affected patients last month.
The incident marks the second-largest healthcare data breach reported to HHS this year, outranked by an attack on business process outsourcer Conduent Business Services, which exposed the data of more than 62 million people.
Both incidents demonstrate just how much a single compromised vendor can expose patients who have never directly interacted with the company at all — given most of the thousands of provider organizations that rely on Unlimited for billing and claims processing had no role in the breach itself.
Unlimited confirmed the attack was ransomware, but no group has claimed responsibility for the attack. The exposed data varied by patient but included Social Security numbers, medical records, diagnosis and treatment details and scanned insurance cards.
The company has not said whether it paid a ransom or how the attackers initially gained access to its systems. With the investigation still open, security researchers say the total number of affected individuals could climb further, as it often does in the case of vendor breaches.
The attack is part of a broader trend. Vendors that process claims, billing and records on providers’ behalf have accounted for six of this year’s ten largest healthcare breaches — which has prompted HHS to propose tightening the HIPAA Security Rule’s requirements for vendor oversight, though the rule has yet to be finalized.
The incident’s timing also lines up with industry data. Ransomware attacks on healthcare companies rose 46% in July alone, according to monthly tracking from Comparitech, which also showed that attacks on providers specifically are up 20% year-over-date compared to the same period in 2025.
In a separate July incident, hackers claimed to have stolen nearly a terabyte of file data from Craneware Group, another medical billing software vendor.
If 2026’s pattern holds, Unlimited’s breach may not hold its rank for long, either in scale or in company.
Photo: boonchai wedmakawand, Getty Images
