security

Unlimited Technology Systems says names, Social Security numbers, diagnoses, and insurance details may have been swiped

A US healthcare software provider has admitted that hackers may have made off with sensitive data belonging to 3.8 million people, making it the largest healthcare breach reported to regulators so far this year.The attack dates to last October, when Ohio-based medical software maker Unlimited Technology Systems (UTS) detected someone poking around its commercial datacenter. The company disclosed the breach in July but did not initially say how many people were affected.The scale is now clearer. According to the US Department of Health and Human Services' breach portal, the incident affected the protected health information of 3,803,750 people.

In a notification letter filed with the Iowa attorney general, UTS said an unauthorized actor may have copied personal information from its systems between October 5 and 10, 2025. Depending on the individual, the haul may include names, Social Security numbers, dates of birth, home and email addresses, phone numbers, and other demographic information.

The potentially stolen files also contained medical and insurance data, including policy numbers, claims and benefits information, patient balances, medical record numbers, dates of service, and diagnoses. UTS said the stolen files may also have contained scans of driving licenses and other government IDs, insurance cards, and patient intake forms.There were some limits to the exposure. UTS said the files did not contain complete medical records, medical images, credit card numbers, or bank account details.After detecting the intrusion, UTS called in a forensic security firm, notified law enforcement, and began determining which files the intruder had accessed. It hasn't publicly named whoever was behind the attack or explained how they got into the datacenter in the first place.