Unlimited Technology Systems (UTS), a Montgomery, Ohio-based revenue cycle management provider, has finally confirmed that its October 2025 data breach affected 3,803,750 individuals — making it the largest healthcare data breach of the year to date, surpassing the 3.4 million-record TriZetto Provider Solutions breach reported in March. Attackers had access to the environment between October 5 and 10, 2025, with UTS identifying unauthorized activity weeks later on October 19 and only recently completing the data review. Exposed information includes names, contact details, dates of birth, SSNs, health insurance data, patient balance information, diagnoses, and scanned government IDs.
Six of the top ten healthcare breaches this year occurred at business associates, and 50% of the largest healthcare breaches of all time trace back to vendors handling billing, revenue cycle, and technology services on behalf of providers. The reason is structural — a single compromise at a company like UTS reaches every provider it serves, giving attackers a force multiplier that direct attacks on individual hospitals cannot match. Regulators have recognized the risk: proposed HIPAA Security Rule updates aim to tighten business associate security and covered entity oversight.
Until regulation catches up, the burden falls on both business associates and the covered entities that rely on them to detect intrusions faster and reconstruct scope accurately. The nine-month gap between compromise and disclosure at UTS is representative of an industry-wide problem: without full-fidelity evidence retained from the moment of intrusion, scope reviews stretch across quarters while affected patients wait to learn what happened. Closing that gap requires a healthcare cybersecurity approach built on unified evidence — packets, flows, logs, and identity events retained together and queryable on demand — in a single platform like NIKSUN so investigators can answer "what was accessed, by whom, and how much left the network" in minutes rather than months. Read more about this story on our LinkedIn page
We use cookies to offer you a better browsing experience and to analyze site traffic. By using our site, you consent to our use of cookies.
Essential Cookies
Site Analytics
Essential Cookies
These cookies are necessary for certain areas of the site to function. They are used for access to secure areas of the website and to help us comply with legal requirements like GDPR.
Site Analytics
These cookies are used to collect information about how users use our site. We use these to improve how our website works.