3.8 million patients’ data exposed in ransomware attack on billing vendor Unlimited Technology Systems

Most of the 3.8 million people whose data was stolen in this breach had no idea Unlimited Technology Systems even existed. That’s the part worth sitting with. Ohio-based Unlimited processes billing and claims for more than 4,500 oncology practices and 6,500 specialty providers. Patients didn’t sign up for Unlimited’s services. Their doctors did. And now those patients are receiving notification letters telling them their Social Security numbers, medical records, diagnosis and treatment details, and scanned insurance cards may be in the hands of ransomware operators.

According to MedCity News, hackers accessed Unlimited’s commercial data center between October 5 and 10. The company confirmed the attack was ransomware, but no group has publicly claimed responsibility. Unlimited has not said whether it paid a ransom, and it has not disclosed how the attackers got in. The investigation is still open, which means the 3.8 million figure could rise. In vendor breaches, it usually does.

The exposed data varied by individual, but the categories are serious. Social Security numbers and insurance card scans create real identity theft risk. Diagnosis and treatment details are among the most sensitive information a person has. Once that data leaves a secured system, there’s no taking it back. Patients can freeze their credit. They can’t change their medical history.

This breach is now the second-largest healthcare data breach reported to the U.S. Department of Health and Human Services this year, behind only the attack on Conduent Business Services, which exposed data on more than 62 million people. Two incidents of this scale in a single year involving third-party vendors is not a coincidence. It’s a structural problem.

Vendors that handle billing, claims processing, and records management have accounted for six of this year’s ten largest healthcare breaches. These companies sit at the center of the healthcare data supply chain. A single compromised vendor can expose patients across thousands of provider organizations simultaneously. HHS has proposed tightening the HIPAA Security Rule’s requirements for vendor oversight in response to exactly this pattern, but that rule has not been finalized. Until it is, the incentive structure for vendors to invest seriously in security remains weak.

The timing of this breach also fits a disturbing trend. Ransomware attacks on healthcare organizations rose 46% in July alone, according to monthly tracking from Comparitech, with attacks on providers up 20% year-to-date compared to the same period in 2025. In July, hackers separately claimed to have stolen nearly a terabyte of data from Craneware Group, another medical billing software vendor. The targeting is deliberate. Healthcare vendors hold sensitive data, operate on thin IT budgets, and often can’t afford extended downtime, which makes them more likely to pay.

What’s missing from Unlimited’s disclosure is almost as notable as what’s in it. No explanation of the initial access vector. No confirmation on ransom payment. No timeline for when the investigation will close. Patients are being asked to monitor their accounts and take protective steps based on very little information about what actually went wrong. That’s a pattern in healthcare breach notifications: legally sufficient, but operationally useless for the people most affected.

So the question for every healthcare provider organization is straightforward. Do you know what data your billing vendor holds, how they protect it, and what your contract requires them to do when something goes wrong? If the answer is vague, this breach is a reason to find out fast.