Skip to main content
3.8 Million Records: What the Unlimited Technology Systems Breach Reveals About Third-Party RiskIncident & Breach Response
6 min readFor GRC Leaders

3.8 Million Records: What the Unlimited Technology Systems Breach Reveals About Third-Party Risk

The Challenge

On October 19, 2025, Unlimited Technology Systems discovered unauthorized activity in its commercial data center. By the time the forensic investigation concluded, the damage was clear: threat actors had exfiltrated data on 3.8 million patients between October 5 and October 10. This became the largest health data breach reported in 2026 out of 401 incidents posted to the HHS HIPAA Breach Reporting Tool.

The Ohio-based practice management and financial software firm serves 6,500 medical practices. That scale turned a five-day intrusion into a catastrophic third-party risk event. The compromised data included names, health insurance policy numbers, claims information, diagnosis codes, Social Security numbers, dates of birth, and scanned identification documents. While full medical records and financial account information weren't accessed, the breach exposed data elements that enable identity theft and insurance fraud.

This incident is particularly instructive not just because of its size, but because Unlimited represents a category of business associate that healthcare organizations depend on but struggle to monitor effectively: the revenue cycle management vendor with deep access to patient data across thousands of practices.

The Environment and Constraints

Unlimited operates in a complex risk environment shared by many healthcare business associates. The company processes billing, claims, and patient balance information for 6,500 medical practices. This model creates inherent tensions:

Centralized data, distributed responsibility. Each medical practice remains the HIPAA-covered entity responsible for patient data. Unlimited is the business associate. But aggregating data from thousands of practices in a shared data center creates a single point of failure affecting millions of patients who've never heard of your company.

Access depth vs. security investment. Revenue cycle management requires access to demographics, insurance details, diagnosis codes, and financial data. You can't process claims without it. But that access breadth means your security controls must match or exceed those of the hospitals and practices you serve. For many business associates, security budgets lag behind access privileges.

Detection latency. The threat actor had five days of access before detection. In a shared data center environment serving thousands of clients, distinguishing malicious data access from legitimate batch processing isn't straightforward. Your SIEM needs to baseline normal behavior across diverse client workflows, and your detection rules must account for authorized bulk data operations that look superficially similar to exfiltration.

This incident also occurred against a backdrop of escalating healthcare business associate breaches. Trizetto Provider Solutions, another billing services vendor, reported a breach affecting 3.4 million people that was discovered in October 2025 but stemmed from a November 2024 intrusion. The pattern is unmistakable: attackers are targeting aggregation points in healthcare's data supply chain.

The Approach Taken

Unlimited's response followed the standard post-breach playbook. Upon discovering the unauthorized activity on October 19, 2025, the company notified law enforcement and engaged a cybersecurity forensic firm. The investigation determined the access window (October 5-10) and the data elements at risk.

The company then initiated breach notification to 3.8 million affected individuals, meeting its obligations under the Health Insurance Portability and Accountability Act and the Health Information Technology for Economic and Clinical Health Act. The notification detailed what data was compromised and clarified what wasn't accessed, specifically noting that full patient medical records, medical imaging, and financial account information were not included.

What we don't see in the public record: evidence of proactive third-party risk management that might have prevented the breach. There's no indication of whether Unlimited maintained SOC 2 Type II attestation, underwent regular penetration testing, or included specific security control requirements in its contracts with medical practices that would have caught configuration gaps or monitoring deficiencies.

Results and Metrics

The breach notification reached 3.8 million patients. As of the reporting date, no cybercrime gang had claimed responsibility on dark web forums, suggesting either a financially motivated actor who sold the data privately or a group that hasn't yet monetized the access.

For the 6,500 medical practices Unlimited serves, the breach triggered their own HIPAA breach notification obligations. Each practice had to assess whether the incident required individual patient notification, media notification (if more than 500 patients in a state were affected), and reporting to HHS. Many likely faced questions from patients about why their data was in a third party's system and what protections were in place.

The incident now stands as the largest health data breach of 2026, a distinction that carries reputational and regulatory weight. It also places Unlimited in the category of business associates that will face heightened scrutiny from the HHS Office for Civil Rights, which has increasingly focused enforcement actions on business associates rather than just covered entities.

What They Would Do Differently

While Unlimited hasn't publicly detailed lessons learned, the timeline reveals critical gaps that your team can learn from:

Reduce detection latency. Five days of unauthorized access is an eternity when you're aggregating data from thousands of sources. If Unlimited had implemented User and Entity Behavior Analytics (UEBA) tuned to detect anomalous data access patterns, the window might have been hours instead of days. In a shared data center environment, you need automated alerting when access volumes, times, or destinations deviate from established baselines.

Segment by client. Storing data from 6,500 practices in a single commercial data center without client-specific segmentation creates blast radius risk. Network segmentation, separate encryption keys per client, and access controls that limit cross-client data visibility would have contained the breach to a subset of practices rather than the entire customer base.

Enforce continuous monitoring requirements. If Unlimited had committed contractually to quarterly vulnerability assessments and annual penetration testing with results shared to clients, the medical practices could have identified security gaps before attackers did. Instead, many practices likely had no visibility into Unlimited's security posture until the breach notification arrived.

Takeaways for Your Team

If you're managing third-party risk for a healthcare organization, this breach offers specific action items:

Classify your business associates by data aggregation risk. Vendors who process data for multiple clients simultaneously (billing services, EHR platforms, cloud storage providers) present different risks than single-client service providers. Your due diligence intensity should scale with aggregation risk.

Require evidence, not attestations. Don't accept a vendor's claim that they follow HIPAA Security Rule requirements. Require SOC 2 Type II reports that cover the security, availability, and confidentiality trust services criteria. Review the report's complementary user entity controls to understand what security responsibilities remain with your organization.

Write detection requirements into contracts. Your business associate agreement should specify maximum detection windows for unauthorized access. If a vendor can't commit to detecting and reporting a breach within 24-48 hours, they don't have adequate monitoring. Make breach notification timelines contractual obligations, not just regulatory ones.

Map data flows to understand concentration risk. If you're using Unlimited for practice management, Trizetto for claims processing, and a third clearinghouse for eligibility verification, you've created three separate aggregation points. Document which patient data elements flow to each vendor and assess whether you're creating redundant risk by sending similar data sets to multiple business associates.

Test your business associate's incident response. During vendor security reviews, ask for their Computer Security Incident Response Team's runbooks. How do they detect data exfiltration? What's their escalation path? How quickly can they provide forensic evidence to support your breach notification obligations? If they can't answer these questions specifically, their incident response capability is theoretical.

The Unlimited breach won't be the last time a healthcare business associate becomes the largest breach of the year. As attackers continue targeting aggregation points in healthcare's data supply chain, your third-party risk program is your first line of defense. Make it count.

You Might Also Like