Skip to main content
3.8M Patient Records: The Data Center Breach That Shows Why HIPAA's BA Rules ExistIncident & Breach Response
6 min readFor Risk Managers

3.8M Patient Records: The Data Center Breach That Shows Why HIPAA's BA Rules Exist

When Unlimited Technology Systems discovered unauthorized activity in its commercial data center on October 19, 2025, the clock had already been ticking for two weeks. Between October 5 and October 10, a threat actor had copied data belonging to 3.8 million patients across 6,500 medical practices. The Ohio-based practice management and financial software firm would spend months investigating before notifying affected individuals in 2026, making this the largest health data breach reported to the U.S. Department of Health and Human Services so far this year.

This wasn't a hospital breach. It was a business associate breach, exposing a vulnerability that's becoming the healthcare sector's most persistent problem: third-party risk that exists in theory on your vendor questionnaires but manifests as millions of compromised records in practice.

Timeline

October 5-10, 2025: Threat actor gains unauthorized access to Unlimited Technology Systems' commercial data center and exfiltrates patient data. The breach window spans five days.

October 19, 2025: Unlimited discovers the unauthorized activity within its data center.

October 19, 2025: Company notifies law enforcement and engages a cybersecurity forensic firm.

Late 2025-Early 2026: Forensic investigation determines the scope of compromised data and the breach window.

2026: Unlimited begins notifying 3.8 million affected individuals. As of August 7, 2026, the incident ranks as the largest breach posted to the HHS HIPAA Breach Reporting Tool for the year.

The 14-day gap between initial compromise and detection is your first red flag. The months-long gap between detection and public reporting is your second.

Which Controls Failed or Were Missing

Network Monitoring and Anomaly Detection: A five-day exfiltration window suggests the data center lacked real-time monitoring capable of flagging unusual data movement patterns. If monitoring existed, it wasn't tuned to detect bulk data transfers or lateral movement within the environment.

Access Controls and Segmentation: The breadth of compromised data types indicates the threat actor gained access to multiple data repositories. This suggests insufficient network segmentation and overly permissive access rights within the data center environment.

Data Loss Prevention: The successful exfiltration of 3.8 million patient records over five days points to absent or ineffective Data Loss Prevention controls. Organizations processing this volume of protected health information should have egress filtering and data movement alerts.

Privileged Access Management: The investigation revealed unauthorized activity but didn't specify how the threat actor gained initial access or what credentials were used. The scope of data accessed suggests either compromised privileged accounts or inadequate restriction of administrative access to sensitive data stores.

Incident Response Timing: While Unlimited engaged forensic support immediately upon discovery, the 14-day detection gap indicates your incident response plan is only as good as your detection capabilities. You can't respond to what you don't see.

What the Relevant Standards Require

The Health Insurance Portability and Accountability Act (HIPAA) Security Rule establishes specific technical safeguard requirements that directly address these control failures.

45 CFR § 164.312(b) - Audit Controls: Covered entities and business associates must "implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information." This isn't optional. You need logging that captures who accessed what data, when, and from where. Those logs must be reviewed.

45 CFR § 164.308(a)(1)(ii)(D) - Information System Activity Review: Your security management process must include "procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports." Regular means frequent enough to detect a five-day exfiltration before it becomes a 3.8-million-record breach.

45 CFR § 164.312(a)(1) - Access Control: You must "implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights." The Principle of Least Privilege isn't a suggestion. It's a regulatory requirement.

45 CFR § 164.308(a)(6) - Security Incident Procedures: You must "identify and respond to suspected or known security incidents; mitigate, to the extent practicable, harmful effects of security incidents that are known to the entity; and document security incidents and their outcomes." The 14-day detection gap suggests these procedures existed on paper but failed in execution.

The Health Information Technology for Economic and Clinical Health (HITECH) Act extends these obligations and adds breach notification requirements. Under 45 CFR § 164.410, business associates like Unlimited must notify affected covered entities (the 6,500 medical practices) within 60 days of discovering a breach. Those covered entities then have their own 60-day notification obligations to patients.

Lessons and Action Items for Your Team

Map your business associate data flows now, not after the breach: You can't manage risk you haven't inventoried. Document which business associates hold what categories of protected health information, where that data resides, and what security controls protect it. This isn't a compliance checkbox exercise. It's the foundation of your third-party risk program.

Rewrite your business associate agreements to include specific technical requirements: Don't accept generic language about "appropriate safeguards." Require network segmentation, encryption at rest and in transit, multi-factor authentication for administrative access, Security Information and Event Management with defined alert thresholds, and quarterly access reviews. Make these contractual obligations with audit rights.

Implement continuous monitoring of business associate security posture: Annual questionnaires don't prevent October breaches. Require your business associates to provide evidence of security control effectiveness quarterly. Request SOC 2 Type II reports. Review penetration test results. Verify patch management cadence. If a business associate processes data for 6,500 entities like Unlimited does, they should be able to demonstrate mature security operations.

Test your business associate incident response integration: When your practice management vendor discovers a breach, how quickly do you learn about it? What information do you receive? Who on your team is responsible for coordinating the response? Run a tabletop exercise that starts with "Your billing vendor just called to report unauthorized access to patient data." You'll discover gaps in your communication protocols and decision-making authority.

Review your data retention policies with business associates: Unlimited's breach included scanned driver's licenses and intake forms. Ask yourself: does your billing vendor need to retain copies of government-issued IDs indefinitely? Does your practice management system need five years of demographic data for patients who haven't been seen in three? Data Minimisation reduces your breach exposure. Define retention periods in your business associate agreements and verify compliance.

Build detection capabilities that don't rely on the vendor telling you: If your business associate agreement includes the right to request logs or security event data, exercise that right. Integrate business associate security events into your Security Operations Center if you have one. Large-scale data exfiltration creates patterns. You should have visibility into those patterns even when the data doesn't reside on your infrastructure.

The Unlimited breach is the largest healthcare data breach reported in 2026, but it won't be the last business associate breach you read about this year. The question isn't whether your vendors will be targeted. It's whether you'll discover the breach in five days or fourteen, and whether your contracts and controls will limit the damage to thousands of records instead of millions.

Your business associate agreements are HIPAA compliance documents. Your business associate risk management program is what actually protects patient data. Build the latter with the same rigor you apply to the former.

You Might Also Like