UTS Data Breach: Health and Identifying Information of 3.8 Million People Exposed
UTS data breach exposes health and personal info of 3.8 million individuals. Unauthorized access to data center files disclosed.
Illustrative image generated with AI
Unauthorized Access to Files at the Data Center
Unlimited Technology Systems (UTS) disclosed a data breach on August 7, 2026, affecting 3,803,750 people. The incident occurred in October 2025 at the company’s commercial data center.
UTS detected unauthorized activity on October 19, 2025, and launched an investigation with a cybersecurity forensics firm. The analysis indicated that an unauthorized party accessed files between October 5 and 10, 2025—over a five-day period—and may have copied their contents.
The U.S. Department of Health and Human Services reported that a company server was compromised and that data was exposed to an unauthorized party. The attackers have not been identified, and no ransomware or extortion group has publicly claimed responsibility for the attack.
A Technology Provider Connected to Thousands of Healthcare Facilities
UTS develops financial software and revenue cycle management tools for specialized healthcare providers. According to company information, it serves 4,500 clinics and 6,500 healthcare providers across the United States.
The company processes more than $70 billion in net healthcare charges each year. The affected individuals are therefore primarily patients of UTS healthcare customers, rather than direct customers of the company.
Personal, Insurance, and Clinical Data Potentially Exposed
The accessible information may have included:
- first and last names, dates of birth, and Social Security numbers;
- email and mailing addresses, phone numbers, and demographic information;
- scans of driver’s licenses and other government-issued identification documents;
- insurance cards, policy numbers, and intake forms;
- information about reimbursements, services, and treatment dates;
- medical record numbers and diagnostic information.
No formal severity classification was provided, and no CVE identifiers were associated with the incident. However, the combination of identifying, insurance, and health information could facilitate identity theft, insurance fraud, and targeted phishing campaigns.
Notifications and Identity Monitoring
UTS submitted sample notification letters to the authorities on July 1, 2026, and began sending notices to affected individuals the same day. The company described the incident on July 20, 2026, and stated that it had notified law enforcement.
Recipients were offered identity monitoring services provided by Kroll. No additional technical measures—such as key rotation, credential resets, system segmentation, or indicators of compromise—were disclosed.
Anyone who receives a notification should verify the communication directly with UTS or their healthcare provider, activate the Kroll service, and remain alert to unusual requests for personal, insurance, or financial information.
Sources
This article is an original reworking based on the sources below.
- BleepingComputer
- SecurityWeek
- The Record




