Briev
Live
Technology

Hackers accessed data of 3.8 million patients at Ohio health-software firm

Unlimited Technology Systems said an intrusion in late 2025 may have exposed personal and medical information for over 3.8 million individuals.

Unlimited Technology Systems, a medical-software company in Ohio, detected an intrusion at its commercial datacenter in early October 2025 and subsequently disclosed that an unauthorized actor may have extracted data from Oct. 5 to Oct. 10. The U.S. Department of Health and Human Services’ breach portal lists 3,803,750 individuals whose protected health information was potentially compromised. Exposed details include names, Social Security numbers, birth dates, addresses, phone numbers, as well as limited medical and insurance information such as policy numbers, claims, diagnoses and patient balances.

Scans of driver’s licenses, government IDs and insurance cards may also have been taken, but full medical records, imaging, credit-card or bank account numbers were not part of the theft. After the breach was identified, UTS hired a forensic security firm, notified law-enforcement agencies and began assessing the scope of accessed files. The firm has not publicly identified the attacker. Affected persons are being provided with 24-month credit-monitoring and identity-protection services.

Why it matters

A breach affecting millions of health records raises privacy risks and highlights vulnerabilities in healthcare data systems.

In this story

data breachhealthcare recordscredit monitoringforensic investigation