Healthcare Billing Giant Hacked: 3.8 Million Patients' SSNs and Medical Records Exposed
A billing software vendor you've never heard of just exposed your SSN, diagnoses, and scanned ID — 3.8 million patients are at risk.
Your Doctor Didn't Get Hacked. Their Billing Vendor Did. That's Worse.
You trust your doctor with your most sensitive information. You've probably never heard of Unlimited Technology Systems. That's exactly the problem.
UTS is an Ohio-based healthcare billing company — the kind of business that operates invisibly between you and your doctor's office. They handle the revenue cycle: claims processing, insurance billing, charge management. You never sign a form with their name on it. You never get an email from them. And yet, they were holding the Social Security numbers, medical records, and personal details of 3.8 million Americans.
In October 2025, attackers got in. They stayed for six days — October 5 through 10 — and helped themselves to everything.
What Was Taken
This wasn't a breach of just names and email addresses. The stolen data is a comprehensive identity destruction kit:
- Full names, dates of birth, and Social Security numbers
- Home addresses, phone numbers, and email addresses
- Scanned copies of driver's licenses and government IDs
- Insurance cards and medical record numbers
- Diagnoses, dates of service, and insurance claims information
That last category matters. Medical diagnoses aren't just private — they're permanent. Unlike a credit card number, you can't reset a cancer diagnosis or change a mental health history. When that data is combined with your SSN and a scanned copy of your ID, criminals have everything they need to open credit accounts, file fraudulent tax returns, submit false Medicare or insurance claims, and impersonate you for years.
Why It Took 9 Months to Tell You
UTS detected the breach on October 19, 2025 — nine days after the attackers left. That's reasonably fast for detection. What's not fast: patients didn't start receiving notifications until July 1, 2026, nearly nine months later.
Nine months is a long time for your SSN to circulate in criminal markets before you know to act.
The company serves 4,500 clinics and 6,500 specialty healthcare providers across the United States, processing over $70 billion in net healthcare charges annually. That's a massive footprint for a company most patients have never encountered. No ransomware group has claimed responsibility for the attack, and the attackers remain unidentified.
Affected patients are being offered identity monitoring through Kroll. Multiple class-action lawsuits have already been filed.
The Hidden Data Supply Chain Your Doctor Never Explained
Here's what most people don't know: when you hand your insurance card and ID to a receptionist, that data rarely stays in one place. Healthcare providers routinely outsource billing, coding, claims management, and collections to third-party vendors. Those vendors sometimes use their own subcontractors.
Every handoff is another attack surface. Every company in that chain holds your data — and you almost certainly have no idea they exist.
This isn't unique to one clinic or one vendor. It's how the U.S. healthcare billing ecosystem works. The 2024 Change Healthcare breach hit the same supply chain, disrupting billing for hospitals and pharmacies nationwide. UTS is another node in that same network.
You cannot opt out of this system. But you can make the stolen data harder to weaponize.
What to Do Right Now
If you've received healthcare in the United States at any point — especially if you've seen a specialist — assume your data may be in circulation. Here's what to do, in priority order:
1. Freeze your credit. Today.
A credit freeze is free, permanent until you lift it, and the single most effective protection against someone opening fraudulent accounts in your name. Freeze at all three major bureaus:
- Equifax — equifax.com
- Experian — experian.com
- TransUnion — transunion.com
Also freeze at NCTUE (utility accounts) and ChexSystems (bank accounts). These are free too and often overlooked.
2. Place a fraud alert.
A fraud alert requires lenders to take extra verification steps before opening credit in your name. You only need to file with one bureau — they notify the others. This is free and lasts one year; extended alerts last seven years if you've confirmed you're a victim.
3. Check your Explanation of Benefits statements.
If you receive an EOB from your insurer for a service you didn't receive, that's medical identity fraud. Call your insurer immediately. Request your full insurance claims history if you're unsure.
4. File your taxes early.
Tax identity theft — where someone files a fraudulent return using your SSN to claim your refund — spikes after breaches involving SSNs. The IRS's Identity Protection PIN (IP PIN) program is free and assigns you a six-digit code required on your return. Sign up at irs.gov.
5. Use the Kroll monitoring if you're notified.
If UTS sends you a breach notification letter, use the free identity monitoring they're offering through Kroll. It won't undo the breach, but it creates an early warning system.
6. Lock down your email and financial accounts.
If your email is compromised, everything else falls. Enable two-factor authentication on your email, bank, and any account linked to your SSN. Use an authenticator app (not SMS when possible). If your provider supports passkeys, enroll — they're phishing-proof.
7. Consider a data removal service.
Your personal information is likely aggregated on dozens of data broker sites. Services like DeleteMe, Privacy Bee, or Kanary can submit removal requests on your behalf. This doesn't fix the breach, but it reduces your overall exposure surface.
The Bottom Line
You didn't choose Unlimited Technology Systems. You didn't sign their data retention policy. You probably didn't know they existed until now. But they had your most sensitive records — and someone else has them now too.
The healthcare billing system is built on invisible intermediaries holding irreplaceable data. Until that changes structurally, the best defense is making your stolen data as useless as possible.
Do this now:
- Freeze credit at Equifax, Experian, TransUnion, NCTUE, and ChexSystems
- Get an IRS IP PIN at irs.gov
- Enable two-factor authentication on email and financial accounts
- Watch your EOB statements for services you didn't receive
- Use the free Kroll monitoring if you receive a notification letter
You can't un-ring this bell. You can make sure it doesn't cost you.
Sources
Common Questions About Breach
What should I do immediately after a data breach?
Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.
How long do companies have to notify me after a data breach?
In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.
Should I freeze my credit after a data breach?
Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.
More in breach
Stay invisible. Follow @hack_decoded