HIPAA Pulse by Patient Protect logo

HIPAA Pulse by Patient Protect

Archives
Log in
August 19, 2026

HIPAA Pulse | August 19th

HIPAA Pulse — August 19, 2026
A vendor found unauthorized access in October. Patients heard in July. Nine months, 3.8 million people, and one of the largest healthcare breaches of the year. ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌
Patient Protect
HIPAA Pulse

HIPAA PULSE

August 19, 2026  ·  Bi-Weekly Briefing

Discovered in October, Disclosed in July: Nine Months, 3.8 Million People

A revenue-cycle vendor found unauthorized access in its network last October. Patients did not hear about it until July. By then, the affected count was 3.8 million people.

Unlimited Technology Systems is now one of the largest healthcare breaches disclosed this year — behind DentaQuest in our tracking, and ahead of the TriZetto cascade from Q1. The delay is bad enough on its own. But the more useful detail is what was exposed: not just database fields, but scanned documents — licenses, insurance cards, intake forms — the kind of messy files many practices barely inventory.

Also this window: DentaQuest's number is now listed on the OCR portal, at exactly the figure we told you about last issue. And a familiar brand disclosed a breach involving data from a company it acquired roughly five years ago — still sitting in a vendor's storage system the whole time.

9 months

is roughly the gap between Unlimited Technology Systems discovering unauthorized activity and the patient notices that followed in July. That is the part practices need to pay attention to: not just whether a vendor gets breached, but how long it takes before anyone downstream is told.

Since the last issue, August 5

3

named stories verified this window, no major corrections since

5 yrs

since One Medical acquired the company whose archived patient data was just exposed

15M

DentaQuest's figure, now listed on the HHS OCR portal

No historical mega-breaches resurfaced with fresh dates this window — the check we run every issue came back clean this time.

Open the live dashboard Free · No account · Updated nightly

Breach of Note: Unlimited Technology Systems

HHS OCR portal  ·  3,803,750 affected  ·  Hacking/IT Incident  ·  Nationwide

Unlimited Technology Systems is a Montgomery, Ohio revenue-cycle and practice-management vendor focused on oncology and specialty care. It serves more than 4,500 clinical offices and 6,500 healthcare providers. It discovered unauthorized activity in one of its commercial data centers on October 19, 2025. Investigators later narrowed the access to October 5–10. The company did not formally disclose the incident to a state attorney general until July 1, 2026. Patient notices followed later that month — roughly nine months after discovery.

HHS OCR now lists 3,803,750 affected people. State filings break out 277,364 in Texas and 148,342 in South Carolina. In our tracking, that puts UTS among the largest healthcare breaches disclosed so far in 2026: behind DentaQuest, ahead of the 3.4-million-record TriZetto cascade from Q1. No ransomware or extortion group has publicly claimed the attack. Unlimited has not explained the length of the disclosure gap. A proposed class action filed in the Southern District of Ohio is already asking that question.

The part that should make practices stop and check their own systems isn't the scale so much as the file type. Alongside Social Security numbers and diagnosis codes, the stolen data included scanned documents: driver's licenses, insurance cards, intake forms. Those files are messy. They are often stored outside the clean database fields everyone thinks about during a risk analysis. Unless OCR or classification is set up to read them, they can sit in a system for years without anyone having a clear inventory of what is inside.

Worth asking: Do any of your billing, RCM, or practice-management vendors process claims through Unlimited Technology Systems, even indirectly? Does your practice scan and retain copies of driver's licenses or insurance cards, and if so, do you know where those scans live and for how long? What's your own plan's target for time-to-disclosure if you ever find something similar? Run the free assessment.

DentaQuest is now listed at 15 million

Last issue, we told you DentaQuest had reportedly acknowledged at least 15 million affected, separate from the roughly 4.5 million that state filings could directly support at the time. HHS OCR now lists the figure at exactly 15,000,000. That is the confirmation we were waiting for. The unofficial 23M+ estimate remains just that: unofficial, and still unconfirmed by OCR.

Old data from an old acquisition, still sitting in a vendor's system

One Medical disclosed that an unauthorized party accessed a third-party file-storage system on June 13, 2026, with actual access dated June 8–11. The system held archived records for One Medical Seniors, formerly Iora Health, which One Medical acquired in 2021. Roughly five years later, those legacy patient files were still sitting in a vendor's storage platform. Current One Medical patient data was not involved, according to the company. But the operational question is obvious: when you change vendors, merge practices, or inherit records through an acquisition, who confirms the old data is actually gone?

There's a second HIPAA rule targeted for this month, too

The Security Rule update we've covered all summer isn't the only one in motion. A separate Privacy Rule update — faster patient access to records, in-person inspection and photographing of PHI, more room for family and caregiver involvement in care — was first released in late 2020 and published in the Federal Register in January 2021, then mostly sat still for years. OCR revived it this year, held a Tribal consultation in February, and the federal regulatory agenda now targets a final rule for August 2026. We checked and could not confirm it has actually published yet. If it lands before our next issue, we'll cover it properly. If your compliance calendar only has the Security Rule on it, this is the one to add.

A note on this issue's data

One entity we checked this window showed an implausible affected count that didn't match any independent reporting we could find, and closely matched a different, already-reported breach's figure. We held it back rather than publish a number we couldn't verify.

30-minute system check

Five items, each tied to something above.

1.

Ask your RCM and billing vendors what their time-to-disclosure target is, in writing. Unlimited Technology Systems took nine months. Ask before a breach happens, not after.

2.

Find out if your practice retains scanned identity documents, and where. Driver's licenses and insurance cards scanned at intake are exactly the kind of unstructured data standard discovery tools can miss. If you don't know where those scans live, neither does your risk analysis.

3.

List every vendor relationship you've ended in the last five years. One Medical's exposure traces to a 2021 acquisition. If you've switched EHR, billing, or lab vendors, confirm in writing that your old vendor actually deleted your patients' data — don't assume it.

4.

Set your own internal target for discovery-to-disclosure, and write it down. HIPAA's 60-day maximum is the ceiling, not a goal to aim for. A practice with a documented 15- or 20-day internal target has an easier time explaining its process to OCR than one with no target at all.

5.

Treat breach rankings as moving targets. DentaQuest, TriZetto, and now Unlimited Technology Systems have each briefly held a spot near the top of the 2026 list. That ranking will shift again before Q4. What won't change is the underlying pattern: the largest exposures keep tracing back to vendors, not practices.

The free HIPAA Risk Assessment inventories your vendors, BAAs, and data flows in about 30 minutes. No account needed.

Run the free assessment Free · No account · 30 minutes
 

A word from Patient Protect, who pays for this newsletter to exist

Your vendors are your attack surface. Track them like it.

Vendor inventory with offboarding and data-disposition tracking. BAA lifecycle alerts, including notification-deadline terms. Continuous risk analysis. $39/month, no contracts, 14-day free trial.

Start free trial See pricing

Worth reading elsewhere

  Amgen Says Cloud Data Breach Exposed Patient Health, Proprietary Info

Attackers reportedly stole patient health data and proprietary corporate information from cloud systems run by third-party providers. No confirmed affected count yet. Source: Bleeping Computer.

  Health-ISAC Warns of Rising ShinyHunters Attacks on Healthcare

The same group behind DentaQuest is using social engineering to compromise single sign-on accounts and steal data from cloud services more broadly. Source: Bleeping Computer.

Seven issues in, the same problem keeps showing up in different forms. A vendor finds something. Months pass. Patients eventually hear about it. By then, the practice or health system is left answering for a timeline it did not fully control. Unlimited Technology Systems isn't a new kind of story so much as a very large version of the one we keep seeing.

Next Pulse drops September 2.

Editorial coverage at hipaapulse.com. Operational response at patient-protect.com/hipaa-pulse. This briefing comes from Patient Protect.

Patient Protect

Chicago, IL  ·  patient-protect.com  ·  HIPAA Pulse

Instagram LinkedIn X

Unlimited Technology Systems figures reflect the HHS OCR breach portal listing and state attorney general filings (Texas, South Carolina). DentaQuest's 15,000,000 figure reflects the HHS OCR breach portal listing, current as of this issue; the previously reported 23M+ estimate remains an independent, unofficial analysis. One Medical figures reflect the company's own published security notice. One entity in this window's raw data was excluded after its affected count could not be independently verified and closely matched a different, unrelated breach's figure.

You're receiving HIPAA Pulse because you subscribed at patient-protect.com. Unsubscribe  ·  Privacy Policy

© 2026 Patient Protect LLC. All rights reserved.

Don't miss what's next. Subscribe to HIPAA Pulse by Patient Protect:
← Newer HIPAA Pulse | Sept 2nd Older → HIPAA Pulse | August 5th
Instagram
Twitter
LinkedIn
YouTube