Unlimited Technology Systems Data Breach Lawsuit, Were You Affected? — Matlock v. Unlimited Technology Systems, LLC, No. 1:26-cv-00729
You’ve probably never heard of Unlimited Technology Systems. Most of the 3.8 million patients caught up in its data breach probably hadn’t either — because UTS isn’t a hospital or a clinic you’d recognize. It’s the billing software running quietly behind the scenes at thousands of specialty medical practices. If your provider used it, your Social Security number, medical record details, and possibly a scanned copy of your driver’s license may now be in the hands of someone who was never supposed to have them. Several class actions are already pending in federal court in Ohio.
Quick Facts
| Field | Detail |
| Lawsuit Filed | July 22–24, 2026 (multiple related suits, including Matlock, filed within days of each other) |
| Defendant | Unlimited Technology Systems, LLC (d/b/a Unlimited Systems) |
| Alleged Harm | Unauthorized access to UTS’s commercial data center, exposing patients’ personal and protected health information |
| Law Alleged | UNVERIFIED — specific causes of action pled in the complaints (e.g., negligence, breach of implied contract, state data breach statutes) not confirmed from public reporting; only the existence and filing dates of the suits are confirmed |
| Who Is Affected | 3,803,750 patients nationwide of healthcare providers that use UTS’s billing and practice management software |
| Company Description | Revenue cycle management and practice management software vendor based in Montgomery, Ohio, near Cincinnati, serving more than 4,500 specialty and oncology practices and 6,500+ specialty healthcare providers |
| Court & Case Number | U.S. District Court, Southern District of Ohio, No. 1:26-cv-00729 (Matlock v. Unlimited Technology Systems, LLC) |
| Current Stage | Multiple related suits pending; motion to consolidate and appoint interim class counsel filed July 26, 2026 |
| Lead Plaintiff Deadline | N/A — not a securities case |
| Settlement Status | No settlement. No claim form exists. |
| Last Updated | August 18, 2026 |
Who Is Unlimited Technology Systems and Why Are They Being Sued for This?
Unlimited Technology Systems doesn’t treat patients. It sells the billing and revenue-cycle software that specialty healthcare practices — many of them oncology clinics — use to process claims and payments behind the scenes. That means UTS ends up holding sensitive data for patients of practices they may never have heard of, on a scale most single hospitals never reach: the company says it processes more than $70 billion in net healthcare charges every year across more than 4,500 clinics. When a vendor sitting that deep in the healthcare billing pipeline gets breached, the fallout doesn’t stay contained to one provider — it spreads across every practice that trusted UTS with its patients’ data.
What Happened, and When?
UTS says it discovered unauthorized activity inside one of its commercial data centers on October 19, 2025. A forensic investigation traced the actual intrusion to a narrow window — October 5 through October 10, 2025 — during which an unauthorized actor accessed files and may have copied personal information belonging to patients of the healthcare providers UTS serves. The exposed data varied by person but could include names, Social Security numbers, dates of birth, mailing addresses, medical record numbers, diagnosis information, and scanned copies of driver’s licenses or other government-issued ID.
Here’s the detail that should raise eyebrows: UTS didn’t begin notifying anyone until mid-2026 — roughly nine months after it says it found the intrusion. And the scale kept growing even after notification started. Early reporting on this incident put the number of affected patients at around 442,000. By the time UTS formally reported the breach to the U.S. Department of Health and Human Services in late July 2026, that number had climbed to 3,803,750 — nearly nine times the original estimate. HHS posted the incident to its public breach portal on August 6, 2026, where it now ranks as the largest healthcare data breach reported to federal regulators so far in 2026, ahead of a 3.4-million-record breach at TriZetto Provider Solutions.
Related article: Shopify Checkout Data Privacy Lawsuit, Were You Affected? — Briskin v. Shopify Inc., No. 4:21-cv-06269-PJH

UTS filed breach notices with attorneys general in at least six states — California, Iowa, Massachusetts, South Carolina, Texas, and Vermont — and began sending individual notification letters, with Kroll handling the mailing and enrollment process on UTS’s behalf. If you got a letter with “Return to Kroll” as the listed address, that’s consistent with the real notice UTS sent out; it isn’t a phishing attempt.
Within days of notification going out, plaintiffs’ firms started filing. Matlock v. Unlimited Technology Systems, LLC — which also names a healthcare provider, Mary Bird Perkins, as a co-defendant — was filed July 24, 2026, in the U.S. District Court for the Southern District of Ohio before Judge Matthew W. McFarland. It’s not alone: related suits including Watts, Owens, and Patterson v. Unlimited Technology Systems, LLC were all filed in the same court within roughly 48 hours of each other. A motion to consolidate these related cases and appoint interim class counsel followed on July 26, 2026 — standard early housekeeping in a case where several firms raced to file on behalf of different named plaintiffs before the litigation had even had its first scheduling conference.
Are You Part of the Unlimited Technology Systems Data Breach Lawsuit?
Here’s exactly how to know if this case could include you.
- Patients of any healthcare practice, including specialty and oncology practices, that used UTS’s billing or practice management software
- Anyone who received a written notice from UTS, or from Kroll on UTS’s behalf, about this specific breach
- Patients whose Social Security number, medical record number, or government ID may have passed through a UTS-managed system, even if you never directly interacted with UTS
- People whose healthcare provider has confirmed it uses UTS for billing or revenue cycle management, even if no notice has arrived yet
You do not need a direct relationship with UTS to be affected — that’s the defining feature of a business-associate breach. Your own doctor’s office may never have had its own systems touched at all; the exposure happened one level removed, inside a vendor most patients never knew existed.
Unlimited Technology Systems Patients Outside Ohio — Are You Still Covered?
Yes. This breach and the resulting lawsuits are not limited to Ohio residents or any single state. UTS reported affected individuals in states across the country, including 277,364 in Texas, 162,478 in Iowa, 148,342 in South Carolina, and 2,223 in Massachusetts, among others. The lawsuits filed so far are proposed nationwide class actions, meaning they seek to represent affected patients regardless of what state they live in — the venue in Ohio reflects where UTS is headquartered, not a geographic limit on who can be included.
Not sure if you qualify for the Unlimited Technology Systems data breach lawsuit? A free consultation with a data breach attorney can help you confirm whether your provider used UTS and what your options look like at this early stage.
What Are Affected Patients Asking the Court to Award?
No money yet. No claim form yet. The pending complaints seek class certification along with damages and injunctive relief requiring UTS to improve its data security practices going forward — but as of this writing, none of the related cases has progressed past the initial filing and consolidation stage. There is no settlement, and it’s far too early to know if or when one might happen.
What Could Affected Patients Receive If This Case Resolves?
Impossible to predict at this stage. Comparable healthcare vendor breach cases have resolved in very different ways: some settle for tens of millions of dollars split among hundreds of thousands or millions of claimants, others take years to even reach class certification, and outcomes depend heavily on what discovery shows about UTS’s security practices and how strong the evidence of actual harm turns out to be. Talk to a data breach attorney if you want a grounded read on your own situation rather than a guess based on unrelated cases.
What Should Unlimited Technology Systems Patients Do Right Now?
- Don’t panic — there’s no lawsuit deadline today. If a class is eventually certified, affected patients are typically included automatically without filing anything.
- Activate your free credit monitoring if you received a letter. UTS is offering two years of credit monitoring, fraud consultation, and identity theft restoration through Kroll, using the activation code printed in your notice.
- Save the notice letter itself, along with any other records showing your relationship to a UTS-using provider — appointment confirmations, billing statements, insurance explanations of benefits.
- Watch your accounts and medical records for anything unfamiliar, including new accounts opened in your name or medical claims you don’t recognize, and document the date you first noticed anything.
- Lead plaintiff deadline: doesn’t apply here. That’s a securities-fraud concept; this is a data breach class action, and no separate deadline exists to become a named plaintiff.
- Monitor the docket under No. 1:26-cv-00729 in the Southern District of Ohio, where the motion to consolidate the related suits is pending.
Unlimited Technology Systems Data Breach Lawsuit — Full Timeline
| Milestone | Date |
| Unauthorized access to UTS data center occurs | October 5–10, 2025 |
| UTS discovers unauthorized activity | October 19, 2025 |
| Sample breach notices begin reaching state attorneys general | July 1, 2026 |
| UTS formally discloses breach scope; initial reports cite roughly 442,000 affected | Mid-to-late July 2026 |
| Watts v. Unlimited Technology Systems, LLC filed (S.D. Ohio) | July 22, 2026 |
| UTS reports final affected total of 3,803,750 to HHS | Late July 2026 |
| Matlock v. Unlimited Technology Systems, LLC, No. 1:26-cv-00729, filed (S.D. Ohio) | July 24, 2026 |
| Motion to consolidate related suits and appoint interim class counsel filed | July 26, 2026 |
| HHS posts breach to public portal — largest healthcare breach reported in 2026 to date | August 6, 2026 |
| Class certification decision | UNVERIFIED — no briefing schedule confirmed yet |
| Settlement or trial | UNVERIFIED — no timeline available |
Worth sitting with: the number of people UTS says were affected didn’t just come out large — it grew nearly nine-fold between the earliest public reporting and the figure UTS ultimately gave federal regulators. That’s not unusual in a healthcare breach involving a vendor rather than a single provider, since the full scope often only becomes clear once every client practice’s data is reviewed — but it’s exactly the kind of gap between “what we told you at first” and “what actually happened” that plaintiffs’ attorneys tend to highlight when arguing a company was too slow, or too vague, in telling people the truth.
Unlimited Technology Systems Data Breach — Frequently Asked Questions
Is there a class action lawsuit against Unlimited Technology Systems for the data breach right now?
Yes. Several related proposed class actions, including Matlock v. Unlimited Technology Systems, LLC, No. 1:26-cv-00729, are pending in the U.S. District Court for the Southern District of Ohio, filed in the days immediately following notification to affected patients in July 2026.
Do I need to do anything right now to be part of the Unlimited Technology Systems lawsuit?
No. No class has been certified yet, and there’s no claim form to file. If a class is eventually certified and you qualify, you’ll typically be included automatically.
When will the Unlimited Technology Systems data breach case settle?
There’s no timeline yet. The related suits are still in the earliest stage — a motion to consolidate them and appoint interim class counsel was only filed July 26, 2026. Comparable healthcare vendor breach cases have taken anywhere from about a year to several years to reach a settlement, if one is reached at all.
Can I file my own lawsuit against Unlimited Technology Systems instead of joining the class?
You can, but it typically only makes sense if you’ve suffered specific, documented losses — like confirmed identity theft — beyond the general exposure most affected patients experienced. For most people, letting the pending class actions proceed is the more practical route. A data breach attorney can help you weigh whether your situation is the exception.
How will I find out if the Unlimited Technology Systems case settles?
Watch the docket under case No. 1:26-cv-00729 in the Southern District of Ohio, or check back here — AllAboutLawyer.com updates this article as the litigation develops, including if it converts into a settlement with an active claim form.
What does “lead plaintiff” mean for this case, and why does the deadline matter?
It doesn’t apply here. “Lead plaintiff” deadlines are a securities-fraud concept tied to a specific federal statute governing stock-related class actions. This is a data breach case, so there’s no equivalent deadline — the named plaintiffs in Matlock, Watts, Owens, and Patterson have already stepped forward.
What specific laws does Unlimited Technology Systems allegedly violate?
UNVERIFIED — the exact causes of action pled in the complaints haven’t been confirmed against the filed pleadings as of this writing. What is confirmed is that UTS is a HIPAA business associate and that multiple federal class actions have been filed against it following the breach; this article will be updated once the specific legal claims are verified against the court filings.
How much could affected patients get if this case settles?
There’s no way to know yet. No settlement exists, and any specific dollar figure circulating online right now is speculation — the eventual outcome would depend on class size, what discovery reveals about UTS’s security practices, and how the litigation resolves.
Sources Used in This Unlimited Technology Systems Data Breach Article
- Case Docket — PacerMonitor, Matlock v. Unlimited Technology Systems, LLC, No. 1:26-cv-00729: https://www.pacermonitor.com/public/case/65887759/Matlock_v_Unlimited_Technology_Systems,_LLC
- Complaint Filing Record — PacerMonitor, Matlock v. Unlimited Technology Systems, LLC, Complaint with Jury Demand, filed July 24, 2026: https://www.pacermonitor.com/public/filings/DJQB5IJA/Matlock_v_Unlimited_Technology_Systems_LLC__ohsdce-26-00729__0001.0.pdf
- Case Docket — Justia, Owens v. Unlimited Technology Systems, LLC, No. 1:2026cv00736: https://dockets.justia.com/docket/ohio/ohsdce/1:2026cv00736/314346
- Case Docket — Justia, Patterson v. Unlimited Technology Systems, LLC, No. 1:2026cv00740: https://dockets.justia.com/docket/ohio/ohsdce/1:2026cv00740/314377
- Breach Disclosure Reporting — HIPAA Journal, “Unlimited Technology Systems Data Breach Affects 3.8 Million Patients,” July 2026: https://www.hipaajournal.com/patient-data-exposed-ohio-revenue-cycle-management-company/
- Breach Disclosure Reporting — Bleeping Computer, “Unlimited Technology Systems breach impacts 3.8 million people”: https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/
- Affected Individual Count History — Becker’s Hospital Review, “Ransomware breach at health IT vendor tops 3.8 million patients”: https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/ransomware-breach-at-health-it-vendor-tops-3-8-million-patients/
- Breach Details — Security Affairs, “Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients”: https://securityaffairs.com/196843/data-breach/unlimited-technology-systems-data-breach-exposes-data-of-3-8-million-healthcare-patients.html
- State-by-State Notification Data — DataBreaches.Net, “Unlimited Technology Systems Data Breach Affects 3.8 Million Patients”: https://databreaches.net/2026/08/07/unlimited-technology-systems-data-breach-affects-3-8-million-patients/
- Lawsuit Filing Dates — Emery Reddy law firm, “Unlimited Technology Systems Data Breach Lawsuit”: https://www.emeryreddy.com/blog/data-breach/unlimited-technology-systems-data-breach
Researched and written by Israr Ahmad, legal content researcher and founder of AllAboutLawyer.com. All facts verified against HIPAA Journal, Bleeping Computer, Becker’s Hospital Review, and the public federal court dockets in the Southern District of Ohio on August 18, 2026. Last Updated: August 18, 2026.
This article is for informational purposes only and does not constitute legal advice. Laws vary by state and individual circumstances differ. For advice about your specific situation, consult a qualified attorney.
About the Author
Israr Ahmad is a legal content researcher with 4+ years of experience covering class action settlements and consumer rights cases. He has researched and published coverage of 2,500+ settlements using verified court records, settlement administrator filings, and government sources. Learn more about Israr.
