Well being tech vendor Limitless Know-how Techniques disclosed an information breach affecting about 3.8 million sufferers.
The Ohio-based income cycle administration vendor processes billing for greater than 4,500 oncology practices and 6,500 specialty suppliers. It stated hackers accessed its industrial knowledge heart between October 5-10. Notification letters started going out to affected sufferers final month.
The incident marks the second-largest healthcare knowledge breach reported to HHS this 12 months, outranked by an assault on enterprise course of outsourcer Conduent Enterprise Providers, which uncovered the info of greater than 62 million individuals.
Each incidents display simply how a lot a single compromised vendor can expose sufferers who’ve by no means immediately interacted with the corporate in any respect — given a lot of the hundreds of supplier organizations that depend on Limitless for billing and claims processing had no function within the breach itself.
Limitless confirmed the assault was ransomware, however no group has claimed accountability for the assault. The uncovered knowledge various by affected person however included Social Safety numbers, medical data, analysis and remedy particulars and scanned insurance coverage playing cards.
The corporate has not stated whether or not it paid a ransom or how the attackers initially gained entry to its techniques. With the investigation nonetheless open, safety researchers say the whole variety of affected people may climb additional, because it typically does within the case of vendor breaches.
The assault is a part of a broader pattern. Distributors that course of claims, billing and data on suppliers’ behalf have accounted for six of this 12 months’s ten largest healthcare breaches — which has prompted HHS to suggest tightening the HIPAA Safety Rule’s necessities for vendor oversight, although the rule has but to be finalized.
The incident’s timing additionally traces up with business knowledge. Ransomware assaults on healthcare corporations rose 46% in July alone, in line with month-to-month monitoring from Comparitech, which additionally confirmed that assaults on suppliers particularly are up 20% year-over-date in comparison with the identical interval in 2025.
In a separate July incident, hackers claimed to have stolen practically a terabyte of file knowledge from Craneware Group, one other medical billing software program vendor.
If 2026’s sample holds, Limitless’s breach could not maintain its rank for lengthy, both in scale or in firm.
Photograph: boonchai wedmakawand, Getty Pictures

