A Vendor Breach Hits 3.8M Patients, Texas Halts Data Center Hookups (08/06/2026)

August 6, 2026
A Vendor Breach Hits 3.8M Patients, Texas Halts Data Center Hookups (08/06/2026)
Key Intel / TL;DR
  • Unlimited Technology Systems, an Ohio revenue cycle management provider, now reports a breach affecting 3.8 million patients.
  • The EU's new AI Product Liability Directive reaches manufacturers, software integrators, and anyone in a supply chain touching the bloc.
  • Governor Abbott directed the Public Utility Commission and ERCOT to audit every data center grid connection in Texas, pausing new hookups.
  • The Seventh Circuit ruled text messages are not telephone calls under the Telephone Consumer Protection Act, shifting the text marketing risk picture.
  • The Justice Department declined to charge the company in the first healthcare declination under its new policy, then kept pursuing the chief executive individually.

Another revenue cycle vendor, another seven-figure patient count. Unlimited Technology Systems is now at 3.8 million, and every client practice that outsourced billing to them inherits the notification work. Texas made the more interesting move today by freezing data center grid connections pending a full audit, which turns an energy question into a due diligence question for anyone planning capacity in the state.

Top 5 Critical Compliance Alerts

1. A Revenue Cycle Vendor Breach Reaches 3.8 Million Patients

Unlimited Technology Systems, a Montgomery, Ohio provider of revenue cycle management services, has confirmed a breach affecting 3.8 million patients, up substantially from the figure reported in July. HIPAA Journal

Operator Note: This is the second revenue cycle vendor to disclose a seven-figure patient count in two weeks, after CareCloud reached 345,000 on August 3. If a vendor touches your claims data, they hold your entire patient roster, and that concentration belongs in your risk register at that level rather than as a line item under accounts receivable.

2. The EU Rewrites Product Liability for Software and AI

The EU’s new AI Product Liability Directive overhauls product liability law for companies that make products, integrate software into products, or operate in a supply chain touching the European Union. Software now sits inside the product liability regime rather than beside it. JD Supra

Operator Note: If you embed a model in anything you sell, the liability question is no longer only about your contract terms. Find out this quarter whether your product insurance responds to a defect claim arising from model behavior, because most policies were written before that was a category.

3. Texas Freezes Data Center Grid Connections for an Audit

Governor Abbott directed the Public Utility Commission chairman and the president of the Electric Reliability Council of Texas (ERCOT) to run a full verification and audit of every data center grid connection in the state, pausing new connections while it runs. JD Supra

Operator Note: Anyone with Texas capacity in a build plan now has a schedule risk that no vendor will absorb. Ask your colocation provider today whether their expansion is in the audited set, and get the answer in writing before it becomes a change order.

4. The Seventh Circuit Says Texts Are Not Telephone Calls

In a July 14 decision, the US Court of Appeals for the Seventh Circuit ruled that text messages do not constitute telephone calls under the Telephone Consumer Protection Act (TCPA). JD Supra

Operator Note: This narrows exposure in one circuit and creates a split, which means your text marketing risk now depends on where a plaintiff files. Do not let marketing read the headline as permission.

5. The Company Walked. The Chief Executive Did Not.

The Justice Department resolved its multi-year healthcare fraud investigation into Campus Eye Management with a declination for the company, the first under the new Corporate Enforcement Policy, while continuing to pursue the chief executive individually. JD Supra

Operator Note: Self-disclosure buys the entity a path out and buys the individuals nothing. Anyone advising a board on whether to disclose should be explicit that the calculus differs for the company and for the people signing off.

Additional Compliance Alerts

Regulatory Updates

  • The FTC is enforcing the Consumer Review Rule: Businesses face exposure for suppressing or fabricating reviews, a category many marketing teams still treat as informal. JD Supra
  • A Botox warning letter carries a supply chain lesson: The FDA action has direct implications for Drug Supply Chain Security Act compliance. JD Supra

Third-Party Risk & Due Diligence

  • Two more healthcare breach suits settle: McKenzie Health System and Aspire Health Alliance both resolved data breach litigation. HIPAA Journal
  • Cyber leaders are wary of agentic AI authority: Security executives report reluctance to grant autonomous agents broad permissions, which is a governance signal worth reading before your own deployment decision. Corporate Compliance Insights

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)