3.8 Million People. Almost a Year Before They Knew.

3.8 Million People. Almost a Year Before They Knew.

Written by

Peter Prieto, Cybersecurity Expert

In this post:

In this post:

Section

Healthcare software company Unlimited Technology Systems disclosed a breach affecting 3.8 million people. The incident occurred back in October 2025, but the scale only came to light recently, according to BleepingComputer.

Sit with that gap for a second. Nearly a year passed between the breach happening and the full scope becoming public. For 3.8 million people, that means nearly a year where their information may have been exposed without them knowing it, unable to watch their accounts, freeze their credit, or take any of the steps people normally take once they know they are at risk.

Why the Delay Matters as Much as the Breach

A breach is a bad day. A breach that takes almost a year to fully disclose is a bad year, and the two are not the same category of problem. The initial incident is often a matter of what happened, a vulnerability, a misconfiguration, an attacker who found a way in. The disclosure timeline is a matter of what the company chose to do, and how quickly, once it had at least some understanding that something had gone wrong.

Long disclosure delays tend to happen for a mix of reasons, an investigation that takes time to determine the actual scope, legal review before public statements, or in less charitable interpretations, a reluctance to disclose bad news before it becomes unavoidable. Whatever the reason in any specific case, the effect on affected individuals is the same either way. The exposure window is not just the time between the breach and the fix, it is the time between the breach and the moment people actually learn about it and can act.

This matters especially in healthcare, where the data involved often goes well beyond what a retail or financial breach exposes. Medical records, diagnoses, treatment histories, and insurance details carry a different kind of sensitivity and a longer shelf life for misuse than a credit card number that can simply be canceled and reissued.

The Compounding Cost of a Long Delay

A slow disclosure timeline does not just delay bad news, it actively compounds the consequences once the news does arrive. Regulators tend to scrutinize the gap between discovery and disclosure as closely as the breach itself, and a long delay can become its own separate point of legal exposure, distinct from whatever caused the breach in the first place.

Reputational damage compounds too. A company that discloses quickly, even with an ugly number attached, tends to be perceived as taking the situation seriously. A company whose full scope only becomes clear after nearly a year invites a different, harder question, what took so long, and what were you doing during that time. That question tends to follow a company well past the initial news cycle.

What This Means for Your Business

Build a realistic incident disclosure timeline before you need one, not during a crisis. Know in advance which regulations govern your notification obligations and how quickly they require you to act, so the clock is not the first thing your team has to figure out under pressure.

Treat investigation speed as part of your security posture, not a separate legal matter. The faster your organization can determine the actual scope of an incident, the faster you can meet disclosure obligations and limit the compounding damage of a long delay.

If your business handles healthcare or other highly sensitive data, hold yourself to a stricter disclosure standard than the legal minimum. The reputational cost of a slow disclosure in a sensitive data category tends to be higher than in less sensitive ones.

Communicate proactively even when the full picture isn't complete. An initial disclosure that says the investigation is ongoing, paired with real updates as more becomes known, tends to land better than silence followed by a single, delayed, complete disclosure.

The Bigger Picture

A breach affecting 3.8 million people is a serious event on its own. A breach that takes nearly a year to fully disclose is a reminder that the timeline of a company's response is scrutinized just as closely as the incident itself, sometimes more so. The businesses that come out of an incident with the least additional damage are the ones that treat fast, honest, and clear communication as part of the response from day one, not as an afterthought once the investigation finally concludes.

Stay inside the line.

Empower Your Business with Premier IT

Get reliable, secure, and efficient IT support and cybersecurity that drive real business growth.

Get A FREE Consultation

©2024 Great Marketing AI. All rights reserved.

©2025 Great Marketing. All rights reserved.