
Unlimited Technology Systems, a healthcare software and revenue cycle management provider, has suffered a data breach affecting more than 3.8 million people.
The HHS Office for Civil Rights lists the Ohio-based company as a business associate and says the hacking incident affected 3,803,750 individuals.
Unlimited Technology Systems first detected unauthorized activity in its commercial data center on October 19, 2025, according to breach notification details previously disclosed to state regulators.
An investigation conducted with a cybersecurity forensics firm determined that an unauthorized actor accessed the company's environment between October 5 and October 10, 2025, gaining access to files containing information belonging to patients of healthcare providers that use Unlimited's software.
The company, based in Montgomery, Ohio, provides practice management software and revenue cycle management services to healthcare organizations. Because it processes patient information on behalf of those customers, affected individuals may have had no direct relationship with Unlimited Technology Systems.
The compromised data varied by person but potentially included names, Social Security numbers, dates of birth, email and mailing addresses, phone numbers, demographic information, and scanned copies of documents such as driver's licenses, government-issued IDs, insurance cards, and patient intake forms.
Exposed protected health information may also include health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis information.
Unlimited said it notified law enforcement and reviewed the affected files to determine what information was involved. A sample notification submitted to the Iowa Attorney General on July 1 did not disclose the total number of people affected nationwide, making the newly published HHS figure the clearest indication so far of the breach's scale.
No ransomware or data-extortion group has publicly claimed responsibility for the intrusion, and Unlimited has not identified the attacker.
People receiving breach notifications should monitor their credit reports, financial accounts, explanation of benefits (EOB) statements, and medical records for suspicious activity. Because Social Security numbers and identity documents may have been exposed, affected individuals should also consider placing a fraud alert or credit freeze and enrolling in any identity-monitoring services offered through the breach notification.







Leave a Reply