3.8 Million Impacted by Unlimited Technology Systems Data Breach

A massive data breach affecting over 3.8 million individuals has been uncovered by Unlimited Technology Systems, a company providing financial and revenue cycle technology to healthcare providers and organizations across the United States. The breach, which occurred in October 2025, involved one of the company’s commercial data centers and resulted in hackers stealing sensitive personal, medical, and health insurance information.

Unlimited Technology Systems, based in Montgomery, Ohio, claims to work with more than 4,500 oncology offices and over 6,500 specialty providers. The stolen data includes names, addresses, phone numbers, email addresses, Social Security numbers, medical record numbers, diagnoses, dates of service, insurance policy numbers, claims/benefits information, and scanned documents such as driver’s licenses and government IDs.

The good news is that the hackers did not manage to obtain full patient medical records, medical imaging, or financial information like credit card or bank account details. However, the compromised data still poses a significant risk of identity theft and unauthorized access to sensitive health information. Unlimited Technology Systems has reportedly notified the US Department of Health and Human Services (HHS) that 3,803,750 people were affected, and the HHS has added the company to its breach portal.

The investigation into the breach is ongoing, but it appears that hackers managed to breach one of Unlimited’s data centers between October 5th and 10th, 2025. The company claims not to be aware of any attempted or actual misuse of the stolen information, but this is a typical response in such cases, making it difficult to determine the true extent of the breach.

As a result of the breach, Unlimited Technology Systems is providing affected individuals with two years of free credit monitoring, fraud consultation, and identity theft restoration services. This move aims to mitigate the potential harm caused by the breach and prevent any future misuse of the stolen data.

The data breach serves as a stark reminder of the ongoing threat posed by cyber attacks against healthcare providers and organizations that handle sensitive patient information. It highlights the importance of robust cybersecurity measures, regular security audits, and timely incident response procedures in preventing such breaches from occurring in the first place.

In light of this incident, it is essential for individuals to remain vigilant and take proactive steps to protect their personal data. This includes regularly monitoring credit reports, being cautious when sharing sensitive information online, and using strong passwords to secure digital accounts. By taking these precautions, we can minimize the risk of falling victim to identity theft and unauthorized access to our sensitive information.


Source: SecurityWeek — 2026-08-07