A massive data breach has left nearly four million people vulnerable to identity theft and other malicious activities. Unlimited Technology Systems, a software company that provides financial and revenue cycle technology for healthcare providers, reported that hackers accessed its server in October 2025, exposing sensitive information on patients.
The incident occurred when an unauthorized party accessed files between October 5th and 10th of last year. The data types potentially exposed include full names, social security numbers, dates of birth, email and mailing addresses, phone numbers, demographic information, scans of driver’s licenses or other government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis information.
The company serves over 4,500 clinics and 6,500 specialty healthcare providers across the United States, processing more than $70 billion in net healthcare charges annually. As a result of the breach, Unlimited Technology Systems has notified law enforcement and distributed data breach notices to affected patients on July 1st this year.
The fact that nearly four million people have been impacted by this incident highlights the importance of robust cybersecurity measures in protecting sensitive information. Healthcare organizations often rely on third-party vendors like Unlimited Technology Systems to manage their data, but this also increases the risk of a breach occurring through these relationships.
Notably, Unlimited Technology Systems has not identified the perpetrators behind the hack and no ransomware or data-extortion groups have publicly claimed responsibility. To mitigate the risks associated with the exposed sensitive information, notice recipients were offered identity monitoring services through Kroll.
The incident serves as a reminder to individuals and organizations alike to prioritize cybersecurity measures and regularly test their defenses against potential threats. By taking proactive steps to identify vulnerabilities and address them before they are exploited by attackers, we can reduce the likelihood of a similar breach occurring in the future.
Source: Bleeping Computer — 2026-08-07