Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025.

The organization submitted data breach notification samples to the authorities this year on July 1st without revealing the exact number of impacted individuals.

An entry on the breach notification portal of the U.S. Dept. of Health and Human Services now shows that a company server was breached and data of 3,803,750 people was exposed to an unauthorized party.

Unlimited Technology Systems is a software company specializing in providing financial and revenue cycle technology for specialty healthcare providers. According to its website, the firm serves 4,500 clinics and 6,500 specialty healthcare providers across the United States, and processes more than $70 billion in net healthcare charges annually.

In October 2025, the firm detected unauthorized activity in its commercial data center and launched an investigation that revealed that hackers had accessed certain files for a five-day period.

“On October 19, 2025, Unlimited Technology Systems detected unauthorized activity within its commercial data center and launched an investigation with the assistance of a cybersecurity forensic firm,” the company disclosed on July 20, 2026.

“That investigation determined that, between October 5, 2025, and October 10, 2025, an unauthorized actor accessed files and may have obtained copies of personal information belonging to patients of the healthcare providers Unlimited serves.”

The data types that were potentially exposed in this incident include:

  • Full names
  • Social Security numbers
  • Dates of birth
  • Email and mailing addresses
  • Phone numbers
  • Demographic information
  • Scans of driver's licenses/other government IDs
  • Insurance cards
  • Intake forms
  • Health insurance policy numbers
  • Claims and benefits information
  • Medical record numbers
  • Dates of service
  • Diagnosis information

The company notified law enforcement of the incident and began distributing data breach notices to affected patients on July 1, 2026.

According to the notification, no ransomware or data-extortion groups have publicly claimed responsibility, and Unlimited Technology Systems has not identified the perpetrators.

Because Unlimited Technology Systems processes information on behalf of healthcare organizations, affected patients typically have no direct relationship with the company itself, and receiving a notice of data breach from it can be confusing.

To mitigate the risk that arises from the exposure of sensitive data, notice recipients were offered identity monitoring services through Kroll.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper