Healthcare Software Provider Unlimited Technology Systems Suffers Major Data Breach, 3.8 Million Individuals Affected
A significant data breach at **Unlimited Technology Systems**, a healthcare software company, has exposed the personal and health information of over 3.8 million individuals. The incident, detected in October 2025, involved unauthorized access to sensitive data for a five-day period, highlighting the persistent vulnerabilities within the healthcare technology sector.

**Unlimited Technology Systems**, a software firm specializing in financial and revenue cycle technology for specialty healthcare providers, has confirmed a substantial data breach impacting 3,803,750 individuals. The breach, which occurred in October 2025, involved an unauthorized actor accessing a company server.
### Breach Details Emerge
The organization initially submitted data breach notification samples to authorities on July 1, 2026, without disclosing the exact number of affected individuals. However, an entry on the **U.S. Dept. of Health and Human Services** breach notification portal has since clarified the scale of the incident.
**Unlimited Technology Systems** serves approximately 4,500 clinics and 6,500 specialty healthcare providers across the United States, processing over $70 billion in net healthcare charges annually.
### Timeline of the Incident
The company detected unauthorized activity within its commercial data center on October 19, 2025. A subsequent investigation, conducted with the assistance of a cybersecurity forensic firm, determined that an unauthorized actor had accessed and potentially copied files between October 5, 2025, and October 10, 2025.
βOn October 19, 2025, **Unlimited Technology Systems** detected unauthorized activity within its commercial data center and launched an investigation with the assistance of a cybersecurity forensic firm,β the company disclosed on July 20, 2026. βThat investigation determined that, between October 5, 2025, and October 10, 2025, an unauthorized actor accessed files and may have obtained copies of personal information belonging to patients of the healthcare providers **Unlimited** serves.β
### Exposed Data Types
The breach exposed a wide array of highly sensitive personal and health information, including:
* Full names
* Social Security numbers
* Dates of birth
* Email and mailing addresses
* Phone numbers
* Demographic information
* Scans of driver's licenses/other government IDs
* Insurance cards
* Intake forms
* Health insurance policy numbers
* Claims and benefits information
* Medical record numbers
* Dates of service
* Diagnosis information
### Response and Mitigation
Law enforcement was notified of the incident, and **Unlimited Technology Systems** began distributing data breach notices to affected patients on July 1, 2026. As of now, no ransomware or data-extortion groups have publicly claimed responsibility for the attack, and the perpetrators have not been identified.
Given that **Unlimited Technology Systems** processes information on behalf of healthcare organizations, many affected patients may not have a direct relationship with the company, potentially leading to confusion upon receiving a breach notification. To help mitigate the risks associated with the exposed data, recipients of the notice have been offered identity monitoring services through **Kroll**.