Unlimited Technology Systems says more than 3.8 million individuals were affected by a data breach. The company, based in Montgomery, Ohio, provides advanced financial and revenue cycle technology for healthcare providers and related organizations, including oncology and specialty practices.
According to the notification letters sent to affected people, the incident involved the theft of personal, medical, and health insurance information from the company’s systems. Below is what the company disclosed, what data was reportedly exposed, and the steps those impacted can consider.
What the company says happened
Unlimited Technology Systems reported that the breach was discovered in October 2025. In its assessment, the company linked the incident to one of its commercial data centers.
The investigation concluded that hackers accessed certain data stored within the company’s systems during the period October 5 through October 10, 2025. The company then sent notifications to affected individuals after completing its review.
How many people were impacted
The company’s reporting centers on a large-scale impact. In late July, Unlimited notified the US Department of Health and Human Services (HHS) that 3,803,750 people were affected. The HHS later added the company to its breach portal on August 6.
This aligns with the figure cited publicly in connection with the incident—commonly described as the 3.8 million data breach.
What information was stolen
In the letters issued to individuals, Unlimited states that the stolen content included a mix of identity data and healthcare-related information. The company says the affected files included:
- Names, addresses, phone numbers, and email addresses
- Social Security numbers
- Medical record numbers
- Diagnoses
- Dates of service
- Health insurance details, including policy numbers
- Claims and benefits information
- Scanned documents such as driver’s licenses and government IDs
Unlimited also emphasized that the incident did not involve full medical records, medical imaging, or financial information like credit card or bank account details.
Credit monitoring and identity protection offered
To help affected people, Unlimited Technology Systems is providing two years of free credit monitoring. The company also includes fraud consultation and identity theft restoration services for those notified.
Offering credit monitoring is a common response when Social Security numbers and identity documents are reportedly included. Fraud consultation and restoration services can also help individuals navigate account issues if misuse occurs later.
Misuse and attempted activity
Unlimited stated that it is not aware of any attempted or actual misuse of the information involved in the breach. While this is an important point, it does not necessarily mean misuse will never occur; it indicates the company had not identified abuse at the time of its disclosures.
For individuals, the key is to stay alert—especially for signs like unexpected account changes, new credit inquiries, or suspicious communications that reference personal details.
Threat actor not identified
Unlimited did not name the threat actor responsible for the intrusion. Additionally, SecurityWeek reported that it had not seen any known extortion or ransomware groups claiming responsibility for the attack.
Without an identified actor, it is difficult to determine whether the breach was financially motivated through ransom, driven by data theft, or linked to other criminal activity patterns.
Regulatory and reporting actions
Unlimited submitted documentation related to the breach to the Iowa Attorney General’s Office. The company noted that a copy of its notification letter was submitted as a PDF to that office, supporting the formal reporting process associated with large-scale data incidents.
These steps often accompany notifications required under state and federal guidance, particularly when sensitive personal information is involved.
What to do if you’re notified
If you received a notice about the 3.8 million data breach, consider these practical actions:
- Enroll in the offered services (such as credit monitoring) promptly and follow the instructions in the notice.
- Review credit reports for unexpected changes or new accounts, and pay attention to credit inquiry activity.
- Verify communications before clicking links or sharing additional information. Use official contact details rather than those included in unsolicited messages.
- Watch for identity theft indicators, including incorrect billing, alerts from lenders, or confusion around insurance-related claims.
Even though Unlimited said it has no knowledge of misuse at the time, monitoring can still help catch issues early.
Why healthcare-related data breaches can be high impact
Healthcare and revenue cycle environments often store data that connects identity with treatment, diagnoses, and coverage details. In this incident, the reported dataset included medical record numbers, diagnoses, dates of service, and insurance policy and claims information—elements that can be used for fraud, social engineering, or targeted impersonation.
That broader context is one reason why individuals may face both identity-related risks (like credit or document misuse) and healthcare-adjacent risks (like confusing claims activity or insurance fraud attempts).
Related breach reporting context
SecurityWeek also referenced other breach incidents affecting different organizations and populations. While those events differ in scope and circumstances, they reflect a broader trend of large-scale exposures impacting healthcare and related sectors.
In general, repeated reporting across the industry suggests that cybersecurity and data protection remain priorities for organizations handling highly sensitive information.
Conclusion
Unlimited Technology Systems’ disclosure indicates that a 3.8 million data breach affected individuals after attackers accessed certain data between October 5 and October 10, 2025. The company reports theft of personal identity details alongside medical and health insurance information, while also clarifying that full medical imaging or direct financial account data was not included.
With two years of credit monitoring, fraud consultation, and identity theft restoration services on offer, affected people have support available. Regardless, staying attentive—especially to credit activity and potential scams—remains an important part of responding to any notification.
Source: https://www.securityweek.com/3-8-million-impacted-by-unlimited-technology-systems-data-breach/
