The Unlimited Technology Systems breach has affected more than 3.8 million people after attackers accessed files in the healthcare software provider’s data centre in October 2025.

The company says the intruders may have copied highly sensitive patient and personal information during a five-day period. It began notifying affected people in July 2026.

Attackers Accessed Files for Five Days

Unlimited Technology Systems detected unauthorised activity in its commercial data centre on October 19, 2025. The company launched an investigation with help from a cybersecurity forensic firm.

That investigation found that an unauthorised actor accessed files between October 5 and October 10, 2025. The attacker may have obtained copies of personal information belonging to patients whose healthcare providers use the company’s services.

A US Department of Health and Human Services breach portal entry now lists 3,803,750 people as affected by the incident.

Unlimited Technology Systems submitted breach-notification samples to authorities on July 1, 2026. At the time, it did not reveal the full number of people affected.

Sensitive Healthcare and Identity Data May Be Exposed

The potentially exposed information includes names, Social Security numbers, dates of birth, email addresses, postal addresses and telephone numbers.

Attackers may also have accessed demographic data, scans of driving licences and other government identification documents, insurance cards and intake forms.

The exposed files may also have contained health insurance policy numbers, claims and benefits information, medical record numbers, dates of service and diagnosis information.

This combination of identity and medical information can create significant risks for affected people. Criminals may use it for identity theft, insurance fraud, phishing campaigns or other targeted scams.

Healthcare Providers Use Its Financial Technology

Unlimited Technology Systems provides financial and revenue-cycle technology for specialty healthcare providers. The company says it supports 4,500 clinics and 6,500 specialty healthcare providers across the United States.

It also says its platforms process more than $70 billion in net healthcare charges each year.

Because the company processes data for healthcare organisations, many affected patients may not have a direct relationship with Unlimited Technology Systems. A breach notice from the company may therefore come as a surprise.

Company Has Not Identified the Attackers

Unlimited Technology Systems notified law enforcement about the breach and started sending notices to affected patients on July 1, 2026.

The company has not identified the attackers. No ransomware or data-extortion group had publicly claimed responsibility at the time of the notification.

Affected people can use the identity-monitoring services offered through Kroll and should watch closely for unexpected insurance activity, suspicious account notices and phishing messages that use their health information as a lure.


0 responses to “Unlimited Technology Systems Breach Impacts 3.8 Million People”