Skip to main content
Emerging ThreatsData Breaches

Unlimited Technology Systems Breach Exposes 3.8 Million People

Rows of computer servers and storage equipment in a data center with some servers having open panels, and a single…

3,803,750 people had personal information exposed after a server breach at Unlimited Technology Systems, according to a U.S. Department of Health and Human Services notification portal entry and the company’s own disclosures.

Scope: a five-day intrusion and a 3,803,750-person exposure

Unlimited Technology Systems reported that an unauthorized actor accessed files hosted in its commercial data center for a five-day window in October 2025. The firm’s disclosure, dated July 20, 2026, says investigators determined the access occurred “between October 5, 2025, and October 10, 2025,” and the company first detected “unauthorized activity” on October 19, 2025.

Although the organization submitted data breach notification samples to authorities on July 1, 2026 without initially revealing an exact impact count, an entry on the U.S. Dept. of Health and Human Services breach notification portal now shows that a company server was breached and data belonging to 3,803,750 people was exposed to an unauthorized party.

Exposed data types: personally identifying and medical details

  • Full names
  • Social Security numbers
  • Dates of birth
  • Email and mailing addresses
  • Phone numbers
  • Demographic information
  • Scans of driver’s licenses or other government IDs
  • Insurance cards
  • Intake forms
  • Health insurance policy numbers
  • Claims and benefits information
  • Medical record numbers
  • Dates of service
  • Diagnosis information

The company’s disclosure states the unauthorized actor “may have obtained copies of personal information belonging to patients of the healthcare providers Unlimited serves.”

Unlimited Technology Systems’ footprint and why this reaches patients directly

Unlimited Technology Systems is a software company that provides financial and revenue cycle technology for specialty healthcare providers. According to the firm’s website details cited in the disclosure, it serves 4,500 clinics and 6,500 specialty healthcare providers across the United States and processes more than $70 billion in net healthcare charges annually.

Because Unlimited processes information on behalf of healthcare organizations, many of the people whose information was exposed do not have a direct relationship with Unlimited. The company’s notification materials note that receiving a breach notice from Unlimited Technology Systems “can be confusing” for patients who normally interact with a clinic or provider rather than the vendor that processes billing and financial data.

Investigation, law enforcement notification, and patient outreach

Unlimited Technology Systems says it launched an investigation with the assistance of a cybersecurity forensic firm after detecting the activity on October 19, 2025. The company notified law enforcement and began distributing data breach notices to affected patients on July 1, 2026.

The company disclosed that no ransomware or data-extortion groups have publicly claimed responsibility for the incident, and that Unlimited “has not identified the perpetrators.” To mitigate risks stemming from the exposure of sensitive data, notice recipients were offered identity monitoring services through Kroll.

What this means for affected patients, healthcare providers, and security teams

  • Patients: Many recipients of the company’s notices will not have a direct contractual relationship with Unlimited, which the firm acknowledges can be confusing. Those notified were offered identity monitoring through Kroll as the immediate remedy provided by Unlimited.
  • Healthcare providers: Clinics and specialty providers that rely on Unlimited for revenue cycle and financial processing are implicated because the breached server hosted information the company processed on their behalf; providers whose patients receive notices will need to reconcile their own communications with Unlimited’s outreach.
  • Security teams and incident responders: Unlimited engaged a cybersecurity forensic firm and notified law enforcement; the company’s timeline shows detection on October 19, 2025, for access that occurred October 5–10, 2025, underscoring the operational reality of investigating and remediating data-center intrusions that may be discovered days or weeks after access.

The factual record in the disclosures and the HHS portal establishes the size of the exposure, the types of information at risk, the firm’s steps to investigate and notify, and that attribution remains unresolved: Unlimited Technology Systems “has not identified the perpetrators,” and no extortion group has claimed responsibility. Those are the concrete next facts to watch in public filings and any law enforcement notices tied to this incident.

Original story