Unlimited Technology Systems, a Montgomery, Ohio-based healthcare technology provider, has begun notifying over 3.8 million individuals that their personal information was compromised in a data breach discovered in late 2025.
The company, which provides financial and revenue cycle technology to more than 4,500 oncology offices and 6,500 specialty healthcare providers, said attackers accessed one of its commercial data centers between October 5 and October 10, 2025. The intrusion was discovered in October of that year, but the full scope of affected individuals was only confirmed months later.
Stolen data includes names, addresses, phone numbers, email addresses, Social Security numbers, medical record numbers, diagnoses, dates of service, insurance policy numbers, claims and benefits information, and scanned documents such as driver’s licenses and government-issued IDs. Unlimited noted that full patient medical records, medical imaging, and financial data such as credit card or bank account numbers were not taken.
The company submitted its breach notification to the US Department of Health and Human Services in late July, reporting that 3,803,750 people were affected. HHS added Unlimited to its breach portal on August 6. The notification letter was also filed with the Iowa Attorney General’s office.
Unlimited has not identified the threat actor behind the intrusion, and no known ransomware or extortion group has claimed responsibility. The company said it is not aware of any attempted or actual misuse of the compromised information.
Affected individuals are being offered two years of free credit monitoring, fraud consultation, and identity theft restoration services. The breach adds to a growing list of large-scale healthcare data incidents in 2026, underscoring the sector’s continued vulnerability to cyberattacks targeting sensitive patient information.
Healthcare providers and their technology vendors remain a top target for cybercriminals due to the high value of medical records and personal identifiers on the dark web. Industry analysts say the volume of healthcare breaches has surged as more providers outsource data management to third-party technology firms like Unlimited, expanding the attack surface across the sector.
discussion