Unlimited Technology Systems data center breach exposes 3.8 million patients
Ohio-based healthcare revenue-cycle technology provider Unlimited Technology Systems reported to HHS that hackers stole personal and medical data on 3,803,750 people from one of its commercial data centers in October 2025.
- Victim
- Unlimited Technology Systems
- users
- 3.8M
In early August 2026, Unlimited Technology Systems, a Montgomery, Ohio company that provides financial and revenue-cycle technology to healthcare providers, reported to the U.S. Department of Health and Human Services that a data breach had affected 3,803,750 people. The filing appeared on the HHS Office for Civil Rights breach portal on 6 August 2026.
The company said it discovered the incident in October 2025 and that hackers had stolen data from one of its commercial data centers between 5 and 10 October 2025. Unlimited serves more than 4,500 oncology offices and 6,500 specialty providers, so most of the people affected were patients of client practices rather than direct customers.
What was exposed
The stolen information includes names, postal and email addresses, phone numbers, Social Security numbers, medical record numbers, diagnoses, dates of service, insurance policy numbers and claims information, as well as scanned documents such as driver's licenses and other government IDs. The company said the data did not include full medical records, medical imaging, or credit card and bank account details.
Unlimited is offering two years of free credit monitoring and identity restoration services and said it had seen no evidence of misuse. No ransomware or extortion group has claimed the attack.
Why it matters
At the time of the filing, the incident ranked as the second-largest U.S. healthcare data breach of 2026, behind DentaQuest and ahead of TriZetto Provider Solutions. It is another example of how billing and revenue-cycle vendors, which collect identity documents and insurance data from many practices, concentrate risk: one compromised data center exposed millions of patients who had never heard of the company.
Timeline
Attackers begin stealing data from one of the company's commercial data centers; the activity lasts until 10 October.
The breach appears on the HHS Office for Civil Rights portal with 3,803,750 affected individuals.
SecurityWeek and BleepingComputer report the breach as one of the largest U.S. healthcare data breaches of 2026.
Sources
- securityweek.comhttps://www.securityweek.com/3-8-million-impacted-by-unlimited-technology-systems-data-breach/
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/
- hipaajournal.comhttps://www.hipaajournal.com/patient-data-exposed-ohio-revenue-cycle-management-company/