Healthcare Software Firm Unlimited Technology Systems Discloses Breach Affecting 3.8 Million Patients

Unlimited Technology Systems, a US healthcare software vendor specializing in financial and revenue-cycle technology for specialty clinics, has disclosed that a data breach dating back to October 2025 exposed the personal and medical information of roughly 3.8 million people. A filing with the US Department of Health and Human Services’ breach notification portal put the exact figure at 3,803,750 affected individuals — among the larger healthcare data incidents reported this year.

According to the company, unauthorized activity was first detected in its commercial data center on October 19, 2025, prompting an investigation with an outside forensics firm. That investigation found that an unauthorized actor had accessed company files over a five-day window between October 5 and October 10, 2025, potentially obtaining copies of patient data belonging to the healthcare providers Unlimited Technology Systems serves. The company processes billing and revenue-cycle data for roughly 4,500 clinics and 6,500 specialty healthcare providers nationwide, handling more than $70 billion in net healthcare charges annually — meaning the breach’s reach extends well beyond the company’s own direct customers to patients who may never have heard of the firm.

The exposed data reportedly includes full names, Social Security numbers, dates of birth, contact information, government ID scans, insurance and claims details, medical record numbers, and diagnosis information — a combination that creates significant risk for identity theft and medical fraud. No ransomware or extortion group has publicly claimed responsibility, and the company says it has not identified the attackers.

Notably, the company did not begin notifying affected patients until July 1, 2026 — roughly nine months after the breach was first detected — a delay that has drawn criticism given US regulatory requirements to report breaches within 60 days of discovery. Affected individuals are being offered identity-monitoring services through Kroll. Because many recipients have no direct relationship with Unlimited Technology Systems, healthcare privacy advocates have flagged the incident as an example of the growing risk posed by third-party vendors that handle sensitive patient data on behalf of providers.

Read the original report →