3.8 Million People's Medical and Personal Data Stolen in Unlimited Technology Systems Breach
A healthcare billing company lost names, Social Security numbers, diagnoses, and scanned ID documents for nearly four million people after hackers spent five days inside its systems last October.

Key points
- Unlimited Technology Systems, a healthcare billing technology company, confirmed hackers stole data belonging to 3,803,750 people between October 5 and October 10, 2025.
- Stolen records include Social Security numbers, medical diagnoses, insurance policy numbers, and scanned government ID documents such as driver's licences.
- The company filed its breach report with the US Department of Health and Human Services on July 2025; the agency added Unlimited to its public breach list on August 6, 2025.
- Affected individuals are being offered two years of free credit monitoring and identity theft restoration services.
- No criminal group has publicly claimed responsibility for the attack.
Unlimited Technology Systems, a company based in Montgomery, Ohio, that handles billing and payment software for cancer clinics and other specialist medical practices, is telling nearly 3.8 million people that criminals stole their personal and health information last autumn.
The break-in ran from October 5 to October 10, 2025. Hackers got into one of the company's commercial data centres, meaning an off-site facility it rents to store and process data, and walked away with a wide range of sensitive records before anyone noticed.
What exactly was taken?
The stolen files cover almost every piece of information a criminal would need to impersonate someone or commit medical fraud. Full names, home addresses, phone numbers, email addresses, and Social Security numbers were all included, as were medical record numbers, diagnosis details, dates of treatment, insurance policy numbers, claims and benefits information, and scanned copies of driver's licences and government ID cards.
Unlimited says the breach did not reach full patient medical records, medical imaging files, or financial details such as credit card or bank account numbers. That is a meaningful limit, but the data that was stolen is still highly sensitive: a Social Security number combined with a diagnosis and an insurance policy number is exactly what fraudsters use to file fake medical claims or open new lines of credit in someone else's name.
Should affected people be worried?
Yes, though Unlimited says it has seen no evidence so far that anyone has actually misused the stolen records. The company reported the incident to the US Department of Health and Human Services (HHS), the federal agency that oversees healthcare privacy rules, which added Unlimited to its public breach tracking list on August 6, 2025.
As a precaution, Unlimited is offering everyone affected two years of free credit monitoring, fraud consultation, and identity theft restoration. Anyone who receives a notification letter should take up that offer immediately.
Beyond that, it is sensible to place a free credit freeze with each of the three major credit bureaus (Equifax, Experian, and TransUnion). A freeze stops lenders from opening new accounts in your name even if someone has your details. Watch any explanation-of-benefits statements from your health insurer for treatments you did not receive; that is a common sign of medical identity theft.
As first reported by SecurityWeek, no known ransomware or extortion group has claimed the attack, and Unlimited has not named the people responsible.
| Detail | Fact |
|---|---|
| Company | Unlimited Technology Systems |
| Breach window | October 5 to October 10, 2025 |
| People affected | 3,803,750 |
| HHS breach portal listing | August 6, 2025 |
| Credit monitoring offered | Two years, free |
| Attacker identified | No |
The company says it works with more than 4,500 oncology offices and 6,500 specialist medical providers, which explains why the breach reached so many patients across different healthcare settings.



