3.8 Million People's Medical and Personal Data Stolen in Unlimited Technology Systems Breach

A healthcare billing company lost names, Social Security numbers, diagnoses, and scanned ID documents for nearly four million people after hackers spent five days inside its systems last October.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Medical documents and identification cards scattered across a desk with digital pixelation effects obscuring sensitive information, representing the stolen pers
Share

Key points

  • Unlimited Technology Systems, a healthcare billing technology company, confirmed hackers stole data belonging to 3,803,750 people between October 5 and October 10, 2025.
  • Stolen records include Social Security numbers, medical diagnoses, insurance policy numbers, and scanned government ID documents such as driver's licences.
  • The company filed its breach report with HHS in late July 2025; the agency added Unlimited to its public breach list on August 6, 2025.
  • Affected individuals are being offered two years of free credit monitoring and identity theft restoration services.
  • No criminal group has publicly claimed responsibility for the attack.

Unlimited Technology Systems, based in Montgomery, Ohio, handles billing software for cancer clinics and specialist medical practices. It's now notifying nearly 3.8 million people that criminals stole their personal and health records last autumn.

The intrusion ran from October 5 to October 10, 2025. Hackers reached one of the company's commercial data centres, an off-site facility it rents for storage and processing, and extracted sensitive records across five days before anyone detected them.

What exactly was taken?

The stolen files cover almost everything a fraudster needs to impersonate someone or file fake medical claims. Full names, home addresses, Social Security numbers, medical record numbers, diagnosis details, dates of treatment, insurance policy numbers, claims data, and scanned copies of driver's licences were all included.

Unlimited says the breach didn't reach full patient records, imaging files, or payment details like credit card or bank account numbers. That matters, but it's a limited comfort. A Social Security number paired with a diagnosis and an insurance policy number is exactly what criminals use to open credit lines or submit fraudulent healthcare claims.

Should affected people be worried?

Yes. Unlimited says it hasn't seen evidence of actual misuse yet, which is typical in the early weeks after discovery. The company reported the incident to HHS, the federal agency overseeing healthcare privacy rules, and the agency listed Unlimited on its public breach portal on August 6, 2025.

This is the third medical-data breach we've covered in a fortnight: a hack at Brown Health Medical Group in Massachusetts exposed 311,000 records on August 5, and Madera Community Hospital's breach surfaced on August 4. The pattern is worth watching: billing and revenue-cycle vendors sit on aggregated data from thousands of practices, making them high-value targets.

Unlimited is offering everyone affected two years of free credit monitoring, fraud consultation, and identity theft restoration. Take that offer. Beyond it, place a free credit freeze with Equifax and Experian (and TransUnion, separately). A freeze stops lenders opening new accounts in your name even if someone holds your details. Check any explanation-of-benefits statements from your insurer for treatments you didn't receive; that's the clearest early sign of medical identity theft.

As first reported by SecurityWeek, no ransomware or extortion group has claimed the attack, and Unlimited hasn't named anyone responsible.

Detail Fact
Company Unlimited Technology Systems
Breach window October 5 to October 10, 2025
People affected 3,803,750
HHS breach portal listing August 6, 2025
Credit monitoring offered Two years, free
Attacker identified No

The company works with more than 4,500 oncology offices and over 6,500 specialist providers, which explains why a single vendor breach reached patients across so many different care settings.

© 2026 Threat Vectr