3.8 Million People's Medical and Personal Data Stolen in Unlimited Technology Systems Breach
A healthcare billing company lost names, Social Security numbers, diagnoses, and scanned ID documents for nearly four million people after hackers spent five days inside its systems last October.

Key points
- Unlimited Technology Systems, a healthcare billing technology company, confirmed hackers stole data belonging to 3,803,750 people between October 5 and October 10, 2025.
- Stolen records include Social Security numbers, medical diagnoses, insurance policy numbers, and scanned government ID documents such as driver's licences.
- The company filed its breach report with HHS in late July 2025; the agency added Unlimited to its public breach list on August 6, 2025.
- Affected individuals are being offered two years of free credit monitoring and identity theft restoration services.
- No criminal group has publicly claimed responsibility for the attack.
Unlimited Technology Systems, based in Montgomery, Ohio, handles billing software for cancer clinics and specialist medical practices. It's now notifying nearly 3.8 million people that criminals stole their personal and health records last autumn.
The intrusion ran from October 5 to October 10, 2025. Hackers reached one of the company's commercial data centres, an off-site facility it rents for storage and processing, and extracted sensitive records across five days before anyone detected them.
What exactly was taken?
The stolen files cover almost everything a fraudster needs to impersonate someone or file fake medical claims. Full names, home addresses, Social Security numbers, medical record numbers, diagnosis details, dates of treatment, insurance policy numbers, claims data, and scanned copies of driver's licences were all included.
Unlimited says the breach didn't reach full patient records, imaging files, or payment details like credit card or bank account numbers. That matters, but it's a limited comfort. A Social Security number paired with a diagnosis and an insurance policy number is exactly what criminals use to open credit lines or submit fraudulent healthcare claims.
Should affected people be worried?
Yes. Unlimited says it hasn't seen evidence of actual misuse yet, which is typical in the early weeks after discovery. The company reported the incident to HHS, the federal agency overseeing healthcare privacy rules, and the agency listed Unlimited on its public breach portal on August 6, 2025.
This is the third medical-data breach we've covered in a fortnight: a hack at Brown Health Medical Group in Massachusetts exposed 311,000 records on August 5, and Madera Community Hospital's breach surfaced on August 4. The pattern is worth watching: billing and revenue-cycle vendors sit on aggregated data from thousands of practices, making them high-value targets.
Unlimited is offering everyone affected two years of free credit monitoring, fraud consultation, and identity theft restoration. Take that offer. Beyond it, place a free credit freeze with Equifax and Experian (and TransUnion, separately). A freeze stops lenders opening new accounts in your name even if someone holds your details. Check any explanation-of-benefits statements from your insurer for treatments you didn't receive; that's the clearest early sign of medical identity theft.
As first reported by SecurityWeek, no ransomware or extortion group has claimed the attack, and Unlimited hasn't named anyone responsible.
| Detail | Fact |
|---|---|
| Company | Unlimited Technology Systems |
| Breach window | October 5 to October 10, 2025 |
| People affected | 3,803,750 |
| HHS breach portal listing | August 6, 2025 |
| Credit monitoring offered | Two years, free |
| Attacker identified | No |
The company works with more than 4,500 oncology offices and over 6,500 specialist providers, which explains why a single vendor breach reached patients across so many different care settings.



