Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center.
Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025.
Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered in Montgomery, Ohio. It provides financial, billing, and revenue cycle management solutions to healthcare organizations, supporting more than 4,500 oncology practices and over 6,500 specialty providers. Its platforms help providers manage payments, claims, and administrative operations.
The company discovered the incident later that month.
“On October 19, 2025, we discovered unauthorized activity within our commercial datacenter. Upon discovering the unauthorized activity, Unlimited hired a leading cybersecurity forensic firm to conduct an investigation, notified law enforcement, and conducted a review of the data involved.” reads the data breach notification letter sent to the affected individuals. “Through this investigation, we determined that an unauthorized actor may have obtained a copy of some of your personal information between October 5 and October 10, 2025.”
Unlimited Technology Systems said the stolen data may include names along with health insurance details, medical information such as medical record numbers, diagnoses and dates of service, scanned documents like driver’s licenses, insurance cards and intake forms, Social Security numbers, and personal details including date of birth, address, email and phone number. The company pointed out the security breach did not expose complete medical records, medical images, or payment card and bank account information.
The company notified the U.S. Department of Health and Human Services that the breach affected 3,803,750 people.
The company did not disclose technical details of the attack or the name of the threat actor behind it. At this time, no known extortion groups have claimed responsibility for the attack.
The company said it has strengthened its security measures to reduce the risk of similar incidents. It is also offering affected individuals two years of free identity protection through Kroll, including credit monitoring, fraud consultation, and identity theft restoration services to help detect and respond to potential misuse of personal information.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, data breach)

