Unlimited Technology Systems, LLC
Incident posture
Linked entities
- Victim
- Unlimited Technology Systems, LLC
- Threat actors
- 0 actors
- Sources
- 6 sources
Timeline
Summary
Unlimited Technology Systems, LLC discovered unauthorized activity within its commercial data center and, after investigation, determined that an intruder accessed the environment and potentially exfiltrated files containing personal and protected health information of approximately 3.8 million individuals. The compromised data included names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, health insurance details, patient balance information, medical information such as diagnoses, and scanned documents like driver’s licenses and government IDs, while full medical records, medical images, and payment card or bank account data were not involved. The company notified law enforcement, regulators, and affected individuals, and offered two years of free credit monitoring and identity protection services; no ransomware or extortion group has claimed responsibility for the incident.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On October 19, 2025, Unlimited Technology Systems detected unauthorized activity within one of its commercial data centers and promptly initiated an investigation with the assistance of a third‑party cybersecurity forensic firm. The company determined that the unauthorized access had occurred between October 5 and October 10, 2025, during which an actor accessed and potentially exfiltrated files containing patient information. Law enforcement and regulatory authorities were notified shortly after the discovery, and the breach was later disclosed to the public beginning July 1, 2026.
The compromised data affected 3,803,750 individuals across the United States and included names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, health insurance information, patient balance information, medical information such as diagnosis, and scanned documents like driver’s licenses, insurance cards, intake forms, and other government IDs. The company confirmed that full medical records, medical images, payment card details, and bank account information were not part of the exposed data. The breach impacted patients served by more than 4,500 clinics and 6,500 specialty healthcare providers that use Unlimited Technology Systems’ revenue cycle management and practice management software.
In response, Unlimited Technology Systems notified the U.S. Department of Health and Human Services Office for Civil Rights, state regulators, and affected individuals, offering 24 months of free credit monitoring and identity protection services through Kroll. The company stated that it had strengthened its security measures to reduce the risk of similar incidents and noted that no ransomware, extortion group, or threat actor had claimed responsibility for the attack. No public indicators of compromise were released, and the investigation did not identify the specific method used to gain initial access. The incident was recorded on the HHS breach portal and remains one of the largest healthcare data breaches reported in 2026.
Sources
Sources available to members: 6 sources.