Cyber Incident Victim: Unlimited Technology Systems, LLC
Timeline
Summary
Unlimited Technology Systems, a revenue cycle management provider based in Montgomery, Ohio, discovered unauthorized activity in a commercial data center that stored patient information for its healthcare clients. An intruder accessed the network over a short period and may have copied files containing names, addresses, email addresses, phone numbers, dates of birth, health insurance details, patient balances, Social Security numbers, medical diagnoses, and scanned government IDs. Full medical records, images, and financial data were not compromised. The breach affected approximately 3.8 million individuals, making it the largest healthcare incident reported so far to date. No threat group has claimed responsibility. The company offered affected persons two years of credit monitoring and has strengthened its security controls.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 23, 2026, the HIPAA Journal reported on a data breach at Unlimited Technology Systems, a Montgomery, Ohio-based revenue cycle management company. The breach was first identified in October 2025, with unauthorized activity detected on October 19, 2025. Investigation assisted by a third‑party cybersecurity and digital forensics firm determined that an unauthorized third party may have accessed the network between October 5 and October 10, 2025 and potentially exfiltrated files containing patient data. The breach was later confirmed to involve the protected health information of 3,803,750 individuals, making it the largest healthcare data breach of the year to date at the time of reporting.

The data review completed by Unlimited Technology Systems indicated that the compromised information may have included name, address, email address, phone number, date of birth, health insurance information, patient balance information, Social Security number, medical information including diagnosis, and scanned documents such as driver’s license or other government‑issued ID. The company stated that full medical records, medical images, and financial information were not involved in the incident. As a precaution, affected individuals were offered complimentary credit monitoring services for 24 months.
Unlimited Technology Systems implemented enhanced security measures after the breach to prevent similar incidents. The incident highlights the attractiveness of business associates to cybercriminals, as six of the top ten data breaches reported that year occurred at business associates and half of the largest healthcare breaches of all time have involved such entities. Although the breach had not yet appeared on the HHS Office for Civil Rights breach portal at the time of the article, a proposed update to the HIPAA Security Rule aimed to tighten security at business associates and strengthen vendor oversight, with the final rule expected by July 2027.
