Menu
Browse

Cyber Incident Victim: Unlimited Technology Systems, LLC

Date

Oct 2025

Location

United States of America

Status

Unknown

Updated

2026-08-10 14:30

Timeline
Occurred
Oct 2025
Discovered
Oct 2025
Disclosed
Jul 2026
Resolved
Pending
Summary

Unlimited Technology Systems, a revenue cycle management provider based in Montgomery, Ohio, discovered unauthorized activity in a commercial data center that stored patient information for its healthcare clients. An intruder accessed the network over a short period and may have copied files containing names, addresses, email addresses, phone numbers, dates of birth, health insurance details, patient balances, Social Security numbers, medical diagnoses, and scanned government IDs. Full medical records, images, and financial data were not compromised. The breach affected approximately 3.8 million individuals, making it the largest healthcare incident reported so far to date. No threat group has claimed responsibility. The company offered affected persons two years of credit monitoring and has strengthened its security controls.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 23, 2026, the HIPAA Journal reported on a data breach at Unlimited Technology Systems, a Montgomery, Ohio-based revenue cycle management company. The breach was first identified in October 2025, with unauthorized activity detected on October 19, 2025. Investigation assisted by a third‑party cybersecurity and digital forensics firm determined that an unauthorized third party may have accessed the network between October 5 and October 10, 2025 and potentially exfiltrated files containing patient data. The breach was later confirmed to involve the protected health information of 3,803,750 individuals, making it the largest healthcare data breach of the year to date at the time of reporting.

Cyber Incident Image

The data review completed by Unlimited Technology Systems indicated that the compromised information may have included name, address, email address, phone number, date of birth, health insurance information, patient balance information, Social Security number, medical information including diagnosis, and scanned documents such as driver’s license or other government‑issued ID. The company stated that full medical records, medical images, and financial information were not involved in the incident. As a precaution, affected individuals were offered complimentary credit monitoring services for 24 months.

Unlimited Technology Systems implemented enhanced security measures after the breach to prevent similar incidents. The incident highlights the attractiveness of business associates to cybercriminals, as six of the top ten data breaches reported that year occurred at business associates and half of the largest healthcare breaches of all time have involved such entities. Although the breach had not yet appeared on the HHS Office for Civil Rights breach portal at the time of the article, a proposed update to the HIPAA Security Rule aimed to tighten security at business associates and strengthen vendor oversight, with the final rule expected by July 2027.

Sources
Sources available to members
1 source