Unlimited Technology breach exposes 3.8M people

Hackers accessed personal, medical and insurance records for 3,803,750 people at Unlimited Technology Systems’ commercial data center in October 2025.

Unlimited Technology Systems reported that hackers accessed personal, medical and insurance records for 3,803,750 people at one of its commercial data centers between Oct. 5 and Oct. 10, 2025. The company discovered the intrusion during an internal investigation in October 2025.

A notification filed with the Iowa Attorney General’s Office lists the information taken: names, addresses, phone numbers, email addresses, Social Security numbers, medical record numbers, diagnoses, dates of service, insurance policy numbers, claims and benefits information, and scanned identity documents such as driver’s licenses and government IDs. The company clarified the theft did not include full patient medical records, medical imaging, or credit card and bank account numbers.

Unlimited, based in Montgomery, Ohio, provides financial and revenue-cycle technology to healthcare providers and reports serving more than 4,500 oncology offices and over 6,500 specialty providers. The vendor’s systems handle billing, claims and other revenue-cycle tasks that require access to patient and insurance data.

In late July the company notified the U.S. Department of Health and Human Services that 3,803,750 people were affected; HHS added Unlimited to its breach portal on Aug. 6. Unlimited is offering two years of complimentary credit monitoring, fraud consultation and identity-theft restoration services to affected individuals and reported it is not aware of any attempted or actual misuse of the compromised information.

The company did not identify the threat actor and noted no public claims from known extortion or ransomware groups at the time of its notification. Unlimited has engaged outside cybersecurity specialists and is coordinating with law enforcement and regulatory agencies while the investigation continues. The firm did not disclose whether a ransom was paid, whether backups or restorations were affected, or technical details about how the intruders gained access to the data center.

The notification advised affected individuals to review the notice they received, monitor accounts and use the credit and identity protection services provided. Health records that include Social Security numbers and insurance policy information can be used for identity theft and insurance fraud.

Articles by this author