3rd Party Risk Management
,
Data Breach Notification
,
Data Security
Ohio-Based Unlimited Technology Systems Serves Thousands of Medical Practices

Practice management and financial software firm Unlimited Technology Systems is notifying 3.8 million people of a data theft related to a hack detected in October 2025 within its data center.
See Also: OnDemand | Transform API Security with Unmatched Discovery and Defense
As of Friday, the incident ranked as the largest of the 401 health data breaches posted so far in 2026 on the U.S. Department of Health and Human Services’ HIPAA Breach Reporting Tool website.
Unlimited, in a breach notice, said that on Oct. 19, 2025, it discovered unauthorized activity within its commercial data center.
The company notified law enforcement and hired a cybersecurity forensic firm to assist in the investigation, which determined that a threat actor obtained copies of individuals’ information between Oct. 5 and Oct. 10, 2025.
Affected information potentially includes names, health insurance and patient balance information such as insurance policy numbers, claims and benefits information; medical information including record number, dates of service and diagnosis; scanned documents including driver’s licenses or other government identification, insurance cards and intake forms; Social Security number; date of birth, email, address, phone number and other demographic information.
Affected data varies by individual and did not include full patient medical records, medical imaging or financial information, such as credit card or bank account information, Unlimited said.
As of Friday, no cybercrime gang appeared on the darkweb claiming responsibility for the Unlimited hack. Unlimited did not respond to ISMG’s request for additional details about the incident.
The Unlimited data breach is among a long and growing list of hacks involving third-party business associates, including other providers of revenue cycle management, billing and related services and software to healthcare organizations such as hospitals, clinics and doctor practices.
Other such incidents include a hack also discovered in October 2025 but reported to HHS in February by Missouri-based billing services vendor Trizetto Provider Solutions. That incident, which Trizetto said occurred in November 2024, affected more than 3.4 million people – and prior to Unlimited’s breach report to HHS – ranked for months as the largest health data breach posted on federal breach reporting website so far in 2026 (see: Trizetto Notifying 3.4M of 2025 Data Theft).
