Unlimited Technology Systems, a Montgomery, Ohio-based provider of revenue cycle management services, disclosed a data breach affecting 3,803,750 individuals after hackers stole information from one of its commercial data centers. The intrusion occurred between October 10 and October 15, 2025, and was discovered on October 19, 2025. The company later reported the incident to the US Department of Health and Human Services in late July 2026, and HHS added it to its breach portal.
The stolen data included personal, medical, and health insurance information such as Social Security numbers, medical record numbers, diagnoses, dates of service, insurance details, and scanned identity documents. Unlimited Technology Systems said full patient medical records, medical imaging, and financial account or payment card data were not exposed, and it has not identified attempted or actual misuse of the stolen information. The company is offering affected individuals two years of credit monitoring, fraud consultation, and identity theft restoration services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The US Department of Health and Human Services added Unlimited Technology Systems to its breach portal. The listing reflected the reported impact of 3,803,750 affected individuals.
Unlimited Technology Systems publicly disclosed the breach, stating that 3,803,750 individuals were affected. The disclosure followed its July 1, 2026 notifications to authorities and affected patients.
Unlimited Technology Systems notified the US Department of Health and Human Services in late July 2026 that 3,803,750 individuals were affected by the breach. The disclosure established the scale of the incident to federal regulators.
Unlimited Technology Systems began sending data breach notices to affected patients and offered identity monitoring services through Kroll. The notices concerned personal and health information potentially copied during the October 2025 intrusion.
Unlimited Technology Systems discovered the incident in October 2025. One reference gives a specific discovery date of October 19, 2025.
Unlimited Technology Systems said attackers stole data from one of its commercial data centers in October 2025. One source specifies the exfiltration occurred between October 5 and October 10, 2025, while another reports October 10 to October 15, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcecyberveille.ch
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcemalware.news
Open sourcesecurityweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.