Unlimited Technology Systems Data Breach Affected 3.8 Million
The firm, which processes $70 billion in annual charges, identified unauthorized access to patient data in late 2025.
Updated on Sept. 27, 2026 in Cybersecurity

Live Poll
Do you trust third-party software companies to adequately protect your personal medical information?
Unlimited Technology Systems disclosed that unauthorized actors accessed files containing the medical records and personal information of 3,803,750 individuals between October 5 and October 10, 2025. The company, which manages billing for thousands of healthcare providers across the United States, began notifying affected patients on July 1, 2026.
Why it matters
The breach highlights the systemic risks within the medical billing infrastructure that moves $70 billion in net healthcare charges annually across 11,000 clinics and specialty providers. The delayed notification period underscores the ongoing challenges in identifying and investigating unauthorized access within large-scale financial and medical data networks.
The incident involved unauthorized access to databases containing Social Security numbers, dates of birth, and medical records for over 3.8 million people. This data was stored by a firm handling $70 billion in annual net healthcare charges, far exceeding the scale of typical regional provider breaches.
The players
Unlimited Technology Systems
A medical billing infrastructure provider that processes over $70 billion in net healthcare charges for 11,000 clinics and specialty providers.
Department of Health and Human Services
The federal agency tasked with overseeing the protection of patient health information and receiving reports of major data breaches.
The details
The breach occurred after unauthorized actors gained entry to the company's data center, which maintains billing information for 4,500 clinics and 6,500 specialty healthcare providers. The company discovered the intrusion on October 19, 2025, after internal monitoring systems detected unauthorized activity within the network. The scope of the exposed data includes sensitive identifiers, including dates of birth and Social Security numbers, used in the processing of medical billing.
Timeline
October 5, 2025: Unauthorized access to company files began.
October 10, 2025: Unauthorized access to company files ended.
October 19, 2025: The company first detected unauthorized activity in its data center.
July 1, 2026: The company began the notification process for affected patients.
August 10, 2026: The date of the current report.
The Tech Race
This event reflects the ongoing challenges posed by the HIPAA Breach Notification Rule, which mandates rigorous reporting of incidents impacting large populations. It follows a trend of increasing scrutiny on central data processors that serve thousands of individual clinics simultaneously.
Affected patients have been notified as of July 2026, though the specific financial or medical risk to individuals remains under investigation. Those impacted should monitor their medical identity and credit reports for unauthorized activity related to the compromised Social Security numbers and birth dates.
The takeaway
This incident serves as a reminder of the security risks inherent in centralized billing hubs that manage data for thousands of independent healthcare providers. Observers should track future Department of Health and Human Services filings to see if investigators identify a specific entry vector or threat actor.
Further reading
For broader trends in medical data protection, visit Cybersecurity.
Source note: This article includes information reported by Computer Crime Research Center.
Live Poll
Do you trust third-party software companies to adequately protect your personal medical information?









