Unlimited Technology Systems, a Montgomery, Ohio-based vendor that provides financial and revenue cycle technology to healthcare providers, has disclosed a data theft that affects more than 3.8 million individuals. The company reported the incident to the Department of Health and Human Services in late July, stating that 3,803,750 people were affected, and HHS added the organization to its breach portal on August 6. The company works with more than 4,500 oncology offices and over 6,500 specialty providers.
The October 2025 Data Center Theft Behind the 3.8 Million Figure
Unlimited Technology Systems discovered the incident in October 2025, when hackers stole data from its systems between October 5 and October 10 from one of the company’s commercial data centers. The stolen data includes names, addresses, phone numbers, email addresses, Social Security numbers, medical record numbers, diagnoses, dates of service, insurance policy numbers, claims and benefits information, and scanned documents such as driver’s licenses and government IDs.
What the Breach Does and Does Not Include
The breach does not include full patient medical records, medical imaging, or financial information such as credit card or bank account data, according to the company’s disclosure. The absence of those categories narrows the exposure to identity and claims data, but the combination of Social Security numbers, diagnoses, and government ID scans still represents a significant identity-theft and fraud risk for the affected individuals.
A Roughly Ten-Month Gap Between Theft and Disclosure
The incident predates disclosure by roughly ten months. The company said it is not aware of any attempted or actual misuse of the compromised information, and no threat actor or extortion group has claimed the attack. Unlimited Technology Systems is offering affected individuals two years of free credit monitoring, fraud consultation, and identity theft restoration.
Why a Revenue Cycle Vendor Concentrates Risk Across the Sector
The breach illustrates the risk concentrated in healthcare technology vendors that sit between providers and their billing and claims workflows. Firms supplying revenue cycle management accumulate identity and insurance data across thousands of practices, so a compromise of one data center can expose information on millions of patients who have no direct relationship with the vendor.
Recommended Actions for Affected Individuals and Business Partners
Affected individuals should enroll in the offered credit monitoring and remain alert for identity-theft and fraud activity. The company’s remediation guidance and the exact intrusion vector remain unspecified, because the disclosure does not detail how the attackers reached the data center systems. For healthcare organizations that work with such vendors, the incident should prompt them to confirm that business associates maintain incident-response and notification timelines that match the sensitivity of the data they hold and the magnitude of the populations.
The roughly 10-month gap between the October 2025 theft and the late-July notification to HHS raises questions about how promptly affected individuals were told, and it puts breach notification obligations on the vendor as well as the healthcare provider that engaged it. As the affected individuals begin enrolling in credit monitoring, the incident’s full impact will depend on whether the stolen identity and claims data is used for fraud in the months ahead.
The scale of the affected population is notable in part because of the data mix. Health care identifiers such as diagnoses and dates of service, when combined with Social Security numbers and government ID scans, create the building blocks for patient-fraud schemes and synthetic identity creation that can outlast a standard credit-monitoring window. Because the compromised records do not include full medical images or payment card data, the damage is concentrated in identity rather than in direct financial theft, but identity data is the kind that persists. The incident’s length and scale also make remediation an individual responsibility: with no threat actor named and no extortion claim, the affected people have no adversary to track, only the imperative to stay alert and use the offered monitoring. For the healthcare sector the case stands as a reference point for how high a revenue-cycle vendor’s data concentration risk can reach, and how quickly a commercial data center compromise can scale to millions of patient records.