Unlimited Technology Systems, LLC, a Montgomery, Ohio‑based provider of practice‑management and revenue‑cycle software, disclosed that it had detected unauthorized activity in its commercial data center on October 19 2025. According to reports from the HIPAA Journal and BleepingComputer, forensic investigators determined that an attacker had copied data between October 5 and October 10 2025. The company notified the U.S. Department of Health and Human Services (HHS) in late July 2026 that 3,803,750 people were affected, and HHS added Unlimited to its breach portal on August 6 2026.

The stolen data did not include full clinical records or medical imaging, but it contained a range of personally identifiable information that is valuable for fraud and identity theft. According to the company’s breach notice filed with the Iowa Attorney General’s Office, the data set included insurance policy numbers, claims and benefits information, Social Security numbers, medical record numbers, diagnoses, dates of service, and scanned copies of driver’s licenses, government IDs, and insurance cards. The breadth of the data suggests that the breach could impact a wide network of healthcare providers, many of whom may not have known that their patients’ information was stored in Unlimited’s systems.

The incident underscores the growing risk of third‑party vendor breaches in the healthcare sector. The 2024 Change Healthcare cyberattack, which exposed health insurance details and Social Security numbers for millions of Americans, also originated at a vendor. A recent Willis report found that healthcare entities account for 20 percent of all cyber policy notifications, more than any other sector. Because Unlimited does not operate hospitals or insurers, the breach illustrates how a single weak link in a vendor chain can expose sensitive data across an entire ecosystem of oncology and specialty practices.

Under HIPAA’s Breach Notification Rule, covered entities must notify HHS within 60 days of discovering a breach that affects 500 or more individuals. The nine‑month gap between the discovery of the unauthorized activity in October 2025 and the notification to HHS in July 2026 raises questions about compliance. Unlimited engaged Kroll, a global risk and investigations firm, to provide affected individuals with two years of credit monitoring, fraud consultation, and identity‑theft restoration at no cost. The company has stated that it is not aware of any actual misuse of the compromised data, and no threat actor has publicly claimed responsibility.

At present, the breach remains the largest known incident involving a practice‑management vendor. Regulators are monitoring the company’s notification timeline, and brokers advising clients in the healthcare space are urged to review vendor ecosystems more closely. No further regulatory actions or court proceedings have been announced, and the company has not reported any confirmed data misuse. The situation remains under observation as authorities assess compliance with HIPAA notification requirements and as the industry continues to grapple with supply‑chain cybersecurity risks.