Were you recently affected by a data breach?

Unlimited Systems Data Breach

Unlimited Technology Systems, a healthcare software vendor based in Ohio, disclosed a data breach after discovering unauthorized network access in October 2025. Exposed information may include Social Security numbers, dates of birth, driver’s license numbers, and health insurance details. The company serves healthcare providers nationwide.

Unlimited Systems
Date of Breach: October 5-10, 2025 (discovered October 19, 2025)
CAU logo

Who was affected:

Clients of Unlimited Systems

Impacted Data:

Names, Social Security numbers, dates of birth, email addresses, physical addresses, driver’s license numbers, health insurance information, medical record numbers

Unlimited Technology Systems, LLC, known publicly as Unlimited Systems, has notified individuals that a cybersecurity incident may have exposed their personal and health-related information. As a technology vendor that processes data on behalf of healthcare providers across the country, a breach at Unlimited Systems can affect patients who may have never directly interacted with the company itself. Any organization entrusted with sensitive personal and medical information has a responsibility to protect it from unauthorized access.

Unlimited Systems’s Data Breach Investigation

Unlimited Technology Systems, LLC, doing business as Unlimited Systems, is a healthcare software and revenue cycle management company headquartered in Montgomery, Ohio, near Cincinnati. The company provides financial management and practice management technology to specialty healthcare providers across the United States, meaning its systems can hold personal and medical information belonging to patients of many different medical practices, even those patients who have no direct relationship with Unlimited Systems itself.

According to a notification filed with the Iowa Attorney General’s office on July 1, 2026, Unlimited Systems discovered unauthorized activity within its commercial datacenter environment. The company’s investigation determined that an unauthorized actor may have obtained copies of personal information between October 5 and October 10, 2025, with the intrusion itself first discovered on October 19, 2025. The gap between the incident window, its discovery, and the eventual public notification illustrates how long a thorough forensic review and legal compliance process can take before affected individuals are formally notified.

The information exposed in the breach reportedly included both personally identifiable information and protected health information. According to the company’s own notification, exposed data may have included full names, Social Security numbers, dates of birth, email addresses, physical addresses, and scanned documents such as copies of driver’s licenses, insurance cards, and intake forms. On the health information side, the breach may have involved health insurance and patient balance information, insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis information. The company has stated that the breach did not involve complete patient medical records, medical imaging, or financial account numbers such as credit card or bank account information.

Data breaches involving third-party healthcare technology vendors have become increasingly common and increasingly consequential, because a single vendor breach can potentially expose information belonging to patients of dozens or even hundreds of separate healthcare provider clients. Vendors like Unlimited Systems often serve as a central data-processing hub, meaning their security posture effectively becomes the security posture of every provider that relies on them. This creates an attractive target for cybercriminals, who can access a much larger volume of sensitive data through one vendor breach than they typically could by targeting an individual medical practice directly.

The combination of Social Security numbers, dates of birth, and government-issued identification numbers exposed in this incident is particularly valuable to identity thieves, who can use this data to open new lines of credit, file fraudulent tax returns, or impersonate victims when applying for loans, medical services, or government benefits. When health insurance and medical billing information is exposed alongside these identifiers, criminals can also engage in medical identity theft, submitting fraudulent insurance claims or obtaining medical services and equipment under a victim’s identity, which can be difficult and time-consuming to detect and unwind, sometimes corrupting a victim’s own medical records for years afterward.

Unlimited Systems is offering two years of complimentary identity monitoring services through Kroll to individuals affected by the breach, which is a longer monitoring period than the one-year offer commonly seen in smaller-scale breaches, suggesting the company considers the risk to affected individuals to be significant. Affected individuals who received a notification letter should enroll in these services promptly and remain alert for any signs of fraudulent activity tied to their personal or medical information in the months and years following the breach.

When Did This Breach Occur?

Unlimited Systems has provided a relatively specific timeline for this incident compared to many data breaches. According to the company’s notification, unauthorized activity was first detected within its commercial datacenter on October 19, 2025. Following an internal and third-party forensic investigation, the company determined that an unauthorized actor may have obtained copies of personal information between October 5 and October 10, 2025, a window of approximately five days.

The breach was formally disclosed to the Iowa Attorney General’s office on July 1, 2026, roughly nine months after the incident itself occurred. This extended gap between discovery and public notification is not unusual for breaches involving large volumes of data or multiple affected healthcare provider clients, since the company needed time to determine the full scope of the incident, identify every individual whose information may have been involved, and coordinate notification obligations across the many states where affected individuals reside.

What Information Was Breached?

According to Unlimited Systems’ notification, the information exposed in the breach fell into two broad categories. Personally identifiable information that may have been accessed included full names, Social Security numbers, dates of birth, email addresses, physical addresses, phone numbers, and other demographic details, along with scanned documents such as copies of driver’s licenses, insurance cards, and patient intake forms.

Protected health information involved in the breach may have included health insurance and patient balance information, such as insurance policy numbers and claims and benefits data, as well as medical information including medical record numbers, dates of service, and diagnosis information. The company has specifically stated that the breach did not involve complete patient medical records, medical imaging, or financial account information such as credit card or bank account numbers. If you received a notification letter, review it carefully, as the exact categories of information affected may vary by individual.

What You Can Do

If you received a notification letter regarding the Unlimited Systems data breach, consider taking the following steps:

  • Enroll in the two years of complimentary Kroll identity monitoring services referenced in your notification letter before the activation deadline.
  • Review your credit reports from Equifax, Experian, and TransUnion for unfamiliar accounts or inquiries.
  • Watch your health insurance statements (Explanation of Benefits) closely for services you did not receive.
  • Consider placing a fraud alert or security freeze on your credit files.
  • Contact Unlimited Systems’ dedicated call center at 844-576-3063 with any questions about the incident.

These steps can help you catch unauthorized activity early and limit the potential damage from the breach.

File a Data Breach Lawsuit Against Unlimited Systems

If your personal or medical information was exposed in the Unlimited Systems data breach, you may be entitled to pursue legal action. Companies that manage sensitive personal and health information on behalf of healthcare providers are expected to maintain strong security safeguards, and when those safeguards fail, the people whose data was entrusted to them can suffer real, lasting harm.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: October 8, 2025 (discovered); notifications sent July 10, 2026
Date of Breach: August 3, 2026 (reported)
Date of Breach: May 22, 2026 (incident); notifications began August 3, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.