Unlimited Technology Systems, LLC, known publicly as Unlimited Systems, has notified individuals that a cybersecurity incident may have exposed their personal and health-related information. As a technology vendor that processes data on behalf of healthcare providers across the country, a breach at Unlimited Systems can affect patients who may have never directly interacted with the company itself. Any organization entrusted with sensitive personal and medical information has a responsibility to protect it from unauthorized access.
Unlimited Systems’s Data Breach Investigation
Unlimited Technology Systems, LLC, doing business as Unlimited Systems, is a healthcare software and revenue cycle management company headquartered in Montgomery, Ohio, near Cincinnati. The company provides financial management and practice management technology to specialty healthcare providers across the United States, meaning its systems can hold personal and medical information belonging to patients of many different medical practices, even those patients who have no direct relationship with Unlimited Systems itself.
According to a notification filed with the Iowa Attorney General’s office on July 1, 2026, Unlimited Systems discovered unauthorized activity within its commercial datacenter environment. The company’s investigation determined that an unauthorized actor may have obtained copies of personal information between October 5 and October 10, 2025, with the intrusion itself first discovered on October 19, 2025. The gap between the incident window, its discovery, and the eventual public notification illustrates how long a thorough forensic review and legal compliance process can take before affected individuals are formally notified.
The information exposed in the breach reportedly included both personally identifiable information and protected health information. According to the company’s own notification, exposed data may have included full names, Social Security numbers, dates of birth, email addresses, physical addresses, and scanned documents such as copies of driver’s licenses, insurance cards, and intake forms. On the health information side, the breach may have involved health insurance and patient balance information, insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis information. The company has stated that the breach did not involve complete patient medical records, medical imaging, or financial account numbers such as credit card or bank account information.
Data breaches involving third-party healthcare technology vendors have become increasingly common and increasingly consequential, because a single vendor breach can potentially expose information belonging to patients of dozens or even hundreds of separate healthcare provider clients. Vendors like Unlimited Systems often serve as a central data-processing hub, meaning their security posture effectively becomes the security posture of every provider that relies on them. This creates an attractive target for cybercriminals, who can access a much larger volume of sensitive data through one vendor breach than they typically could by targeting an individual medical practice directly.
The combination of Social Security numbers, dates of birth, and government-issued identification numbers exposed in this incident is particularly valuable to identity thieves, who can use this data to open new lines of credit, file fraudulent tax returns, or impersonate victims when applying for loans, medical services, or government benefits. When health insurance and medical billing information is exposed alongside these identifiers, criminals can also engage in medical identity theft, submitting fraudulent insurance claims or obtaining medical services and equipment under a victim’s identity, which can be difficult and time-consuming to detect and unwind, sometimes corrupting a victim’s own medical records for years afterward.
Unlimited Systems is offering two years of complimentary identity monitoring services through Kroll to individuals affected by the breach, which is a longer monitoring period than the one-year offer commonly seen in smaller-scale breaches, suggesting the company considers the risk to affected individuals to be significant. Affected individuals who received a notification letter should enroll in these services promptly and remain alert for any signs of fraudulent activity tied to their personal or medical information in the months and years following the breach.
When Did This Breach Occur?
Unlimited Systems has provided a relatively specific timeline for this incident compared to many data breaches. According to the company’s notification, unauthorized activity was first detected within its commercial datacenter on October 19, 2025. Following an internal and third-party forensic investigation, the company determined that an unauthorized actor may have obtained copies of personal information between October 5 and October 10, 2025, a window of approximately five days.
The breach was formally disclosed to the Iowa Attorney General’s office on July 1, 2026, roughly nine months after the incident itself occurred. This extended gap between discovery and public notification is not unusual for breaches involving large volumes of data or multiple affected healthcare provider clients, since the company needed time to determine the full scope of the incident, identify every individual whose information may have been involved, and coordinate notification obligations across the many states where affected individuals reside.
What Information Was Breached?
According to Unlimited Systems’ notification, the information exposed in the breach fell into two broad categories. Personally identifiable information that may have been accessed included full names, Social Security numbers, dates of birth, email addresses, physical addresses, phone numbers, and other demographic details, along with scanned documents such as copies of driver’s licenses, insurance cards, and patient intake forms.
Protected health information involved in the breach may have included health insurance and patient balance information, such as insurance policy numbers and claims and benefits data, as well as medical information including medical record numbers, dates of service, and diagnosis information. The company has specifically stated that the breach did not involve complete patient medical records, medical imaging, or financial account information such as credit card or bank account numbers. If you received a notification letter, review it carefully, as the exact categories of information affected may vary by individual.
What You Can Do
If you received a notification letter regarding the Unlimited Systems data breach, consider taking the following steps:
- Enroll in the two years of complimentary Kroll identity monitoring services referenced in your notification letter before the activation deadline.
- Review your credit reports from Equifax, Experian, and TransUnion for unfamiliar accounts or inquiries.
- Watch your health insurance statements (Explanation of Benefits) closely for services you did not receive.
- Consider placing a fraud alert or security freeze on your credit files.
- Contact Unlimited Systems’ dedicated call center at 844-576-3063 with any questions about the incident.
These steps can help you catch unauthorized activity early and limit the potential damage from the breach.
File a Data Breach Lawsuit Against Unlimited Systems
If your personal or medical information was exposed in the Unlimited Systems data breach, you may be entitled to pursue legal action. Companies that manage sensitive personal and health information on behalf of healthcare providers are expected to maintain strong security safeguards, and when those safeguards fail, the people whose data was entrusted to them can suffer real, lasting harm.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.