Healthcare software breach may expose data of 3.8 million people
Patients are receiving individual notifications after a healthcare software vendor disclosed a breach that may affect roughly 3.8 million people nationwide, according to recent independent reporting.
Unlimited Technology Systems, a third-party provider of practice-management software and revenue-cycle services, says an unauthorized actor obtained copies of some individuals’ information between October 5 and October 10, 2025. The company discovered unauthorized activity in its commercial data center on October 19, 2025, according to state filings and the sample consumer notice.
Unlimited began providing notices on approximately July 21, 2026, and is sending them on a rolling basis. That rollout is what makes the incident newly relevant for patients who may not have known that a vendor serving their medical provider was involved.
Why one vendor’s breach can reach many patients
Unlimited provides administrative, practice-management and financial technology services to healthcare organizations and providers. Its role as a third-party vendor means information from patients at unrelated medical practices may have been stored or processed through the same company.
Provider notices describe Unlimited as the vendor involved in the incident. One provider notice says the incident did not involve that provider’s own computer systems or disrupt patient care. That does not mean every patient at an affected practice was involved: notices are being sent to individuals identified through reviews by Unlimited and the relevant data owners.
What information may be involved
The categories varied by individual. Depending on the person, potentially involved information may include:
- Names, dates of birth and demographic information;
- Social Security numbers, driver’s licenses or other government identification;
- Email addresses, physical addresses and phone numbers;
- Insurance cards, policy and claims information, intake forms and patient-balance information; and
- Medical record numbers, dates of service and diagnosis information.
The notices do not establish that every listed category was exposed for every person who receives a letter. Some provider notices also say Social Security numbers may have been involved for only some patients.
What the notice says was not involved
Unlimited’s sample notice says full patient medical records, medical imaging, credit-card information and bank-account information were not involved. The same notice separately lists medical record numbers, dates of service and diagnosis information as data that may have been involved, so patients should read their individualized letters rather than assume that all health-related information was excluded.
Unlimited says it was unaware of any attempted or actual misuse of the information when the notices were issued. The disclosure does not establish that notified individuals have experienced identity theft.
How large is the incident?
TechRadar reported on August 10, 2026, that the broader incident may affect approximately 3.8 million people. That is an independent report of the national scope, not a final government-confirmed count presented in the state filings cited here.
Other reporting has described at least 442,000 affected patients based on notices and disclosures available at the time. State records show the incident reaches multiple states: an Iowa filing lists 162,478 Iowa residents, while a South Carolina state record lists 148,342 affected residents.
Those figures illustrate how a breach at a healthcare technology vendor can spread across multiple provider networks. They should not be added together as a national total because the available reports may cover overlapping or differently updated populations.
What notified consumers should do
Individuals who receive a letter should use the contact information in that notice and activate the offered services before the deadline printed in the letter. Unlimited says notified individuals are being offered 24 months of identity monitoring, fraud consultation and identity-theft restoration through Kroll. Monitoring can help identify suspicious activity, but it does not prevent fraud or guarantee reimbursement.
Consumers should review their credit reports, bank and payment-account statements, insurance explanations of benefits and medical-account activity for unfamiliar changes. A one-year fraud alert may be appropriate for some people. Those seeking stronger protection can consider a security freeze with each of the three major credit bureaus.
Anyone who sees suspected identity theft or unauthorized financial activity should contact the relevant financial institution and appropriate authorities promptly. People who believe they may be affected but did not receive a notice can call Unlimited’s incident-response line at 844-576-3063.
Sources
- Iowa Attorney General breach notification filed by Unlimited Technology Systems
- California Attorney General sample individual notice
- TechRadar report on the approximately 3.8 million figure
- South Carolina Department of Consumer Affairs breach notice listing
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.