All Breaches
October 5, 2025 Verified Sensitive Record Healthcare Technology

Unlimited Technology Systems 2025 Data Breach

The Unlimited Technology Systems 2025 data breach resulted from unauthorized activity in the commercial data center of a company providing practice-management and revenue-cycle software to healthcare organizations. Unlimited discovered the event October 19, 2025. Its investigation found that an unauthorized actor may have obtained copies of some personal information from October 5 through October 10.

Possible data included names, SSNs, birth dates, emails, physical addresses, telephone numbers, and demographic information; scans of driver's licenses or other government IDs, insurance cards, and intake forms; medical-record numbers, service dates, diagnoses, insurance-policy numbers, claims or benefits, and patient-balance information. No unique national total was disclosed, so pwnCount and totalRecords are zero, and importedRecordCount is zero.

How Was the Unlimited Technology Systems Breach Confirmed?

The primary evidence is Unlimited Technology Systems' consumer letter published in an Iowa Attorney General filing. On the company's behalf, it directly explains discovery, the October 5–10 copy-acquisition period, law-enforcement and forensic response, confirmed information categories, data expressly excluded, two years of Kroll services, and the assistance line.

A California Attorney General record provides a separate official notification trail. Claim Depot connects those files with Massachusetts, South Carolina, and Texas notices and reports 277,364 people in Texas, 148,342 in South Carolina, and 2,223 in Massachusetts. These are state subsets, not a national total, and are not added without knowing whether the populations are mutually exclusive.

What Happened From October 5 Through October 10, 2025?

Unlimited discovered unauthorized activity in its commercial data center October 19. The company retained a leading cybersecurity forensics firm, notified law enforcement, and reviewed the data involved. The investigation concluded that an unauthorized actor may have obtained a copy of some personal information from October 5 through October 10.

The public letter does not identify the initial access vector, actor, malware, ransom demand, or publication of data. “May have obtained a copy” confirms potential extraction but does not establish that every field was copied for every person. Because Unlimited processes information for healthcare providers, some individuals may be affected even if they have no direct relationship with the company.

What Identity and Contact Information Was Affected?

Depending on the individual, data could include names, Social security numbers, dates of birth, email addresses, physical addresses, telephone numbers, and other demographic information. Scanned documents could include driver's licenses or other government IDs, insurance cards, and patient-intake forms. It should not be assumed that every individual had all fields present; personal letters define the specific scope.

A combination of SSN, birth date, contact data, and identity images creates lasting exposure to fraudulent credit, tax-identity misuse, document impersonation, and targeted social engineering. Recipients should consider a credit freeze, fraud alert, and IRS Identity Protection PIN and should not provide identity images, passwords, or verification codes in messages claiming to come from a healthcare provider or Unlimited.

What Medical and Insurance Data Was in Scope?

Health-insurance and patient-balance information could include insurance-policy numbers, claims or benefits information, and patient balances. Medical information included medical-record numbers, dates of service, and diagnoses. Insurance cards and intake forms were also listed among scanned documents. These fields can enable medical-identity misuse, fraudulent claims, or scams using authentic care context.

Individuals should review explanation-of-benefits statements, patient portals, and provider accounts for services, diagnoses, claims, balances, or contact changes they do not recognize. Suspicious entries should be verified directly with the provider and insurer. Because Unlimited serves multiple healthcare customers, a recipient who does not recognize the vendor should verify the provider relationship identified in the notice through an official channel.

What Data Was Expressly Excluded?

The official consumer letter expressly says the incident data did not include full patient medical records or medical imaging. It also excludes financial information such as credit-card and bank-account information. Patient-balance information does not conflict with this exclusion: a debt or balance context may be present while card and bank-account details are absent.

LeakData preserves that distinction in its data classes and does not add payment cards, bank accounts, complete medical files, or images to the incident scope. General guidance to monitor bank and card statements does not prove that those fields were exposed. Incorrectly adding source-excluded data would distort both user risk assessment and search-result accuracy.

How Many People Were Affected and How Did Unlimited Respond?

Texas reported 277,364 people, South Carolina 148,342, and Massachusetts 2,223; these are not a deduplicated nationwide population. It is unclear whether a person can appear across jurisdictional records or what other states cover. LeakData therefore keeps pwnCount and totalRecords at zero instead of presenting subsets as a total; importedRecordCount is zero because no patient or customer rows were obtained.

Unlimited enhanced security, investigated with forensic specialists, notified law enforcement, and offered eligible people two years of Kroll identity monitoring. The package includes single-bureau credit monitoring, fraud consultation, and identity-theft restoration. Questions may be directed to 844-576-3063 weekdays from 9 a.m. to 6:30 p.m. ET. LeakData does not host incident files or personal records.

0
Affected Accounts
20
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

20
Personal information
Protected health information
Names
Social security numbers
Dates of birth
Email addresses
Physical addresses
Phone numbers
Demographic information
Driver's license numbers
Government identification
Insurance cards
Intake forms
Health insurance information
Insurance policy numbers
Claims or benefits information
Patient balance information
Medical record numbers
Dates of service
Diagnosis information

Additional Information

Added DateJuly 27, 2026
Breach DateOctober 5, 2025
Domainunlimitedsystems.com
SourceOfficial Unlimited Technology Systems regulatory letter confirming possible acquisition of personal and protected health information from its commercial data center
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information