Unlimited Technology Systems discloses breach of 3.8 million patient records
This digest was compiled by AI from multiple sources — links to the originals are below.

US healthcare software company Unlimited Technology Systems disclosed that attackers stole sensitive personal and medical data from 3.8 million individuals in an October 2025 breach. The company is offering free identity monitoring through Kroll to those affected.
The Breach
Unlimited Technology Systems, a fintech provider for US healthcare, disclosed that intruders broke into its systems on October 5, 2025 and exfiltrated data over five days. The company notified the Department of Health and Human Services and has not identified the attack method or perpetrators. It works with 4,500 clinics and handles over $70 billion in healthcare charges annually.
Exposed Data
The stolen records include full names, Social Security numbers, dates of birth, addresses, phone numbers, driver’s license scans, insurance cards, medical record numbers, and diagnosis data. As the company processes information on behalf of client clinics, most victims had no direct relationship with Unlimited Technology Systems.
Fraud Risks
The data set enables identity theft and wire fraud, carrying serious financial and privacy risks. Unlimited is offering complimentary identity monitoring services through Kroll in response. No ransom demand or claim of responsibility has surfaced.
What's Next
Investigations are ongoing, but the attack vector remains unknown. It is unclear whether the stolen data has been sold or misused.
1 source
Unlimited Technology Systems discloses breach of 3.8 million patient records



