Practice Management Firm Unlimited Technology Systems Reports 2025 Data Breach Affecting 3.8 Million Patients
Ohio-based Unlimited Technology Systems, a provider of practice management and financial software to medical practices, has disclosed a data breach that occurred in October 2025, impacting approximately 3.8 million individuals.

Unlimited Technology Systems (UTS), a significant player in practice management and financial software for the healthcare sector, has officially notified 3.8 million patients of a data theft incident discovered in October 2025. The breach, which occurred within UTS's data center, has emerged as the largest health data breach reported to federal regulators in 2026, affecting thousands of medical practices that rely on the company's services.
According to the breach notice issued by UTS, unauthorized activity was first detected on October 19, 2025. The company promptly engaged law enforcement and retained a cybersecurity forensic firm to investigate the incident. The subsequent investigation revealed that a threat actor had gained access to and exfiltrated copies of individuals' sensitive information between October 5 and October 10, 2025.
The compromised data potentially includes a wide range of personal and health-related information. This encompasses names, health insurance details, patient balance information, insurance policy numbers, claims and benefits data, medical record numbers, dates of service, diagnoses, and scanned documents such as driver's licenses, government identification, insurance cards, and intake forms. Additionally, Social Security numbers, dates of birth, email addresses, phone numbers, and other demographic information may have been accessed.
UTS has clarified that the affected data varies by individual and importantly, does not include full patient medical records, medical imaging, or financial information such as credit card or bank account details. This distinction is crucial for understanding the scope and immediate financial risk to affected individuals.
As of the reporting date, no cybercrime gang had publicly claimed responsibility for the attack on the dark web. Unlimited Technology Systems did not provide further details when contacted for additional information. This lack of immediate attribution is not uncommon in large-scale data breaches, as investigations are ongoing and threat actors may choose to remain silent or use sophisticated obfuscation techniques.
The Unlimited Technology Systems breach underscores a persistent and growing trend of attacks targeting third-party business associates within the healthcare ecosystem. These vendors, including providers of revenue cycle management, billing services, and software solutions, represent a critical nexus of sensitive patient data. A compromise at one of these vendors can have a cascading effect across numerous healthcare organizations.
This incident follows a pattern seen in other recent breaches. For example, a hack discovered in October 2025 by Trizetto Provider Solutions, a Missouri-based billing services vendor, affected over 3.4 million individuals. Prior to the UTS disclosure, the Trizetto breach had been the largest health data breach reported to HHS in 2026, highlighting the vulnerability of the healthcare supply chain.
The scale and nature of the Unlimited Technology Systems breach serve as a stark reminder for healthcare organizations and their vendors to continuously assess and strengthen their third-party risk management strategies. Robust security measures, regular audits, and clear incident response plans are essential to protect the sensitive data entrusted to them.