Unlimited Technology Systems data breach (2026): was your email exposed?
A billing and practice-management vendor used by thousands of US oncology and specialty clinics was broken into over five days in October 2025, and the filing that followed nine months later put 3,803,750 patients in the affected count. Check whether your email was caught up in it — and lock down your accounts before the data is misused.
See which breaches hold my email — free →This incident is known from Unlimited Technology Systems’s own notice and regulatory filings, not from a set of leaked records that anyone can search. The data was taken, but it hasn’t been published — so no breach-checking tool, ours included, can tell you whether you were in it. The letter is the answer: if one arrived, treat yourself as affected. A free check is still worth running for a different reason — it shows which other breaches already hold your email.
That is the figure the company filed with the federal health regulator, and it is a headcount of individuals rather than a count of records or email addresses. It is also the revised number: the first public notice in late July 2026 did not put a scale on the incident at all. Source: the company's public breach notice of July 23, 2026, its filing with the US Department of Health and Human Services' Office for Civil Rights listing 3,803,750 people on August 6, 2026, and healthcare and security press reporting through mid-August 2026.
What happened in the Unlimited Technology Systems breach?
Unlimited Technology Systems and Unlimited Systems: one company. The breach is filed under the legal name, Unlimited Technology Systems, LLC, and that is the name in the news coverage. The company trades as Unlimited Systems, which is the name on its website and on the paperwork a clinic sees. Same company, same incident, two names.
Almost nobody in this breach chose the company that lost their data. Unlimited Technology Systems, based in Montgomery, Ohio, outside Cincinnati, sells revenue-cycle and practice-management software to healthcare providers: the systems that turn a visit into a claim and a claim into a bill. Its customers are clinics, and by its own account they number in the thousands, weighted towards oncology and specialty practices. Patients picked a doctor. The doctor picked the software, and the software held the file.
The intrusion itself was short. An attacker was inside the network between October 5 and October 10, 2025, and the company identified the problem on October 19. What followed was long: the first public notice did not appear until July 23, 2026, and the scale only became public on August 6, 2026, when the incident was posted to the federal breach portal with 3,803,750 people attached to it. That is nine months between the break-in and the number, and for most of that stretch the people in the file had no way to know it existed.
The exposed categories are the awkward combination. Names, addresses, email addresses, phone numbers and dates of birth sat alongside Social Security numbers, health insurance information, patient balances, medical information including diagnoses, and scanned identity documents such as driver's licences. The company has said full medical records, imaging and financial details like card or bank account numbers were not involved. That distinction matters less than it sounds: a scanned government ID plus a Social Security number plus a diagnosis is already enough to open an account, file a claim or make a phone call that sounds informed.
No extortion group has claimed the attack and nothing from it has surfaced publicly, which cuts both ways. There is no leaked set to search, so nobody can confirm from the outside whether they are in it, and the notification letter is the only answer anyone gets. Affected people are being offered two years of credit monitoring with fraud consultation and identity-theft restoration; take it, and treat the deadline on the enrolment page as real, because those offers expire. Then do the part the monitoring does not cover: read the explanations of benefits from your insurer for care you never received, and freeze your credit at all three bureaus, which is free and blocks the one outcome a Social Security number makes possible.
What data was exposed in the Unlimited Technology Systems breach?
The Unlimited Technology Systems breach exposed names, email addresses, phone numbers, physical addresses, dates of birth, social security numbers, health insurance information, personal health data and government-issued ids. The more of these are tied to you, the more ways an attacker can impersonate you or break into your other accounts.
How the leaked Unlimited Technology Systems data can be used against you
Because the Unlimited Technology Systems breach exposed names, email addresses, phone numbers, physical addresses, dates of birth and social security numbers and more, your email address becomes a target for convincing phishing, often referencing this very breach to look legitimate; your phone number fuels scam calls and smishing (fraudulent texts); an exposed government ID number is the most dangerous of all, enabling full identity theft; and your address can be used to locate you, sold on to people-search sites, or used in doxxing.
How to check if you were affected
For this one, the notification letter is the only confirmation there is — nothing about it is searchable yet. If you got a letter, use only the contact details printed on it, because scam waves follow every notification rollout. What you can check right now is the rest of your exposure: which known breaches already hold your email, and what leaked in them.
Check my email against known breaches — free →What to do if your Unlimited Technology Systems account was breached
These steps are prioritized for exactly the kind of data the Unlimited Technology Systems breach exposed.
Add 2FA — ideally an authenticator app or a passkey rather than SMS — to your email, banking and other important accounts, so a stolen password alone can’t get in.
A government ID number is high-risk. Consider a credit freeze with the major bureaus so no one can open credit in your name, and turn on identity monitoring.
Leaked numbers feed robocalls and smishing. Never act on an unsolicited call or text, enable your carrier’s spam filter, and remove your number from data-broker sites that resell it.
Exposed addresses spread to people-search sites that anyone can look up. Opting out of data brokers makes your home harder to find and lowers your doxxing risk.
Health data misuse shows up as care you never received: a bill, an explanation-of-benefits letter, or a claim on your policy for a treatment that isn’t yours. Read those statements instead of filing them, and query anything unfamiliar with the provider and your insurer — medical identity theft is usually caught this way rather than by credit monitoring.
Scammers reference real breaches to sound credible, so treat any email mentioning Unlimited Technology Systems with suspicion, and never use a password-reset link you didn’t request — go to the site directly instead.
Leaked data is resold for years, so a one-time clean-up isn’t enough. Ongoing breach and dark-web monitoring tells you the moment your details reappear, so you can act before an account is misused.
Medical records breached? What to do
Health data has no reset button and no bureau to freeze it at, so the steps differ from a normal breach: read the claims your insurer processes, ask each provider for a copy of your record, and query care you never received.
Read the guide →The Unlimited Technology Systems breach, answered
Was I affected by the Unlimited Technology Systems breach?
The notification letter is the only confirmation. Nothing from this incident has been published as a searchable set of records, so no breach-checking tool can answer it for you — including ours. If a letter reached you, treat yourself as affected and act on it; if none did, there is nothing to check yet.
Is the Unlimited Technology Systems breach letter I received genuine?
Letters from a real notification rollout do arrive by post and can look alarming. Verify it the safe way: use only the phone number or web address printed on the letter itself, typed in by hand — never a link in an email or text about the breach. Notification waves are followed by scams that copy the wording of the real letter.
What data was involved in the Unlimited Technology Systems breach?
Per the disclosure, the data included names, email addresses, phone numbers, physical addresses, dates of birth, social security numbers, health insurance information, personal health data and government-issued ids. Affected people: 3,803,750. That is the figure the company filed with the federal health regulator, and it is a headcount of individuals rather than a count of records or email addresses. It is also the revised number: the first public notice in late July 2026 did not put a scale on the incident at all.
What should I do after the Unlimited Technology Systems breach?
Freeze your credit file with all three bureaus — it is free and, unlike monitoring, it blocks new accounts rather than reporting them afterwards. Take the identity-protection offer in the letter as well, watch medical bills and insurance statements for care you did not receive, and expect phishing that references this breach by name.
When did the Unlimited Technology Systems breach happen?
The incident is dated October 2025 and became public in July 2026. Source: the company's public breach notice of July 23, 2026, its filing with the US Department of Health and Human Services' Office for Civil Rights listing 3,803,750 people on August 6, 2026, and healthcare and security press reporting through mid-August 2026.
Is there compensation for this breach?
Breaches this size often end in a class action, and a settlement can take a year or more to reach a claim form. If one opens for Unlimited Technology Systems, it will be run by a court-appointed administrator and announced on the company’s own breach page — never through an unsolicited email asking you to confirm bank details. Our guide to breach settlement claims covers who qualifies, what a payout actually covers, and the deadlines that decide it.
Was your email in the Unlimited Technology Systems breach?
Check free in about a minute — then we’ll help you remove your exposed data and keep it monitored.
Run my free breach check →