The third-party business vendor recently discovered the breach impacted far more individuals than they initially believed, and the incident is currently the largest breach of the year.
What happened
Unlimited Technology Systems, LLC, a business associate based out of Ohio, recently reported a data breach to the Department of Health and Human Services (HHS). The organization initially believed the incident only impacted approximately 500,000. Now, as the organization has deepened their investigation, they have updated the breach as impacting 3,803,750 individuals. The HHS has described the incident as a hacking incident against the company’s network server.
The company has also begun providing notices to state Attorney Generals when required by law. According to their notice to the Iowa Attorney General, the breach took place between October 5th and October 10th, 2025. It was discovered within the company’s commercial data center on October 19th, 2025. Since the breach was so large in scale, a significant amount of time was needed to investigate the incident, notify impacted organizations and governing organizations, and begin sending notices.
Going deeper
According to the breach notice, the data impacted included patient health insurance information, medical information, any scanned documents (like driver’s licenses), Social Security numbers, and other personal information, like dates of birth, emails, and addresses. The specific information varies per individual.
Furthermore, according to a report from Becker’s Health IT, Unlimited Technology Systems confirmed the incident was a ransomware attack, but did not specify (or may not know) who conducted the attack. They did say however that “several systems within the commercial datacenter hosting its g4-Centricity for Vector platform were encrypted.” The g4-Centricity for Vector is a software created by the company for medical billing, claims data, and more. According to Becker, once the company discovered the encryption, they promptly worked to “suspend access to the hosted systems, launch a forensic investigation and notify law enforcement.”
What’s next
Now that Unlimited Technology Systems has notified many of its partners, we will begin seeing notices to specific individuals. These notices may come from practices themselves, like the Pennsylvania Cancer Specialists, that notified the public on July 21st, 2026, about their connection to the breach. The research center shared that Unlimited began notifications on July 20th. The healthcare center likely also produced this notice to help increase awareness, since Unlimited’s obligation of notifying millions of individuals is likely to be time-consuming and challenging. When multiple organizations notify patients, it can help ensure victims receive the information they need.
In this case, it looks like Unlimited identified a specific software, g4-Centricity for Vector, as the impacted system, so if the technology company faces any legal repercussions, it will likely be related to the security of that specific system.
The big picture
Business associates have been responsible for some of the largest breaches in recent times. According to a Paubox article, business associate breaches have increased approximately 22% each year, making the security of these vendors a critical part of security in the healthcare sector as a whole. The 2024 Change Healthcare breach exposed just how many records business associates can have access to, with that breach exposing records from over 100 million individuals. The breach at Unlimited Technology Systems will be another blow to many organizations that rely on these vendors for software, and also place trust in them for security.
FAQs
Why does impacted information vary?
Since Unlimited Technology Systems is a business associate, they may not have a complete set of data for every individual that was involved in the breach. Some individuals may actually only have a very small amount of data, like names and email addresses, that were accessed. Even though a lot of individuals were impacted, it’s difficult to tell who may be more prone to experience identify theft or fraud.
Will every impacted practice also notify victims?
Not necessarily. Practices have likely come to an agreement with Unlimited Technology Systems to determine who will send notices. Generally, the responsible party takes on the task, but in some cases, practices may also notify victims to help the process go quicker.
