A back-office technology company that most plan sponsors have never heard of has exposed the health insurance and medical data of nearly 3.8 million people. The incident is a direct warning to benefits brokers about blind spots hiding in their clients' vendor chains.
Unlimited Technology Systems, LLC is a Montgomery, Ohio-based provider of practice management and revenue cycle software. The company discovered unauthorized activity in one of its commercial data centers on October 19, 2025. Hackers had already been inside the system for nearly two weeks.
The company's forensic investigation determined that an unauthorized actor copied data between October 5 and October 10, 2025. Unlimited notified the US Department of Health and Human Services (HHS) in late July 2026 that 3,803,750 people were affected. HHS added Unlimited to its breach portal on August 6, 2026, nearly nine months after the breach occurred.
The data taken was not clinical records in the traditional sense. Unlimited does not hold full patient medical records or medical imaging. But what it does hold, and what hackers took, is more useful for fraud and identity theft.
Stolen fields included insurance policy numbers, claims and benefits information, Social Security numbers, and medical record numbers. Hackers also took diagnoses, dates of service, and scanned copies of driver's licenses, government IDs, and insurance cards. Unlimited confirmed these details in a notification letter filed with the Iowa Attorney General's Office in July 2026.
The category that should stand out for benefits brokers is the claims and benefits data. Plan members' insurance policy numbers and benefits information were in scope. Those same data types appear in the systems of third-party billing companies, clearinghouses, and specialty tech providers that brokers' clients use routinely.
Unlimited says it works with more than 4,500 oncology offices and over 6,500 specialty providers. That volume of sensitive patient data means a vast web of healthcare organizations were exposed. Most of them likely had no direct knowledge their patients' information was in Unlimited's data center.
That is the supply chain problem. The breach did not happen at a hospital or a health insurer. It happened at a vendor. As healthcare cyber risk experts have noted, third-party vendor breaches have become one of the fastest-growing sources of healthcare cyber liability.
Brokers advising clients in this space need to be asking harder questions about vendor ecosystems. The 2024 Change Healthcare cyberattack, which exposed health insurance details and Social Security numbers for millions of Americans, originated at a subsidiary of UnitedHealth Group. The Unlimited breach follows the same logic: the weakest link was not the provider, it was the technology in between.
A recent Willis report found that healthcare entities account for 20 percent of all cyber policy notifications, more than any other sector. The finding comes from a Willis dataset spanning 5,500 claims across 13 years and 95 countries.
The breach was discovered in October 2025. HHS was not notified until late July, with the breach portal listing appearing on August 6. That is a gap of roughly nine months.
Under HIPAA's Breach Notification Rule, covered entities must notify HHS within 60 days of discovering a breach affecting 500 or more individuals. Whether Unlimited's timeline complies is a question for regulators. For brokers, it is a reminder that clients need coverage and protocols covering the full disclosure cycle, not just the moment of discovery.
Unlimited said it engaged Kroll, a global risk and investigations firm, to provide affected individuals with two years of credit monitoring, fraud consultation, and identity theft restoration at no cost. The company said it is not aware of any actual misuse of the compromised data.
No threat actor has publicly claimed responsibility for the attack.