Skip to main content
Jump to a category page

On October 19, 2025, Unlimited Technology Systems, LLC (“Unlimited”) discovered unauthorized activity within its commercial datacenter. Unlimited provides practice management software to a range of health care organizations and providers across the country. After discovering the activity, Unlimited hired a cybersecurity forensics firm, notified law enforcement, and reviewed the data involved.

The investigation determined that an unauthorized actor obtained a copy of certain personal information between October 5 and October 10, 2025. According to the Notice of Data Breach, the exposed information may have included name, health insurance and patient balance information (such as insurance policy numbers and claims/benefits information), medical information (such as medical record number, dates of service, and diagnosis information), scanned documents including driver’s licenses or other government-issued identification, insurance cards, and intake forms, Social Security number, and other personal information such as date of birth, email address, phone number, or demographic information. Unlimited states it is unaware of any attempted or actual misuse of this information to date.

Why the Timeline Matters

Unlimited discovered the unauthorized activity on October 19, 2025, and traced the actual data access to a window between October 5 and October 10, 2025. But the company did not file notice with the California Attorney General or begin sending letters to affected individuals until July 21, 2026, roughly nine and a half months after discovery. Unlimited has not publicly explained the reason for the gap.

The delay is notable: a proposed class action, Watts v. Unlimited Technology Systems, LLC, was filed in the U.S. District Court for the Southern District of Ohio on July 22, 2026, one day after the California filing.

What Information Was Exposed?

Based on the official notice, the compromised information may include:

  • Full name
  • Social Security number
  • Date of birth
  • Health insurance policy and claims/benefits information
  • Medical information (medical record number, dates of service, diagnosis information)
  • Scanned driver’s license or other government-issued ID
  • Insurance cards and intake forms
  • Email address, phone number, and other demographic information

Unlimited states the incident did not involve full patient medical records, medical imaging, or financial account information such as credit card or bank account numbers.

What Is Unlimited Offering Affected Individuals?

Unlimited has arranged two years of complimentary identity monitoring through Kroll, including single-bureau credit monitoring, fraud consultation, and identity theft restoration services. Individuals who received a letter can activate these services using the activation code provided before the deadline listed, or call (844) 576-3063 with questions.

Your Information Is at Risk

Because the exposed data includes Social Security numbers, dates of birth, government ID scans, and detailed medical and health insurance information, affected individuals face an elevated risk of identity theft, medical identity theft, and insurance fraud, not just routine financial fraud. A stolen Social Security number paired with medical record numbers and diagnosis information can be used to file fraudulent insurance claims or obtain medical care in someone else’s name, which can be far harder to detect and unwind than a stolen credit card number.

Affected individuals should:

  • Enroll in the free Kroll identity monitoring before the activation deadline in their letter
  • Review medical bills, insurance Explanation of Benefits statements, and credit reports for unfamiliar activity
  • Consider placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion
  • Watch for phishing attempts or calls referencing this incident
  • Consider speaking with a data breach attorney about legal options

Do You Have Legal Options?

Companies that collect and store sensitive health and financial information, particularly a HIPAA Business Associate handling data on behalf of numerous health care providers, have a legal obligation to secure it. A nine-and-a-half-month gap between discovering unauthorized access and notifying the people affected raises real questions about whether Unlimited met that obligation. A proposed class action has already been filed in Ohio; Emery | Reddy is investigating potential claims on behalf of additional individuals affected by this breach.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.

FAQ

How many people were affected by the Unlimited Technology Systems data breach?

Unlimited has not publicly disclosed a total number of affected individuals. It filed notice with the California Attorney General on July 21, 2026; the full scope of the breach is not yet known.

What information was exposed in the breach?

Depending on the individual, the exposed data may include name, Social Security number, date of birth, health insurance and claims/benefits information, medical record number and diagnosis information, and a scanned driver’s license or other government ID.

Why did it take so long for Unlimited to notify people?

Unlimited discovered the unauthorized activity on October 19, 2025 and traced the data access to October 5–10, 2025, but didn’t file notice with the California Attorney General or begin notifying individuals until July 21, 2026, about nine and a half months later. Unlimited has not explained the delay.

What should I do if I received a notification letter?

Activate the free Kroll identity monitoring before the deadline in your letter, monitor your credit reports and medical bills/insurance statements, consider a credit freeze, and consider speaking with a data breach attorney about your legal options.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now