In October 2025, Unlimited Technology Systems, LLC, a healthcare practice management software and revenue cycle management company, identified unauthorized activity in its commercial datacenter on October 19, 2025. The company later determined that an unauthorized actor may have accessed and obtained copies of certain information between October 5 and October 10, 2025. This incident involved patient and insurance-related information.
The exposed data types include personally identifiable information (PII) such as names, Social Security numbers, dates of birth, email and mailing addresses, phone numbers, demographic information, and scanned documents like driver’s licenses, government IDs, insurance cards, and intake forms. Protected health information (PHI) such as health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis information were also involved. The total number of affected individuals has not been publicly disclosed.
A sample notice was submitted to the Iowa Attorney General on July 1, 2026. Details regarding the full scope of the breach and the total number of individuals affected remain unclear, as does a comprehensive official statement from the company.