Unlimited Technology Systems, a provider of practice management software to healthcare organizations, disclosed a data breach that likely occurred between October 5 and October 10, 2025. The company detected unusual activity on October 19, 2025. Notifications to affected individuals began around June 20, 2026, with a sample notice submitted to the Iowa Attorney General on July 1, 2026. The compromised data types include Social Security Numbers, dates of birth, addresses, phone numbers, email addresses, demographic information, medical record numbers, government IDs, names, dates of service, driver’s licenses, insurance policy numbers, diagnoses, insurance claims and benefits, insurance cards, and intake forms. However, full medical records, medical imaging, credit card numbers, and bank account numbers were explicitly excluded. The exact number of affected individuals has not been publicly disclosed. This incident is identified as a vendor breach, as Unlimited Technology Systems acts as a third-party service provider for healthcare clients. While notifications have been sent, further details regarding the full scope of the breach and any additional impacts may emerge.