Ransomware at Ohio vendor triggers notices for 442,000 patients

A ransomware attack on revenue cycle vendor Unlimited Technology Systems put 442,000 patients on notice across six states.

MedRisk Staff
By
2 Min Read

Unlimited Technology Systems, a practice management and revenue cycle software vendor based in Montgomery, Ohio, has confirmed that a ransomware attack exposed the personal and medical information of at least 442,000 patients whose providers use its hosted platform.

The company said unauthorized actors accessed files between October 5 and October 10, 2025, encrypting systems within the commercial datacenter that hosts its g4-Centricity for Vector platform. The breach triggered a forensic investigation and notifications that began July 21, 2026.

Exposed data varied by individual and may include health insurance and patient balance information, medical record numbers, dates of service, diagnosis details, Social Security numbers, and scanned identification documents and insurance cards. The vendor said the incident did not involve full patient medical records, medical imaging, or credit card and bank account numbers, and that it has no evidence the data has been misused.

The impact spans multiple states. Iowa’s attorney general filing alone covers roughly 162,000 residents, while South Carolina lists about 148,000; residents of California, Massachusetts, Texas and Vermont are also affected. The company is offering 24 months of free identity monitoring.

The case illustrates how a single vendor incident ripples across patients of dozens of unrelated provider organizations. As a third-party software vendor serving specialty practices nationwide, Unlimited Systems holds data on patients who may never have interacted with the company directly.

For hospitals and physician practices that outsource revenue cycle operations, the episode is a reminder to inventory downstream vendors, review their incident response and notification obligations, and pressure-test whether hosted platforms meet their own security requirements.

Share This Article