Desk live·
ForensicPost
Breaches/Third party/File 26-0721b

Patients Learned About an October 2025 Intrusion in July 2026

A revenue cycle vendor most patients have never heard of was breached over five days in October 2025. Notification letters began going out on 21 July 2026 — around 289 days later — carrying social security numbers and scanned identity documents.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUnlimited Systems
ActorUnattributed
D. Kennedy11 min readConfidence: high2 sources reviewed

Unlimited Systems, an Ohio practice management and revenue cycle software vendor, has disclosed a breach affecting at least 442,000 patients. Reporting places unauthorised access to files between 5 and 10 October 2025, with systems in the commercial data centre hosting its platform encrypted.

Notification of affected individuals began on 21 July 2026, with 24 months of identity monitoring offered. Iowa’s filing covers roughly 162,000 residents and South Carolina’s about 148,000. Reported categories include health insurance and balance information, medical record numbers, dates of service, diagnosis details, social security numbers, scanned identification documents and insurance cards.

Two Hundred And Eighty-Nine Days

The gap between the intrusion and the first letter is around nine and a half months. For that period every affected patient was exposed and uninformed, which is the only interval that matters to them.

The corpus files the same gap repeatedly — eleven months at 24-0221 for Change Healthcare, three months at 23-0512b for PharMerica — and argues that notification clocks generally start at a determination the notifying organisation controls, not at the intrusion. A patient cannot freeze credit against a breach nobody has told them about.

Scanned Identity Documents Are The Aggravator

A social security number is a string that can be reissued with difficulty. A photographed passport or driving licence is an image of a document, and it is the thing an identity verification process is designed to accept.

The corpus records the same category at 26-0726 for AssuranceAmerica and 26-0628 for Texas licence holders, and the same asymmetry: the vendor’s remedy is 24 months of monitoring, and the document remains valid for ten years.

Nobody Chose This Vendor

Revenue cycle management is billing. A patient attends a clinic, and the clinic’s billing runs through a company the patient never selected, evaluated or agreed to — the arrangement this desk described at 26-0713 as the support ticket being the breach, and at 25-1219b, where seventeen million patients depended on one supplier most had never heard of.

The affected population here is defined by which clinic someone attended. That is not a market relationship, and the consumer remedies the notification letter offers assume one.

How we reported this

Built on contemporaneous reporting of the notification and of state attorney general filings. The 442,000 figure, the 5–10 October 2025 access window, the encryption of systems in the hosting data centre, the 21 July 2026 notification start, the 24 months of monitoring, the state-level counts and the data categories are as reported from those filings and the company’s notice; this desk has not read the notice itself. The ~289-day interval is this desk’s arithmetic from the reported dates and is stated as such. Reporting notes that full medical records, medical imaging and financial account numbers were not involved; that is recorded. Class action filings referenced in reporting are pleadings and no allegation from them is carried. No actor attribution is made. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management CompanyHIPAA Journal
  2. Ransomware attack at health IT vendor exposes 442,000 patients’ dataBecker’s Hospital Review
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary