The Envelope Says 'Kroll.' The Break-In It Is About Was Discovered 274 Days Earlier.
Roughly 428,000 people in just three states are receiving letters from a company they have never heard of, about intruders found on October 19, 2025. Here is who Unlimited Systems is, why the letter is real, and why there is nothing to claim.
By Settlement Insight Data Desk ·
Why a company you never used has your medical file
Unlimited Technology Systems LLC — trading as Unlimited Systems, based in Montgomery, Ohio — sells practice-management and revenue-cycle software to healthcare providers, heavily in oncology and specialty practice. Patients never sign anything with them. The provider does, and the patient data flows through as a matter of billing.
That is why the letter arrives from an unfamiliar name, and why so many people are searching for the words on the envelope: Kroll is not the company that was breached. Kroll is the identity-monitoring vendor Unlimited hired to run the response, which is why the return address and enrollment materials carry its name.
The letter is real. What is not real: anyone phoning to ask for your Social Security number to verify enrollment, and anyone offering a claim form or a payout. Neither exists in this incident.
The 274-day gap
The official notices lay out a timeline that is unusual on its face. Unauthorized access occurred October 5–10, 2025. Unlimited discovered the intrusion on October 19, 2025. One affected provider's official patient notice states that Unlimited informed it on or around July 20, 2026 — 274 days after discovery.
Regulator filings landed in the same stretch: the Iowa Attorney General on July 1, 2026, and the Vermont Attorney General and South Carolina Department of Consumer Affairs on July 21, 2026.
For context, HIPAA's Breach Notification Rule generally requires notification without unreasonable delay and no later than 60 days from discovery, with a business associate required to notify the covered entity on that clock. Whether this timeline actually breached that standard is a question for regulators and the courts — not for us to declare. But it is the specific fact the investigating law firms are pointing at, and it is the reason a fourteen-month-old break-in is landing in mailboxes now.
How many people? Nobody has said.
No national total has been disclosed, and at the time of writing the incident had not appeared on the HHS Office for Civil Rights breach portal — the federal registry where the authoritative count normally shows up.
State-level filings give only partial counts: 277,364 Texas residents, 148,342 South Carolina residents, and 2,223 Massachusetts residents. That is roughly 428,000 people across just three states, with dozens unaccounted for.
The exposed data, per the notices: names, health insurance information, medical record numbers, dates of service, diagnosis information, scanned identification documents, Social Security numbers and demographic data. The notices state that complete medical records, imaging files and financial account information were not involved.
The scanned IDs are the standout. A photographed driver's license or insurance card is reusable in a way a leaked email address never is — it survives a password change, and it is exactly what is needed to open accounts or obtain care in someone else's name.
No settlement. No fund. No claim form.
At least four firms — among them Edelson Lechtzin LLP, Shamis & Gentile P.A. and Migliaccio & Rathod LLP — have announced investigations into potential class claims. An investigation is not a lawsuit, and a lawsuit is not a settlement. As of publication there is no settlement, no fund, no administrator and no claim deadline.
What does exist is the free offer: two years of Kroll identity monitoring, covering single-bureau credit monitoring, fraud consultation and identity-theft restoration, enrolled through the number printed on the letter, (844) 576-3063. Enrolling does not waive your right to join a future case.
And the step that outperforms the free monitoring: a credit freeze at all three bureaus, which costs nothing and blocks new-account fraud rather than reporting it afterward. Given that scanned IDs and SSNs were involved, that is the proportionate response here.
The Data Behind This Story
- Unauthorized access
- October 5–10, 2025
- Discovered
- October 19, 2025
- Provider notified (documented)
- ~July 20, 2026
- Gap, discovery to that notice
- 274 days
- Counted across 3 states
- ~427,929
- National total disclosed
- None
- Settlement fund
- None — no settlement exists
- Free monitoring
- 2 years via Kroll
- Source: Unlimited Systems service-provider breach notices published by affected healthcare providers, July 2026
- Source: Breach filings with the Iowa Attorney General (July 1, 2026), Vermont Attorney General and South Carolina Department of Consumer Affairs (July 21, 2026)
- Source: State-level affected counts from attorney general filings: Texas (277,364), South Carolina (148,342), Massachusetts (2,223)
- Source: U.S. HHS Office for Civil Rights breach portal (no entry at time of writing)
- Source: Settlement Insight tracker: settlementinsight.com/unlimited-technology-systems-data-breach
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.