Unlimited Technology Systems Data Breach: There Is No Settlement Yet
Notices went out in late July 2026 about a breach discovered in October 2025. If you received the letter marked "Return to Kroll," it is real. Here is what is verified and what to do.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What the Lawsuit Alleges
Unlimited Technology Systems, LLC of Cincinnati, Ohio provides practice-management and revenue-cycle software to specialty medical practices, including several cancer centers. Because it handles patient data on behalf of healthcare providers, it is a HIPAA business associate. Between October 5 and 10, 2025, an unauthorized party accessed systems in its commercial data center; the company discovered this on October 19, 2025. Trade press has described the incident as ransomware that encrypted systems hosting its patient platform, though the official notice letters use only the phrase "unauthorized activity," and no ransomware group has publicly claimed responsibility. Notices to affected individuals began roughly nine months after discovery, in late July 2026, and that delay is the central allegation in the lawsuits now being filed. Note that an unrelated company with a similar name, Unlimited Technology, Inc. of Pennsylvania, a physical-security integrator, has nothing to do with this incident.
Case Details
U.S. District Court, Southern District of Ohio — Matlock v. Unlimited Technology Systems, LLC, No. 1:26-cv-00729, filed July 24, 2026 before Judge Matthew W. McFarland. A motion to consolidate related cases and appoint interim class counsel was filed July 26, 2026.
Current Status
Who Is Affected & Can You Join?
Affected individuals are patients of medical practices that used Unlimited's software. Confirmed providers include Mary Bird Perkins Cancer Center in Louisiana, Astera Cancer Care in New Jersey, and West Cancer Center. No total number of affected people has been published. Individual state filings confirm at least 277,364 in Texas, 162,478 in Iowa, 148,342 in South Carolina, 2,223 in Massachusetts and roughly 286 in Vermont, already more than 590,000 across those five states alone and well above the "442,000" figure repeated in some coverage, which is an earlier partial sum. California also received a filing with no published count. According to the notice letters, exposed data varies by person and may include name, date of birth, address, Social Security number, health-insurance and patient-balance information, medical information such as record number, treatment date and diagnosis, and scanned documents including driver's licenses and insurance cards. Unlimited states that complete medical records, medical imaging, and credit-card or bank-account details were not involved.
Is There a Payout?
Case Timeline
- 1
October 5–10, 2025 — Unauthorized access
An unauthorized party accessed systems in Unlimited's commercial data center over a six-day window, according to the company's official notice filed with state attorneys general.
- 2
October 19, 2025 — Discovery
Unlimited discovered the unauthorized activity and began an investigation. Trade press later described the incident as ransomware affecting the data center hosting its patient platform.
- 3
May 20, 2026 — Provider notified
Unlimited informed at least one affected practice, West Cancer Center, about the incident: seven months after discovery and two months before patients were told.
- 4
July 21, 2026 — Regulators notified
Counsel for Unlimited filed breach notices with state attorneys general, including Iowa (162,478 residents), alongside filings in Texas, South Carolina, Massachusetts, Vermont and California.
- 5
July 20–21, 2026 onward — Letters mailed
Individual notice letters began going out on a rolling basis with 24 months of Kroll monitoring. Practices without a mailing address for some patients published substitute notices on their own websites.
- 6
July 22–26, 2026 — First lawsuits
Proposed class actions were filed in the Southern District of Ohio, followed by a motion to consolidate them and appoint interim class counsel. No settlement exists.
Scam & Misinformation Warnings
Whenever a brand lawsuit goes viral, scam sites and bad actors follow. Watch for these red flags:
"Return to Kroll" is not a scam
That line appears as the return address on the genuine notice letter, because Kroll handles the mailing and enrollment on Unlimited's behalf. Seeing an unfamiliar company name on a letter about your medical data is unsettling, but this one checks out against the notice filed with state attorneys general.
Anyone offering a claim form or payout
No settlement exists, so no legitimate claim form exists either. Sites promising "up to $X,000" for this breach are collecting your information for lead generation, not processing claims.
Callers asking to verify your SSN
Neither Unlimited nor Kroll will call to ask for your Social Security number, and enrollment never requires payment. If someone calls citing this breach and asks for personal data, hang up and call the official hotline at (844) 576-3063 yourself.
Frequently Asked Questions
Is there a settlement for the Unlimited Technology Systems data breach?
No. As of July 30, 2026 there is no settlement, no certified class, no claim form and no payout. The first lawsuits were filed on July 22 and 24, 2026, and a motion to consolidate them is pending. Comparable healthcare breach class actions typically take 12 to 30 months before any settlement is reached, if one is reached at all.
I got a letter that says "Return to Kroll" — is it real?
Yes. Kroll is the firm handling notification and identity-monitoring enrollment for Unlimited, and "Return to Kroll" is the return address printed on the genuine letters. The same letter text appears in the breach notice Unlimited's counsel filed with state attorneys general in July 2026.
What should I do right now?
Enroll in the free 24-month Kroll monitoring using the activation code and verification ID on your letter at Enroll.krollmonitoring.com/redeem, and check your own letter for your personal activation deadline, which differs per recipient. Then consider freezing your credit with all three bureaus, which is free and stronger than monitoring alone. Because Social Security numbers and medical information may be involved, also review Explanation of Benefits statements from your insurer for care you did not receive.
How many people were affected by the Unlimited Systems breach?
No official total has been published. State filings confirm at least 277,364 in Texas, 162,478 in Iowa, 148,342 in South Carolina, 2,223 in Massachusetts and about 286 in Vermont, more than 590,000 across those five states alone, plus a California filing with no published count. The 442,000 figure in some coverage is an earlier partial sum and is out of date.
Why did it take nine months to tell me?
That gap, discovery on October 19, 2025 and notices in late July 2026, is the central allegation in the lawsuits now pending. Unlimited has not publicly explained the timeline beyond describing an ongoing investigation and data review.
Should I join a lawsuit?
That is a decision for you and, if you want one, an attorney. In a class action you are generally included automatically if a class is certified, without signing up in advance. Nothing requires you to hire anyone today to preserve your rights, and enrolling in the free monitoring does not waive them.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.