Data Breach Exposes 3.8 Million Patient Records at Unlimited Technology Systems
What Happened — Unlimited Technology Systems (UTS), a revenue‑cycle software provider for specialty health‑care clinics, disclosed that an unauthorized actor accessed a commercial data‑center server from Oct 5‑10 2025. The breach exposed personal and health information for 3,803,750 individuals, including names, SSNs, dates of birth, insurance details, and medical records.
Why It Matters for Compliance & Audit Readiness
- The incident illustrates a failure of SOC 2 Security (CC5) and Privacy (CC6) controls around data‑access monitoring, encryption, and incident‑response documentation.
- Continuous evidence of who accessed PHI, when, and why is essential to demonstrate due‑diligence to auditors and regulators.
- Verisq’s CookiePLUS privacy suite can automate collection of consent, data‑handling logs, and DSAR readiness evidence, turning a reactive breach response into proactive audit proof.
Who Is Affected – Specialty health‑care providers (clinics, physician groups) and their patients across the United States.
Recommended Actions
- Map the breach to SOC 2 CC5/CC6 controls; verify that encryption at rest/in‑transit, least‑privilege access, and logging are enforced.
- Deploy continuous monitoring of data‑center access logs and retain immutable audit trails for the required 12‑month SOC 2 window.
- Conduct a privacy‑impact assessment, update breach‑notification procedures, and integrate automated evidence collection for future audits.
Technical Notes – The breach was discovered via anomalous activity in the commercial data center; no ransomware claim or specific exploit was identified. Exposed data includes full PII and PHI (SSNs, driver’s‑license scans, insurance cards, diagnosis codes, etc.). Source: BleepingComputer