MCBS Healthcare Data Breach Affects 1.26 Million People

A cyberattack on a medical billing company has potentially exposed information belonging to more than 1.26 million people, underscoring that healthcare’s biggest security risks often lie outside the hospital. Medical Computer Business Services (MCBS), a US software vendor for healthcare providers, disclosed that attackers gained unauthorized access to its network between September 22 and 26, […]

Jul 29, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A cyberattack on a medical billing company has potentially exposed information belonging to more than 1.26 million people, underscoring that healthcare’s biggest security risks often lie outside the hospital.

Medical Computer Business Services (MCBS), a US software vendor for healthcare providers, disclosed that attackers gained unauthorized access to its network between September 22 and 26, 2025. 

Although the intrusion was detected during the attack, the company has just begun notifying affected individuals after roughly eight months of investigations that ended in late May.

Public reporting has linked the incident to the PEAR ransomware group, which claimed to have stolen 3.3 TB of data. However, MCBS has confirmed only that unauthorized actors accessed systems and may have acquired files.

How the MCBS breach unfolded

According to BleepingComputer, the company disclosed the incident late last month. But the hack, which it says impacted exactly 1,261,464, dates back to 2025.

MCBS did not provide technical details on how the attackers gained access to its networks or how they successfully accessed and exfiltrated the stolen data. However, the company said that on September 25, 2025, it “experienced unauthorized access” on its network. 

Following that discovery, the company immediately contacted external cybersecurity professionals, contained the incident, and launched an investigation to determine its scope. 

The Pure Extraction And Ransom (PEAR) hacking group claimed responsibility for the breach, and subsequently dumped 3.3 TB of data they say was exfiltrated during the attack. The group highlighted HR, operational, messaging, and business partners’ data among the leaked information.

PEAR claims responsibility for the breach.
PEAR claims responsibility for the breach. Image: BleepingComputer

MCBS concluded its investigation on May 28 and confirmed that data was indeed stolen from its network. The company has not attributed the incident to PEAR or verified the group’s 3.3 TB claim.

Advertisement

Who and what was affected

Because MCBS provides revenue cycle management services — including medical billing, insurance claims processing, and patient account administration — for multiple US healthcare organizations, the breach extended well beyond a single company. 

The Georgia-based company said the information exposed varies by individual but may include names, addresses, dates of birth, Social Security numbers, health plan beneficiary numbers, and health insurance numbers. 

Other information includes medical history, patients’ mental and physical conditions, treatment, and diagnosis.

MCBS also noted that seven partner healthcare organizations were affected. They include:

  • C&C MD PC
  • Nuclear Medicine and Pathology Associates
  • Radiation Oncology Associates, LLP
  • SkinPath Solutions, LLC
  • South Georgia Radiology Consultants PC
  • Stephen W. Brown & Radiology Associates of Augusta, LLP
  • Vascular Radiology Associates II, LLP

The scope of this breach highlights a recurring cybersecurity challenge for healthcare providers: attackers are increasingly targeting third-party vendors that centralize sensitive data from multiple providers, rather than compromising providers individually. That effectively allows a single intrusion to snowball across numerous organizations and affect far more individuals.

Steps for affected individuals and healthcare organizations

With the PEAR ransomware group claiming to have published the stolen data and MCBS confirming that sensitive patient information may have been accessed, affected individuals should remain alert for signs of identity theft, medical fraud, and phishing attempts. 

Individuals should closely monitor activity on financial, insurance, and medical accounts, place a fraud alert or security freeze, and review their credit reports regularly. Even those who have not yet noticed suspicious activity should remain cautious, as stolen data is frequently reused or sold long after the initial breach.

Businesses that employ third-party vendors should inventory vendor access to patient data, apply least privilege and multifactor authentication, monitor unusual data exports, and establish clear breach-notification requirements.

Also read: A CareCloud security incident exposed patient data and disrupted one of the company’s six EHR environments, highlighting the operational risk of healthcare SaaS breaches.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.