Data breach at medical billing firm MCBS affects 1.26 million people

A massive data breach at a medical billing firm has exposed sensitive information for over 1.26 million people, highlighting the ongoing risks to patient confidentiality in the healthcare sector.

Medical Computer Business Services (MCBS), a regional private medical billing and practice-management company based in Augusta, Georgia, disclosed that its network was breached by threat actors between September 22 and 26, 2025. The breach allowed unauthorized access to MCBS’s systems, where sensitive data on patients was stored and processed for healthcare providers.

The affected individuals’ information may have included their full name, physical address, Social Security number, date of birth, health plan beneficiary number, health insurance policy number, subscriber identification number, medical history, mental and physical condition, medical treatment information, and diagnosis information. It’s worth noting that the extent of exposed data varies per individual.

MCBS is a healthcare data aggregator, processing patient records for multiple healthcare organizations in its network. The company has identified seven “covered entities” whose patient data it handled as a business associate, including South Georgia Radiology Consultants, SkinPath Solutions, and Stephen W. Brown and Radiology Associates. Individuals who have received medical services in Georgia are advised to contact their healthcare provider to determine whether they work with MCBS and if their personal information may have been affected by the breach.

The PEAR (Pure Extraction and Ransom) ransomware group has claimed responsibility for the attack, alleging that it exfiltrated 3.3 terabytes of data from MCBS systems. In addition to client data highlighted in the announcement, the threat actor claims to hold human resources data, business operation details, payment information, email correspondence, and various databases.

What’s particularly concerning about this breach is the amount of sensitive patient data that was stolen and potentially leaked online. While BleepingComputer has not verified the authenticity of the leaked cache, it’s clear that a significant amount of personal and medical information is at risk of being exploited by cybercriminals or sold on dark web markets.

As a result, MCBS urges affected individuals to take proactive steps to protect their credit and identity, including placing a fraud alert and considering a security freeze on their credit file. It’s also essential for healthcare providers and business associates to review their data handling practices and ensure that they have robust cybersecurity measures in place to prevent similar breaches from occurring in the future.

For individuals who may be impacted by this breach, it’s crucial to remain vigilant and monitor their financial accounts closely for any suspicious activity. Regularly reviewing credit reports, taking advantage of free credit monitoring services, and being cautious when receiving unsolicited emails or phone calls can also help mitigate potential harm. As we continue to navigate the complex landscape of healthcare data breaches, one thing is clear: individuals must be proactive in protecting their sensitive information from falling into the wrong hands.


Source: Bleeping Computer — 2026-07-28