Data breach at medical billing firm MCBS affects 1.26 million people

A massive data breach at a medical billing firm has left over 1.26 million people’s sensitive information exposed, highlighting the continued vulnerability of healthcare organizations to cyber threats.

Medical Computer Business Services (MCBS), a regional private medical billing and practice-management company based in Augusta, Georgia, disclosed that a network breach occurred between September 22 and 26, 2025. The company processes patient records for healthcare providers as a business associate, making it a critical player in the handling of sensitive healthcare data.

The scope of the breach was only recently revealed when MCBS informed the U.S. Department of Health and Human Services that 1,261,464 people had been impacted. Exposed data includes full name, physical address, Social Security number, date of birth, health plan beneficiary number, medical history, mental and physical condition, diagnosis information, and treatment details. It’s worth noting that the type of exposed data varies per individual.

The breach is attributed to the PEAR (Pure Extraction and Ransom) ransomware group, which claims to have exfiltrated 3.3 terabytes of data from MCBS systems. The attackers also claim to hold human resources data, business operation details, payment information, email correspondence, and various databases. While some of this data has been leaked online, its authenticity cannot be verified.

MCBS is urging potentially affected individuals to take proactive measures to protect their personal information, such as placing a fraud alert on their credit file or considering a security freeze. For those who have received medical services in Georgia, it’s recommended that they contact their healthcare provider to determine if MCBS handled their data and whether their information may be at risk.

The incident serves as a reminder of the importance of robust cybersecurity measures for healthcare organizations. With sensitive patient data being targeted by cyber attackers, it’s essential for these companies to prioritize security and invest in measures such as threat detection and prevention, regular network monitoring, and employee education on cybersecurity best practices.

In light of this breach, individuals should exercise caution when sharing personal information online or over the phone, especially with healthcare providers. It’s also crucial for medical billing firms like MCBS to implement stricter security protocols to prevent similar incidents in the future. By staying vigilant and proactive, we can mitigate the impact of these types of breaches and protect sensitive patient data from falling into the wrong hands.


Source: Bleeping Computer — 2026-07-28