The MCBS data breach has affected 1,261,464 people, according to a new filing with the US Department of Health and Human Services.

Medical Computer Business Services, or MCBS, disclosed the security incident in late June. The medical billing company said attackers accessed its network for several days in September 2025.

MCBS later investigated the breach and completed its review on 28 May 2026. The company found that sensitive personal, insurance and medical information may have been exposed.

Attackers accessed MCBS systems in September 2025

MCBS said unauthorised actors accessed its network between 22 and 26 September 2025.

The company provides billing, coding, accounts receivable, financial and administrative services to healthcare organisations. Based in Augusta, Georgia, it processes patient information on behalf of healthcare providers.

As a result, the MCBS data breach may affect patients who received medical services from one of the providers that used its services.

MCBS listed seven covered entities in its notice. They include South Georgia Radiology Consultants, SkinPath Solutions and Stephen W. Brown and Radiology Associates.

Sensitive health and identity data may be exposed

The data exposed in the MCBS data breach varies by person. However, the company said the affected records may include:

  • Full names and physical addresses
  • Social Security numbers and dates of birth
  • Health plan beneficiary and insurance policy numbers
  • Subscriber identification numbers
  • Medical histories and treatment information
  • Mental and physical health condition details
  • Diagnosis information

The combination of identity, insurance and health information creates a significant risk for affected individuals. Criminals can use this data for identity theft, insurance fraud and targeted phishing attempts.

PEAR ransomware group claims responsibility

The PEAR ransomware group, also known as Pure Extraction and Ransom, has claimed responsibility for the attack.

The group alleges that it stole 3.3TB of data from MCBS systems. It also claims the files include human resources records, payment information, business details, email communications and databases.

The group has published data that it claims came from MCBS online. However, the authenticity and full contents of that material have not been independently verified.

MCBS has not confirmed the group’s claims about the volume or categories of data stolen beyond the information listed in its own breach notice.

What potentially affected patients should do

MCBS advises affected people to place a fraud alert on their credit files. It also recommends considering a security freeze, which restricts access to a credit report and can make it harder for someone to open new accounts in another person’s name.

People who received healthcare services in Georgia should contact their provider to ask whether it works with MCBS and whether their information may be involved.

Anyone who may have been affected should also watch for suspicious insurance statements, medical bills and messages that ask for personal details. Healthcare-related phishing attempts often use real provider names and information from breach notices to look convincing.

The MCBS data breach highlights the exposure created when healthcare providers rely on outside billing and practice-management firms. A compromise at one service provider can put sensitive records from several medical organisations at risk.


0 responses to “MCBS Data Breach Affects 1.26 Million People”