MCBS medical billing breach exposes 1.26 million patients (PEAR extortion)
Medical Computer Business Services (MCBS), a Georgia billing and software vendor for healthcare providers, disclosed that a September 2025 network intrusion exposed Social Security numbers and medical information of 1,261,464 people.
- Victim
- Medical Computer Business Services (MCBS)
- users
- 1.3M
In late July 2026, Medical Computer Business Services (MCBS), a Georgia-based billing and software vendor for healthcare providers, began notifying 1,261,464 people that their personal and medical information had been exposed in a network intrusion that took place between 22 and 26 September 2025. The company finished its investigation on 28 May 2026, meaning patients learned of the breach roughly ten months after it happened.
The data-extortion group PEAR (Pure Extraction And Ransom) claimed the attack and said it stole about 3.3 TB of data. PEAR does not encrypt systems; it steals data and demands payment. Reporting indicated the ransom was not paid and that the group published the stolen data on its leak site. MCBS did not independently confirm the group's claims.
What was exposed
According to the notification, the affected information may include names, addresses, dates of birth, Social Security numbers, health plan beneficiary numbers, health insurance policy or subscriber numbers, and medical history, diagnosis and treatment information. Because MCBS processes billing for client practices, patients of several partner healthcare organizations, including radiology and oncology practices, were swept into the breach.
Why it matters
Revenue-cycle and billing vendors aggregate data from many providers, so one intrusion at a small supplier can expose more than a million patients who never dealt with it directly. The long delay between the intrusion and notification, and the publication of the data in the meantime, left affected people exposed to fraud for months before they were warned.
Timeline
Attackers gain unauthorized access to the MCBS network; the intrusion lasts until 26 September.
MCBS completes its investigation into the affected data.
The breach becomes public as MCBS begins notifying 1,261,464 affected individuals.
Sources
- esecurityplanet.comhttps://www.esecurityplanet.com/threats/news-mcbs-healthcare-data-breach/
- hipaaguide.nethttps://www.hipaaguide.net/mcbs-data-breach/
- beckershospitalreview.comhttps://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/rcm-vendor-data-breach-affects-1-2-million-patients/