Skip to main content
Emerging ThreatsData Breaches

MCBS Data Breach Exposes 1.26 Million People's Sensitive Information

Calm medical office setting with blurred patient records in background.

1,261,464 people — and a threat actor claiming to have taken 3.3 terabytes of data — are at the center of a medical-billing breach disclosed by Medical Computer Business Services (MCBS).

Medical Computer Business Services: who they are and the timeline

MCBS is a regional private medical billing and practice-management company headquartered in Augusta, Georgia, that provides billing, coding, accounts receivable, financial, and administrative services to healthcare organizations. The firm acts as a healthcare data aggregator, processing patient records for healthcare providers.

According to MCBS, threat actors gained unauthorized access to its network between September 22 and 26, 2025. The company conducted an investigation and completed it on May 28 this year. MCBS published a notification on its website in late June and, in a disclosure to the U.S. Department of Health and Human Services (HHS), reported that 1,261,464 people have been impacted.

What the company says was exposed

MCBS’s investigation concluded that a broad range of sensitive patient information “may have been exposed,” with the specific items varying by individual. The company listed the following categories of data as potentially included in the breach:

  • Full name
  • Physical address
  • Social Security number
  • Date of birth
  • Health plan beneficiary number
  • Health insurance policy number
  • Subscriber identification number
  • Medical history
  • Mental and physical condition
  • Medical treatment information
  • Diagnosis information

MCBS notes that the exact data exposed differs from person to person.

Covered entities named and who may want to check

The notification lists seven “covered entities,” meaning healthcare providers whose patient data MCBS handled as a business associate. The disclosure specifically names South Georgia Radiology Consultants, SkinPath Solutions, and Stephen W. Brown and Radiology Associates among those entities. MCBS advises potentially impacted individuals to place a fraud alert and to consider placing a security freeze on their credit file.

MCBS also directs individuals who have received medical services in Georgia to contact their healthcare provider to determine whether that provider works with MCBS and whether their personal information may have been affected.

PEAR (Pure Extraction and Ransom) claims and the leaked cache

The attack has been claimed by the PEAR (Pure Extraction and Ransom) ransomware group, which alleges it exfiltrated 3.3 terabytes of data from MCBS systems. Beyond the client patient data MCBS highlighted in its announcement, the threat actor also claims to hold human resources data, business operation details, payment information, email correspondence, and various databases.

According to the reporting, the data has been fully leaked online. BleepingComputer reported that it did not examine the posted cache and therefore could not validate the authenticity of the material claimed by the actor.

What this means for patients in Georgia, healthcare providers, and security teams

  • Patients in Georgia: MCBS’s guidance is explicit — individuals who received care in Georgia should contact their provider to learn whether that provider uses MCBS and whether their records could be involved. The company also urges a fraud alert and consideration of a credit freeze.
  • Healthcare providers named as covered entities: Those providers will need to assess whether their patient records were part of the MCBS business-associate relationship and, if so, how to notify affected patients and coordinate remediation with MCBS and regulators.
  • Security teams and incident responders: The timeline — intrusion in September 2025, an investigation concluding May 28 of this year, a public notice in late June, and the HHS disclosure of 1,261,464 impacted individuals — will factor into forensic reviews, breach reporting obligations, and any follow-on remediation or litigation planning.

MCBS’s public disclosures establish the contours of a large patient-data incident: the company’s role as a processor of provider records, a multi-day intrusion in September 2025, an investigation that ran into May, and a final HHS notification tallying 1,261,464 affected people. The PEAR group’s claim of 3.3 terabytes taken and the online leak raise further questions about the nature and extent of exposed corporate and personnel records, but the posted cache’s authenticity has not been independently validated.

Read the original report: https://www.bleepingcomputer.com/news/security/data-breach-at-medical-billing-firm-mcbs-affects-126-million-people/