Medical Computer Business Services (MCBS) has confirmed that a 2025 network intrusion exposed sensitive personal and medical information belonging to 1,261,464 people.
The scale of the breach was disclosed in a filing with the U.S. Department of Health and Human Services, which classifies MCBS as a healthcare business associate and the incident as a hacking or information technology event involving a network server.
MCBS provides medical billing and administrative services to healthcare organizations, placing it in possession of patient information supplied by multiple providers. The breach therefore extends beyond the company itself and potentially affects patients whose healthcare providers used MCBS for billing and related services.
Attackers accessed the network for several days
In an official data breach notice, MCBS said it detected unauthorized network activity on or around September 25, 2025. The company contained the intrusion and brought in external cybersecurity specialists to investigate.
The forensic review determined that an unauthorized party may have accessed or removed files from the MCBS network between September 22 and September 26, 2025.
MCBS then conducted a manual review of the potentially affected files. That process concluded on May 28, 2026, approximately 8 months after the intrusion occurred.
The company has not disclosed how the attacker entered its network, which systems were compromised, or whether credentials, vulnerabilities, or another initial access method contributed to the incident.
Social Security numbers and medical records involved
The exposed information varies by individual, but MCBS said affected files may have contained:
- Names and physical addresses
- Social Security numbers
- Dates of birth
- Health plan beneficiary numbers
- Health insurance policy and subscriber identification numbers
- Other health insurance information
- Medical histories
- Diagnosis and treatment information
- Mental or physical condition information
The combination of identity, insurance, and medical data creates risks extending beyond conventional payment card fraud. Criminals may use the information for identity theft, fraudulent insurance claims, medical identity theft, targeted phishing, or attempts to impersonate patients and healthcare providers.
MCBS said it had found no evidence of identity theft connected to the incident at the time its notice was published. The absence of detected misuse does not establish that the exposed information has not been distributed or retained by unauthorized parties.
Healthcare providers named in notification
The MCBS notice identifies 7 covered healthcare entities associated with the affected information:
- C&C MD PC
- Nuclear Medicine and Pathology Associates
- Radiation Oncology Associates, LLP
- SkinPath Solutions, LLC
- South Georgia Radiology Consultants PC
- Stephen W. Brown & Radiology Associates of Augusta, LLP
- Vascular Radiology Associates II, LLP
As a business associate, MCBS processes information for healthcare providers rather than collecting all affected patient data through a direct relationship. Some individuals may therefore recognize the name of their medical provider but have no previous awareness that MCBS handled their information.
PEAR alleges 3.3 TB data theft
The PEAR extortion group has claimed responsibility for the attack, alleging that it removed approximately 3.3 TB of data from MCBS systems.
PEAR also claims the stolen material includes human resources records, payment information, email correspondence, operational documents, databases, and information belonging to MCBS clients.
MCBS has confirmed that files may have been accessed or removed, but it has not publicly attributed the intrusion to PEAR or confirmed the group’s claims about the volume and full contents of the allegedly stolen data.
MCBS recommends fraud alerts and credit freezes
MCBS is advising affected individuals to monitor their financial account statements and credit reports for suspicious activity. The company recommends considering a one-year fraud alert or a security freeze with the major credit reporting agencies.
A fraud alert instructs lenders to take additional steps to verify an applicant’s identity before opening credit, while a security freeze generally prevents access to a consumer’s credit file until the freeze is lifted.
Given the involvement of Social Security numbers and dates of birth, affected individuals should remain alert for identity-related fraud over the long term. Medical and insurance information can also support convincing scams that reference real providers, diagnoses, or treatment details.











