MCBS Healthcare Data Breach Affects 1.2 Million People
Atlanta-based Medical Computer Business Services, known as MCBS, provides medical revenue cycle management and billing services. Its notice lists C&C MD PC, Nuclear Medicine and Pathology Associates, Radiation Oncology Associates, SkinPath Solutions, South Georgia Radiology Consultants, Stephen W. Brown and Radiology Associates of Augusta, and Vascular Radiology Associates II as covered entities involved in the notification.
MCBS said it detected unauthorized network activity around September 25, 2025, contained the incident and hired cybersecurity specialists to investigate. The forensic review determined that an unauthorized user may have accessed or removed files between September 22 and September 26. A manual review concluded on May 28, 2026, that the affected files could contain personal information, with the specific data varying by person.
Potentially exposed records included names, addresses, Social Security numbers, dates of birth, health plan beneficiary numbers, insurance policy or subscriber identifiers, other insurance data, medical histories, physical or mental condition information, treatment details and diagnoses, according to the MCBS notice. The HHS Office for Civil Rights lists the event as a hacking or IT incident involving a network server and identifies MCBS as a business associate.
SecurityWeek reported that the PEAR ransomware group claimed responsibility and alleged it stole more than 3 terabytes of company, client, financial, patient and email data. That assertion comes from the ransomware group's leak-site claim; the MCBS notice does not identify an attacker, describe ransomware deployment or confirm the claimed volume. MCBS said it has no evidence of identity theft related to the incident.
MCBS advises affected individuals to review financial statements for fraudulent activity and provides instructions for placing fraud alerts or security freezes and obtaining credit reports. Healthcare organizations connected to the breach should preserve investigation records, verify that notifications reach affected patients and monitor for misuse of exposed identity and medical data, while individuals should treat unexpected messages using health or insurance details with caution.