Data Breach at Medical Billing Firm Affects 1.26 Million Patients
A cyberattack on the healthcare billing company Medical Computer Business Services (MCBS) has resulted in the exposure of the protected health information of 1.26 million individuals. MCBS is a private medical billing and practice management company that provides billing, coding, accounts receivable, financial, and administrative services to healthcare providers.
The cyberattack was identified on or around September 25, 2025. The forensic investigation confirmed that the attackers had access to its computer systems between September 22 and September 26, 2025, and exfiltrated files containing the data of patients of its healthcare clients.
MCBS said C&C MD PC, Nuclear Medicine and Pathology Associates, Radiation Oncology Associates, LLP, SkinPath Solutions, LLC, South Georgia Radiology Consultants PC, Stephen W. Brown & Radiology Associates of Augusta, LLP, and Vascular Radiology Associates II, LLP were affected and had patient data stolen in the attack. The Department of Health and Human Services’ Office for Civil Rights data breach portal states that 1,261,464 individuals had their protected health information compromised or exposed in the incident.
The compromised data has been reviewed and was found to include names, addresses, Social Security numbers, dates of birth, health plan beneficiary numbers, health insurance policy numbers/ subscriber identification numbers, other health insurance information, medical histories, condition information, and medical diagnosis and treatment information.
While data was stolen, MCBS said it is unaware of any actual or attempted identity theft as a result of the incident, although the affected individuals have been advised to remain vigilant against identity theft and fraud. The PEAR threat group claimed responsibility for the attack and issued a ransom demand that was not paid. The group proceeded to leak the 3.3 terabytes of stolen data in full on its dark web data leak site. PEAR is a data theft and extortion group that does not encrypt files using ransomware. The group attacks many sectors, and its data leak site includes many healthcare providers.