Medical Computer Business Services (MCBS), a medical billing and revenue cycle management firm serving physician practices in Georgia, has disclosed a September 2025 network intrusion that exposed personal and health data belonging to roughly 1.26 million people. Counts vary by outlet: HHS Office for Civil Rights records cited by SecurityWeek, Becker's, HIPAA Journal and BreachNews give the precise figure 1,261,464, SecurityWeek's headline rounds to "more than 1.2 million," and Health Exec rounds up to 1.3 million. There is no evidence of separate incidents behind those numbers; they are the same filing rounded differently. The PEAR group claimed the attack, said it took multiple terabytes of files, and published the data on its leak site after the ransom went unpaid. Note that no victim statement, regulator document or CERT advisory is in the source set directly; every account of the breach notice and the OCR filing here is secondhand.
What Happened
MCBS detected unauthorized activity on its network on or about September 25, 2025, contained it, and engaged outside forensics. The company later determined the intruder had access for several days before detection. Sources differ slightly on the end of that window: HIPAA Journal reports access between September 22 and September 25, 2025, while SecurityWeek, Becker's, BreachNews and Rescana all place the window at September 22 to September 26. The one-day discrepancy likely reflects different readings of the same notice, but it is worth flagging because it bears on whether exfiltration continued past detection.
The forensic and manual document review did not conclude until May 28, 2026, roughly eight months after the intrusion. Rescana reports the OCR filing was submitted June 26, 2026, with a public notice posted in late June. Becker's notes that the late-June notice did not include a total affected figure, which only surfaced through the HHS breach portal. That is a nine to ten month gap between compromise and the public learning its scale.
Sources also disagree on where the company is based. HIPAA Journal and Rescana place MCBS in Augusta, Georgia, consistent with the Augusta-area clinics named in the notice; SecurityWeek describes it as Atlanta-based.
Seven HIPAA covered entities had patient data in the compromised environment. HIPAA Journal lists them as C&C MD PC, Nuclear Medicine and Pathology Associates, Radiation Oncology Associates LLP, SkinPath Solutions LLC, South Georgia Radiology Consultants PC, Stephen W. Brown & Radiology Associates of Augusta LLP, and Vascular Radiology Associates II LLP. None of these practices was breached directly. Their patients were exposed because the practices outsourced billing.
What Was Taken
The exposed data set is unusually complete for a healthcare breach, combining identity, financial and clinical elements in one record. Per the breach notice as reported by HIPAA Journal, Becker's and BreachNews, affected files may have contained names, physical addresses, dates of birth, Social Security numbers, health plan beneficiary numbers, health insurance policy and subscriber identification numbers, medical histories, diagnosis information, treatment information, and mental and physical condition details. The specific fields vary per individual.
On volume, accounts differ. HIPAA Journal, SecurityWeek and Daily Security Review report PEAR's claim of more than 3 TB. Becker's and Rescana report 3.3 TB. Becker's attributes the figure to press reporting rather than to MCBS, and notes MCBS has not addressed the claim at all in its public notice.
SecurityWeek's description of what PEAR says it took goes well beyond patient records: company and client financials, HR and business operations documents, partner and vendor data, patient PII and PHI, payment details, and email. If accurate, the downstream exposure includes the seven client practices' own business data, not just their patient lists. SecurityWeek reports the stolen data has been made available for download.
Why It Matters
This is a business associate breach, and the structure is the story. One intrusion at a billing intermediary produced 1.26 million notifications across seven separate provider organizations, none of which was itself attacked. Daily Security Review makes the point directly: RCM and practice management firms aggregate records from many downstream clients into a single concentrated repository, which multiplies the return on one compromise. Becker's places the incident in a continuing pattern of large breaches tied to third-party billing and revenue cycle vendors.
The eight-month review and ten-month disclosure lag matter operationally. Patients had SSNs and clinical histories circulating for the better part of a year before anyone told them to watch their accounts. MCBS says it has no evidence of identity theft tied to the incident, but with the data already published on a leak site, absence of evidence at notification time is weak reassurance.
PEAR itself is worth tracking. It surfaced in mid-2025 and its leak site now lists over 100 alleged victims, with what Daily Security Review characterizes as a documented healthcare focus. SecurityWeek attributes two other healthcare-adjacent incidents to the group: Motility Software Solutions (766,000 affected) and Tri-Century Eye Care (200,000).
The Attack Technique
Initial access is unknown. BreachNews states plainly that MCBS has not disclosed how the attacker entered the network, which systems were touched, or whether credentials, an exploited vulnerability or another vector was involved. Rescana reports that no attack-specific indicators of compromise had been published as of July 2026, which it says limits high-confidence technical attribution.
One characterization does conflict across sources, and it is the most defensively significant detail in the set. HIPAA Journal states that PEAR, which stands for Pure Extortion and Ransom, engages in data theft and extortion and does not deploy encryption at all. Daily Security Review, SecurityWeek and Rescana refer to it as a ransomware group, and the original Health Exec framing calls the incident a ransomware attack. HIPAA Journal's account is the more specific and internally consistent one, and it fits the observed outcome: exfiltration, ransom demand, publication on failure to pay, with no reporting anywhere in the source set of encrypted systems or service disruption at MCBS. Treat "ransomware" here as a label of convenience. The operational reality described is exfiltration-only extortion.
That distinction changes defensive priorities. Backups and recovery time objectives do not help against an actor whose entire leverage is publication.
What Organizations Should Do
- Inventory your business associates and what they actually hold. If a billing, coding or RCM vendor has your patient SSNs, insurance identifiers and diagnosis data, your breach exposure is their security posture. Map which vendors hold which field types, not just which vendors exist.
- Instrument for egress, not just encryption. An exfiltration-only actor never trips ransomware canaries. Alert on bulk reads from billing and claims databases, on unusual outbound volume to cloud storage and file transfer services, and on archive creation at scale. A multi-terabyte transfer over several days should be detectable.
- Set contractual detection and notification floors. Push business associate agreements to require notification within days of detection, not months, and to require the vendor to share intrusion window, affected data categories and preliminary counts before its own review concludes. Ten months is what the current baseline produces.
- Reduce dwell-time-to-value in the aggregated data store. Purge records past retention, tokenize or segregate SSNs from clinical data, and separate the environments serving different covered entities so one compromise does not yield seven client data sets.
- Hunt for PEAR-consistent activity if you use a shared RCM platform. With no published IOCs, focus on behaviour: new remote access tooling, credential reuse across client tenants, and staged archives on file servers.
- Run a leak-site exposure check. PEAR has published the data. Downstream practices named in the notice, and any organization sharing a vendor, should assume the records are in circulation and move to credit monitoring and identity fraud watch rather than waiting for confirmed misuse.
Sources: Ransomware attack on medical billing company results in data on 1.3... | Data breach at medical billing firm MCBS affects 1.26 million people | MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals | MCBS Data Breach Affects 1.2 Million Individuals - SecurityWeek | RCM vendor data breach affects 1.2 million patients | MCBS Data Breach Affects 1.26 Million People | PEAR Ransomware Breach at MCBS Hits 1.26 Million Patients - Ransomware | MCBS Medical Billing Data Breach 2026: 1.26 Million Patients Expose...