Medical Computer Business Services (MCBS), a Georgia-based medical billing and revenue cycle management firm, has confirmed that attackers accessed its network in September 2025 and made off with protected health information belonging to 1,261,464 people. The figure comes from MCBS's own filing with the U.S. Department of Health and Human Services Office for Civil Rights, and is reported consistently by BleepingComputer, HIPAA Journal, SecurityWeek and BreachNews. Headline rounding varies: most outlets say 1.26 million, SecurityWeek says "more than 1.2 million," and HealthExec's headline says 1.3 million, though its body text cites the same 1,261,464 OCR figure. The extortion group PEAR claimed responsibility, and multiple outlets report the stolen data was published on PEAR's leak site after no ransom was paid. MCBS itself has not named the threat actor.
What Happened
MCBS detected unauthorized activity on its network on or around September 25, 2025, contained the intrusion, and engaged outside forensic specialists. The company's own notice, published to its website in late June 2026, described the intrusion window but withheld the victim count until the OCR filing followed.
Accounts differ slightly on the intrusion window. BleepingComputer, SecurityWeek, HealthExec and HotHardware all report unauthorized access between September 22 and September 26, 2025. HIPAA Journal reports the confirmed access window as September 22 to September 25. The four-day September 22 to 26 span is the more widely reported figure and matches MCBS's own public notice as quoted by HealthExec.
The forensic file review took roughly eight months, concluding on May 28, 2026. Public disclosure came in late June 2026, with the full impact number surfacing through the HHS breach tracker in late July, nearly ten months after the intrusion. That lag between compromise and patient notification is one of the more consequential facts in this incident.
There is also a minor discrepancy on the company's location. BleepingComputer, HIPAA Journal and HotHardware place MCBS in Augusta, Georgia; SecurityWeek describes it as Atlanta-based. Augusta is the better-sourced figure, appearing in three independent reports including the two closest to the company's own notice.
MCBS operates as a HIPAA business associate rather than a covered entity. Its notice names seven affected covered entities. HIPAA Journal lists all seven: C&C MD PC, Nuclear Medicine and Pathology Associates, Radiation Oncology Associates LLP, SkinPath Solutions LLC, South Georgia Radiology Consultants PC, Stephen W. Brown & Radiology Associates of Augusta LLP, and Vascular Radiology Associates II LLP. Note the concentration: four of the seven are radiology, nuclear medicine, or radiation oncology practices.
What Was Taken
MCBS confirmed that files potentially accessed or exfiltrated may have contained, varying by individual:
- Full name and physical address
- Social Security number
- Date of birth
- Health plan beneficiary number
- Health insurance policy and subscriber identification numbers
- Medical history
- Mental and physical condition information
- Medical treatment and diagnosis information
This is the full identity-theft package layered on top of clinical detail. Social Security numbers plus dates of birth support synthetic identity fraud indefinitely; diagnosis and treatment records support targeted extortion and medical fraud that no credit freeze addresses.
PEAR's claims go further than MCBS's notice. SecurityWeek and HIPAA Journal report PEAR claimed more than 3 TB of exfiltrated files; HotHardware reports the group claimed 3.3 TB. Both figures are the attacker's own claim and remain unverified by MCBS. PEAR's inventory, per SecurityWeek, allegedly includes company and client financials, HR and business operations documents, partner and vendor data, patient PII and PHI, payment details, and email correspondence.
MCBS has not confirmed that files were moved offsite, stating only that data may have been "accessed or removed." HealthExec notes that BleepingComputer independently observed the leaked trove on the dark web, complete with a screenshot, and that the data was posted for open download, which typically indicates the ransom went unpaid.
Why It Matters
One compromised billing vendor produced patient exposure across seven separate provider organizations. The attackers did not need to defeat seven sets of perimeter defenses. This is the recurring structural weakness in healthcare: business associates aggregate data from many covered entities while frequently operating with a fraction of a hospital system's security budget and monitoring maturity. Biopharma Curated frames this as an "upstream" targeting strategy against centralized service hubs, though that characterization is the outlet's own analysis rather than a finding from MCBS or any investigator.
The threat actor label also deserves scrutiny. PEAR is widely described as a ransomware group, but HIPAA Journal reports that PEAR conducts data theft and extortion without deploying file-encrypting ransomware at all. Sources also disagree on what the acronym stands for: HIPAA Journal renders it "Pure Extortion and Ransom," while HealthExec and HotHardware render it "Pure Extraction and Ransom." Either way, encryption-free extortion means the detection signals defenders traditionally rely on, mass file encryption and ransom notes on endpoints, never fire. Detection has to come from data movement, not data destruction.
PEAR is not a one-off. SecurityWeek reports the group emerged in mid-2025 and its leak site now lists more than 100 alleged victims, including Motility Software Solutions (766,000 people) and Tri-Century Eye Care (200,000 people). This is a high-tempo operation with demonstrated appetite for healthcare and healthcare-adjacent service providers.
The Attack Technique
MCBS has not disclosed the initial access vector. BreachNews states plainly that the company has not said how the attacker entered the network, which systems were compromised, or whether credentials, a vulnerability, or another method was involved. No source in this set establishes the entry point. Treat any claim otherwise as speculation.
What is known operationally: dwell time of roughly four days from earliest confirmed access to detection, containment on or around September 25, and exfiltration at a scale PEAR puts in the multi-terabyte range. Moving 3 TB out of a billing network in under a week is a volume of egress that network flow monitoring should be able to catch.
One piece of adjacent context is worth flagging carefully, because it is not connected to this incident by any source. CVE-2026-58126, published to the NVD on July 1, 2026, is an unauthenticated remote code execution flaw in PACSgear PACS Scan 5.2.1. A legacy .NET Remoting service on TCP port 22222, hosted by PGImageExchQueue.exe, exposes arbitrary file read and write primitives with no authentication (CWE-306). Attackers chain the file write into a DLL hijack against PGImageExchangeQueueSvc.exe, which loads CRYPTSP.DLL from the application directory when absent, yielding SYSTEM on service restart. There is no evidence this CVE played any role in the MCBS breach, and the timeline (published nine months after the intrusion) makes it unlikely. It is included here because it illustrates the class of exposed, unauthenticated legacy service that sits inside imaging and radiology environments of exactly the kind MCBS's client list is dominated by, and because organizations running PACS Scan 5.2.1 should be patching it regardless.
What Organizations Should Do
-
Inventory your business associates and what they hold. Map every third party that touches PHI, what data classes each receives, and how many patient records they hold on your behalf. Contract language is not an inventory. If you cannot answer "how many of my patients would be exposed if vendor X is breached," you cannot assess this risk.
-
Put egress monitoring ahead of encryption detection. PEAR reportedly does not encrypt. Alert on volumetric outbound transfers, connections to cloud storage and file-transfer services, and any anomalous data movement from billing, claims, and archive systems. A multi-terabyte outbound transfer over a few days should be an incident, not a line in a log.
-
Audit exposed legacy services on healthcare infrastructure. Scan for unauthenticated management and remoting endpoints on non-standard ports, PACS and imaging middleware included. Patch or isolate PACSgear PACS Scan 5.2.1 for CVE-2026-58126 specifically, and treat any .NET Remoting listener reachable from the general network as a finding.
-
Set contractual breach notification clocks with your vendors. Ten months elapsed between intrusion and patient notification here. Require business associates to notify you within days of detection, not after forensic review concludes, and require interim scope estimates.
-
Segment and minimize aggregated data stores. Billing and revenue cycle systems rarely need full clinical histories retained indefinitely alongside SSNs. Enforce retention limits, separate identity data from clinical data where workflow allows, and restrict service accounts to the minimum record scope.
-
Prepare patient-facing response before you need it. MCBS advised affected individuals to place fraud alerts and consider credit freezes. That is the right baseline, but credit monitoring does nothing for exposed diagnosis and treatment data. Plan communications that acknowledge the clinical exposure honestly rather than defaulting to credit-monitoring boilerplate.
Sources: How Did PEAR Ransomware Breach 1.26 Million Patient Records? Bioph... | CVE-2026-58126: PACSgear PACS Scan RCE Vulnerability | Data breach at medical billing firm MCBS affects 1.26 million people | MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals | MCBS Data Breach Affects 1.2 Million Individuals - SecurityWeek | Ransomware attack on medical billing company results in data on 1.3... | MCBS Data Breach Affects 1.26 Million People | 1.26 Million Patients Hit As Medical Breach Exposes Social Security...