MCBS hack exposes data of 1.26M patients

A Sept. 22–26, 2025 breach at Atlanta billing firm MCBS exposed names, SSNs, birth dates, addresses, insurance information and medical records for 1,261,464 people.

Atlanta-based medical billing firm MCBS disclosed a September 2025 cyberattack that exposed personal and medical information for 1,261,464 people, according to the U.S. Department of Health and Human Services breach tracker.

An investigation posted on MCBS’s website found attackers accessed company systems from Sept. 22 to Sept. 26, 2025. Files that may have been accessed include names, addresses, Social Security numbers, dates of birth, health insurance information and medical records.

A ransomware group calling itself PEAR claimed responsibility for the incident and said it extracted more than 3 terabytes of data. The group listed company and client financial records, human resources and business operations documents, partner and vendor files, patient personally identifiable information and protected health information, payment details and internal emails among the material taken. Files the group alleges were stolen have been posted on its leak site, which lists more than 100 alleged victims.

MCBS provides medical revenue cycle management and billing services to health care providers. In its breach notification the company named seven health care organizations whose data was affected but did not publish a full client list. The notification says MCBS is continuing its review of the incident and is notifying affected patients and clients.

Federal rules require covered entities and their business associates to report breaches of unsecured protected health information to HHS and to notify affected individuals. The HHS breach tracker is the public record that shows the scope of the MCBS incident and provides the official count of those affected.

Security researchers tracking PEAR report the group emerged in mid-2025 and has claimed other health care-related incidents, including breaches tied to Motility Software Solutions and Tri-Century Eye Care. The PEAR leak site remains active and continues to host the files the group alleges it obtained.

MCBS has not outlined specific remedial measures beyond the breach notification and the ongoing investigation. Law enforcement and forensic reviews are commonly involved in incidents of this size, and affected parties are being notified as MCBS completes its outreach.

Articles by this author