MCBS
The attackers were inside for four days. Determining whose data they took took eight months. None of the 1.26 million people affected had ever heard of the company.
What happened?
Medical Computer Business Services, a medical billing and practice-management company headquartered in Augusta, Georgia, disclosed a cybersecurity incident affecting 1,261,464 individuals. Attackers had access to its systems between approximately September 22 and September 26, 2025. MCBS identified the attack on or around September 25, 2025.
Following forensic investigation and document review, MCBS determined on or about May 28, 2026 that files containing personal information may have been subject to unauthorized acquisition. The PEAR ransomware group claimed the attack and alleges it exfiltrated 3.3 terabytes of data. The figure of 1,261,464 was reported to the U.S. Department of Health and Human Services.
What data was actually inside?
Per the notification, affected files may have contained names, addresses, Social Security numbers, dates of birth, health plan beneficiary numbers, health insurance policy numbers, subscriber identification numbers, other health insurance information, medical history, mental or physical condition information, medical treatment information, and diagnosis information.
Medical billing data is uniquely concentrated. To submit a claim and get it paid, a single record must carry the patient's identity, the payer's identifiers, and the clinical justification — diagnosis and procedure codes. A hospital can hold identity in one system and diagnoses in another. A billing file cannot. It exists precisely to bind them together.
Who gets hurt and how?
Not one of the 1,261,464 people was a customer of MCBS. They were patients of medical practices that outsourced billing. They never selected this vendor, never saw its name on a form, and had no ability to evaluate its security before handing over their information — because they never knowingly handed it over at all.
SSN plus date of birth supports fraudulent tax filings and new-account fraud. Health plan beneficiary numbers and subscriber IDs support medical identity theft, where fraudulent claims attach to a real person's benefit record — a form of fraud that has to be unwound through the insurer rather than a credit bureau, and that can corrupt a medical record in ways affecting future treatment. Diagnosis and mental or physical condition information supports targeted extortion and, once public, cannot be reissued the way a card number can.
What did they think they were doing right?
Detection was fast. The intrusion ran September 22 to September 26 and MCBS identified it on or around September 25 — while the attackers were still active. Under HIPAA, MCBS operates as a business associate, which means it carries direct regulatory obligations and would have executed business associate agreements with every practice it serves.
Those agreements are the control the healthcare industry relies on for vendor risk. A BAA contractually obligates the vendor to safeguard PHI and to notify on breach. What it does not do is establish what data the vendor actually holds, in what format, going back how many years. It allocates liability. It does not create visibility.
What did they not know about their own data?
Four days of intrusion. Eight months to attribution. September 25, 2025 to May 28, 2026 is 245 days spent answering one question: whose data is this?
That duration is not incompetence, and it is not unusual. It is what document review looks like when 3.3 terabytes of billing files — claim forms, remittance advice, correspondence, scanned documents, spreadsheets accumulated across hundreds of client practices over years — have to be read to determine which named individuals appear and which data elements appear for each. Much of it is unstructured. Some of it is images of paper.
The interval between detection and attribution is the truest available measure of whether an organization knows its own data. MCBS knew within days that it had been breached. It took eight months to learn what it had been holding.
If you handle patient data, could you identify within 24 hours exactly which records were accessed in a breach?
What does attribution look like the morning after?
The HIPAA 60-day notification clock runs from discovery of the breach, and this timeline shows why that phrase is contested in practice. MCBS identified the attack in September 2025 and determined the affected individuals in May 2026. Notification followed the determination, not the detection. Business associates must also notify each affected covered entity, so every one of the hundreds of client practices had to be told, and each of those practices then faced its own patient-notification analysis.
At 1,261,464 individuals, the breach is reportable to the HHS Office for Civil Rights and appears on the OCR breach portal, with media notice required in affected jurisdictions and parallel obligations under state statutes including the California AG breach list. Multiple plaintiffs' firms have announced investigations. For a regional vendor, eight months of forensic review plus notification and monitoring for 1.26 million people is an existential expense — and none of it was the ransom.
What would have changed the outcome?
An existing index of which individuals and which data elements lived in each repository — so that attribution ran in weeks instead of eight months, and 1.26 million people could have acted in 2025 rather than 2026.
Every month of that review was a month affected people spent unaware and unprotected while their Social Security numbers and diagnoses circulated. The forensic work was necessary because the map did not exist; it is the cost an organization pays to learn, retroactively, what it was storing. Providers should be asking vendors a specific question, and it is not whether they have a BAA: how long would it take you to tell me exactly which of my patients are in your systems? The answer is either a number, or a silence that predicts eight months. See also the DentaQuest notification update, where the same clock ran in public across three different victim counts.
MCBS found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.