Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people.
The security incident was disclosed late last month without any details about the number of potentially affected individuals. In a disclosure to the U.S. Department of Health and Human Services, the company reported that 1,261,464 people have been impacted.
MCBS is a regional private medical billing and practice-management company headquartered in Augusta, Georgia, that provides billing, coding, accounts receivable, financial, and administrative services to healthcare organizations.
The company acts as a healthcare data aggregator, processing patient records for healthcare providers.
In late June, MCBS published a notification on its website, informing that threat actors had gained unauthorized access to its network between September 22 and 26, 2025.
The company then conducted an investigation to determine the incident’s scope and impact, and completed it on May 28 this year, determining that the following data may have been exposed:
It should be noted that exposed data varies per individual.
The notice also lists seven “covered entities,” indicating healthcare providers whose patient data MCBS handled as a business associate, including South Georgia Radiology Consultants, SkinPath Solutions, and Stephen W. Brown and Radiology Associates.
MCBS urges potentially impacted individuals to place a fraud alert and consider placing a security freeze on their credit file.
Individuals who have received medical services in Georgia are advised to contact their healthcare provider to determine whether it works with MCBS and whether their personal information may have been affected by the incident.
The attack has been claimed by the PEAR (Pure Extraction and Ransom) ransomware group, which alleges it exfiltrated 3.3 terabytes of data from MCBS systems.
Apart from the client data the firm highlighted as exposed in its announcement, the threat actor also claims to hold human resources data, business operation details, payment information, email correspondence, and various databases.
The data has been fully leaked online, but BleepingComputer did not examine the cache and cannot validate its authenticity.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Medtronic notifies customers impacted by ShinyHunters data breach
Healthtech firm Xolis suffers data breach impacting 1.4 million people
Coca-Cola confirms data theft in Fairlife ransomware attack
DentaQuest data breach exposed info of 2.6 million accounts
OnTrac notifies customers of data breach after network hack
OpenAI confirms ChatGPT is down worldwide
Malicious sites use JavaScript to build malware in browser memory
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Overdue a password health-check? Audit your Active Directory for free
AI agents can speed up ransomware attacks. See how Acronis helps reduce the risk.
Your Scanners Are Green. Your Pipeline Might Not Be. Here’s How to Close the Gap.
Rev5 is ending. See what your FedRAMP 20x transition really requires
Uncover shadow AI apps, agents, and risky data sharing. Get started in 5 min.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



