More than 1.2 million people were affected by a cyberattack targeting Medical Computer Business Services (MCBS), according to updated information filed with the U.S. Department of Health and Human Services. The filing states that 1,261,464 individuals were impacted, providing the first official estimate of the breach’s scale after the company disclosed the incident last month.

 

 

MCBS is a medical billing and practice management company based in Augusta, Georgia. It provides billing, coding, financial and administrative services to healthcare organisations, processing patient information on behalf of medical providers rather than delivering healthcare directly.

According to the company’s breach notification, an unauthorised party accessed its network between September 22 and September 26, 2025. MCBS launched a forensic investigation to determine what had occurred and completed its review on May 28, 2026.

The investigation found that the information exposed varies by individual. Depending on the affected person, the compromised data may include names, home addresses, Social Security numbers, dates of birth, health insurance policy numbers, beneficiary identifiers, subscriber identification numbers, medical histories, treatment details, diagnosis information, and information relating to physical or mental health conditions.

MCBS identified several healthcare providers whose patient information it handled as a business associate. Those organisations include South Georgia Radiology Consultants, SkinPath Solutions, Stephen W. Brown, and Radiology Associates. The company said additional covered entities may also be involved based on the services it provided.

The company is encouraging potentially affected individuals to take steps to reduce the risk of identity theft. Recommended measures include placing a fraud alert on credit files, considering a credit freeze, and monitoring accounts for suspicious activity. Patients who received healthcare services in Georgia are also advised to contact their healthcare provider to determine whether their information was processed by MCBS and whether they may have been affected.

Separately, the ransomware group PEAR (Pure Extraction and Ransom) has claimed responsibility for the intrusion. According to the group’s posting on its data leak site, it allegedly exfiltrated approximately 3.3 terabytes of information from MCBS systems. MCBS has not confirmed that claim, and it has not been independently verified.

The ransomware group further alleges that the stolen files include human resources records, payment information, internal business documents, email correspondence, and company databases in addition to patient information. MCBS has confirmed that patient and healthcare-related information was exposed but has not verified those additional claims or disclosed how the attackers gained access to its network.

The company has not announced whether a ransom demand was received. It has completed its investigation into the incident, while the claims made by the PEAR ransomware group regarding the scope of the allegedly stolen data remain unverified.

Incoming search terms:

Leave a Reply