>samit_hota
Back to security news
SN-2026-212HighOpen

MCBS Data Breach Exposes 1.26 Million Patient Records After Ransomware Attack

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Medical Computer Business Services (MCBS), South Georgia Radiology Consultants, SkinPath Solutions, Stephen W. Brown and Radiology Associates
#news#ransomware#mcbs

A major supply-chain security incident in the healthcare sector has come to light following a formal filing with federal regulators by Augusta, Georgia-based Medical Computer Business Services (MCBS). The MCBS data breach has impacted 1,261,464 individuals across multiple healthcare networks, exposing a vast repository of sensitive patient information and administrative data after threat actors maintained undetected access to the billing firm’s internal systems.

Breach Timeline and Affected Entities

Between September 22 and September 26, 2025, unauthorized actors infiltrated the internal network of Medical Computer Business Services. Operating as a regional private medical billing and practice-management firm, MCBS provides critical backend infrastructure—including medical coding, accounts receivable management, financial processing, and administrative support—for numerous medical practices across the southeastern United States.

Because MCBS functions as a central healthcare data aggregator, it stores and processes extensive patient databases on behalf of its client organizations. Following the initial network intrusion, MCBS launched a multi-month forensic investigation to determine the full scope of the incident. That investigation concluded on May 28, confirming that sensitive personal and health information managed by the firm was compromised.

Late last month, MCBS submitted an official breach disclosure to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights, confirming the 1,261,464 individual victim count. The company’s public notification identified seven “covered entities” whose patient records were directly handled by MCBS under Business Associate Agreements (BAAs). Confirmed impacted entities include:

  • South Georgia Radiology Consultants
  • SkinPath Solutions
  • Stephen W. Brown and Radiology Associates

Extortion Tactics and Attributed Threat Group

The attack has been claimed by the PEAR (Pure Extraction and Ransom) ransomware group, an extortion threat actor known for targeting organizations with high regulatory compliance liabilities. PEAR claims to have exfiltrated 3.3 terabytes (TB) of sensitive data from MCBS’s environment prior to or alongside any disruption efforts.

The stolen dataset has now been fully leaked online on dark web disclosure platforms. According to PEAR’s public statements, the exfiltrated cache extends well beyond standard patient health records to include:

  • Complete human resources and employee files
  • Business operation logs and internal documentation
  • Corporate payment information and banking details
  • Internal email correspondence across management and staff
  • Multiple active relational databases containing structured client and billing data

While forensic examiners have verified the network intrusion period, the complete scope of the published 3.3 TB dark web dump highlights the threat actor’s deep lateral movement within MCBS’s operational environment. PEAR’s operational model emphasizes “pure extraction”—stealthy data exfiltration without immediately triggering ransomware encryption payloads—which enables threat actors to exfiltrate massive volumes of data undetected over a multi-day window.

The Systematic Risk of Healthcare Data Aggregators

This incident highlights the cascading threat landscape facing third-party business associates in the healthcare ecosystem. Organizations like MCBS act as centralized nodes, aggregating Protected Health Information (PHI) and Personally Identifiable Information (PII) from dozens of independent medical groups, radiology practices, and specialty clinics.

For cybercriminal groups like PEAR, targeting a third-party billing processor offers a far higher return on investment than individually compromising isolated healthcare providers. Compromising a single billing vendor grants access to millions of aggregated patient files, complete financial billing histories, and active insurance claims data across multiple medical providers simultaneously.

When a Business Associate suffers a breach of this magnitude, the blast radius creates complex compliance and reputational fallout for every covered entity connected to its services. Medical practices are forced to evaluate operational dependencies while managing consumer notifications across overlapping patient demographics.

Guidance for Impacted Organizations and Individuals

MCBS has publicly advised individuals who received medical services within Georgia or from connected healthcare providers to take immediate steps to secure their financial profiles. Recommended individual mitigations include:

  • Contacting local healthcare providers to verify whether patient data was transferred to or processed by MCBS.
  • Placing a fraud alert on credit profiles with major credit bureaus (Equifax, Experian, TransUnion).
  • Initiating a security freeze on personal credit reports to prevent unauthorized line-of-credit openings.

For healthcare providers and business associates, this incident underscores the urgent need for stringent third-party risk management. Security teams managing third-party vendor relationships should immediately enforce strict network segmentation between client-facing billing portals and internal database repositories, implement robust data loss prevention (DLP) policies to detect bulk data egress, and conduct continuous security assessments of all third-party aggregators handling PHI.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call