Executive Summary
Medical Computer Business Services (MCBS), a healthcare billing and practice-management company based in Augusta, Georgia, experienced a significant data breach affecting over 1.26 million individuals. The breach occurred between September 22 and 26, 2025, and was discovered and investigated internally, with public disclosure and regulatory filings taking place in June and July 2026. Sensitive information, including protected health information (PHI), Social Security numbers, and medical records, was exposed. The PEAR ransomware group claimed responsibility, alleging exfiltration and online leakage of 3.3 terabytes of data. The breach has sector-wide implications for healthcare providers and their business associates, highlighting the need for robust vendor risk management and timely regulatory notification. No technical indicators of compromise (IOCs) specific to the attack have been published as of July 2026, limiting the ability to perform high-confidence technical attribution.
Technical Information
The MCBS breach represents a large-scale compromise of a healthcare business associate, resulting in the exposure of sensitive data for over 1.26 million individuals. The breach window was identified as September 22–26, 2025, during which unauthorized access to MCBS network servers occurred. The breach was not publicly disclosed until late June 2026, following an internal investigation completed on May 28, 2026, and a formal breach notification filed with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) on June 26, 2026.
The compromised data includes full names, physical addresses, Social Security numbers, dates of birth, health plan beneficiary numbers, health insurance policy numbers, subscriber identification numbers, medical histories, mental and physical condition details, medical treatment information, and diagnosis information. The PEAR ransomware group, which claimed responsibility for the attack, also alleges the theft of human resources data, business operation details, payment information, email correspondence, and various databases. However, the authenticity of the full data cache reportedly leaked online has not been independently verified by security researchers or media outlets (BleepingComputer, Patient Protect).
Technical analysis of the attack, based on sector-wide ransomware tactics, techniques, and procedures (TTPs), suggests that initial access was likely achieved through phishing, exploitation of public-facing applications, or the use of valid accounts. Once inside the network, attackers probably leveraged remote services, credential dumping, and process injection to escalate privileges and move laterally. Data collection and exfiltration likely occurred via web services or command-and-control (C2) channels, followed by the deployment of ransomware to encrypt data and inhibit system recovery. These TTPs align with the MITRE ATT&CK framework and are consistent with the behavior of the PEAR ransomware group and similar actors targeting healthcare vendors.
No specific malware samples, cryptographic hashes, or command-and-control infrastructure have been published in connection with this incident as of July 2026. Attribution to the PEAR group is based on public claims, sector targeting patterns, and confirmation by MCBS and regulatory filings, but lacks high-confidence technical artifacts.
The breach underscores the risks associated with business associate relationships in healthcare, as MCBS acts as a vendor for multiple provider clients. The incident has regulatory implications, particularly regarding the delay between breach occurrence and notification, which may be scrutinized under the HIPAA Breach Notification Rule.
Affected Versions & Timeline
The breach affected the network servers and data repositories managed by MCBS between September 22 and 26, 2025. The internal investigation concluded on May 28, 2026, and the breach was reported to HHS OCR on June 26, 2026. Public notification was posted on the MCBS website in late June 2026, with media coverage beginning on July 28, 2026. The breach impacted 1,261,464 individuals, as reported in the HHS OCR Breach Portal (HHS OCR Breach Portal).
Threat Activity
The PEAR ransomware group claimed responsibility for the attack, stating that 3.3 terabytes of data were exfiltrated and subsequently leaked online. The group’s tactics are consistent with double extortion ransomware operations, which involve both data encryption and the threat of public data leakage to pressure victims into paying ransoms. The attack likely involved initial access via phishing or exploitation of public-facing applications, followed by lateral movement, privilege escalation, and data exfiltration. The lack of published technical indicators limits the ability to confirm the specific malware or infrastructure used.
The breach fits a broader pattern of ransomware attacks targeting healthcare business associates, which often serve as aggregation points for sensitive PHI and are subject to cascading impacts across multiple provider organizations. The incident highlights the importance of network segmentation, privileged access monitoring, audit logging, and encryption of sensitive data.
Mitigation & Workarounds
Critical mitigations for organizations in the healthcare sector and their business associates include implementing network segmentation to limit lateral movement, enforcing privileged access monitoring and least-privilege principles, enabling comprehensive audit logging with anomaly detection, conducting periodic vendor security assessments, and ensuring encryption of PHI both at rest and in transit. Organizations should review and update their incident response and breach notification procedures to ensure compliance with regulatory timelines. Provider clients of MCBS should assess their own exposure, review business associate agreements, and determine whether independent notification to regulators or affected individuals is required.
Indicators of Compromise
The following indicators are provided as point-in-time references and should be validated before enforcement in any security controls. These IOCs are derived from public sources and may not represent direct attacker infrastructure.
Type | Indicator | Reported (date) | Source
|
Domain | ocrportal[.]hhs[.]gov | July 28, 2026 | https://patient-protect.com/hipaa-pulse/story/data-breach-at-medical-billing-firm-mcbs-affects-1-26-millio--722b0c62-7ee0-4b9f-9444-0c3353baa7bb |
Domain | patient-protect[.]com | July 28, 2026 | https://patient-protect.com/hipaa-pulse/story/data-breach-at-medical-billing-firm-mcbs-affects-1-26-millio--722b0c62-7ee0-4b9f-9444-0c3353baa7bb |
URL | hxxps://ocrportal[.]hhs[.]gov/ocr/breach/breach_report_hip[.]jsf | July 28, 2026 | https://patient-protect.com/hipaa-pulse/story/data-breach-at-medical-billing-firm-mcbs-affects-1-26-millio--722b0c62-7ee0-4b9f-9444-0c3353baa7bb |
URL | hxxps://patient-protect[.]com/hipaa-pulse/story/data-breach-at-medical-billing-firm-mcbs-affects-1-26-millio--722b0c62-7ee0-4b9f-9444-0c3353baa7bb | July 28, 2026 | https://patient-protect.com/hipaa-pulse/story/data-breach-at-medical-billing-firm-mcbs-affects-1-26-millio--722b0c62-7ee0-4b9f-9444-0c3353baa7bb |
References
BleepingComputer, July 28, 2026: https://www.bleepingcomputer.com/news/security/data-breach-at-medical-billing-firm-mcbs-affects-126-million-people/
Patient Protect (HIPAA Pulse), July 28, 2026: https://patient-protect.com/hipaa-pulse/story/data-breach-at-medical-billing-firm-mcbs-affects-1-26-millio--722b0c62-7ee0-4b9f-9444-0c3353baa7bb
HHS OCR Breach Portal, accessed July 2026: https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf
MITRE ATT&CK Ransomware TTPs: https://www.picussecurity.com/resource/the-top-ten-mitre-attack-techniques?hs_amp=true
About Rescana
Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, assess, and monitor vendor security posture and supply chain risk. Our platform enables continuous monitoring of business associates, supports regulatory compliance workflows, and facilitates rapid incident response coordination. For questions regarding this incident or to discuss how Rescana can support your risk management program, contact us at info@rescana.com.



