← Blog

MCBS Breach: PEAR Hit Leaves 1.26M in HHS Count

Share on X

Atlanta medical billing firm MCBS (Medical Computer Business Services) has confirmed a September 2025 ransomware-linked intrusion that the U.S. Department of Health and Human Services now ties to 1,261,464 individuals. The company posted a public notice at mcbs.com/data-breach-2025. SecurityWeek reported on July 27, 2026 that the PEAR ransomware group claimed the attack and alleged roughly 3 TB of stolen files.

Canonical BreachHistory record: 2025 MCBS — PEAR ransomware; HHS 1,261,464 individuals.

What happened

MCBS says it experienced unauthorized network access on or about September 25, 2025. After containment and a forensic investigation, the firm concluded that between September 22 and September 26, 2025 an unauthorized user may have accessed or removed files. On May 28, 2026, after a manual data review, MCBS determined those files could hold personal and health information for people connected to client healthcare organizations.

That timeline matters for patients who never heard of MCBS. The company is a revenue cycle and medical billing business associate. When a billing vendor is hit, the PHI of multiple clinics can move in one theft—even if each clinic’s own EHR stayed online.

HHS’s breach portal lists the MCBS event against 1,261,464 affected individuals. That is the denominator BreachHistory uses for the catalog row—not PEAR’s marketing language about terabytes.

What PEAR claimed

PEAR (Pure Extraction and Ransom) claimed responsibility in late September 2025 and said it stole more than 3 TB, including company and client financials, HR and operations documents, partner and vendor data, patient PII and PHI, payment details, and email. SecurityWeek reported the group made alleged stolen data available for download on its leak site.

To be clear: actor volume claims are not the same as a company-attested person count. MCBS’s notice and the HHS filing are the verified spine. PEAR’s leak-site narrative explains who claimed the intrusion and why trade press connected the dots months later when patient letters and the OCR row surfaced.

What data was exposed

Per the MCBS notice, impacted files may have included some combination of:

  • Name and address
  • Social Security number
  • Date of birth
  • Health plan beneficiary number
  • Health insurance policy number or subscriber ID
  • Other health insurance information
  • Medical history, mental or physical condition, treatment information, and diagnosis information

Not every person had every field. MCBS says the information varies by individual. The company stated it had no evidence of identity theft tied to the incident at the time of the notice—while still urging people to watch financial statements.

Which healthcare organizations were named

MCBS’s notice lists seven covered entities whose data was in scope:

  • C&C MD PC
  • Nuclear Medicine and Pathology Associates
  • Radiation Oncology Associates, LLP
  • SkinPath Solutions, LLC
  • South Georgia Radiology Consultants PC
  • Stephen W. Brown & Radiology Associates of Augusta, LLP
  • Vascular Radiology Associates II, LLP

If you received care from a Georgia radiology, pathology, nuclear medicine, or vascular practice in that list—or saw MCBS on an Explanation of Benefits—treat a letter citing this incident as actionable even if you never created an MCBS login.

Who is at risk

Primary risk sits with patients of those named practices: medical identity theft, fraudulent claims filed under your identifiers, and phishing that quotes real provider names. Secondary risk hits employees and partners if PEAR’s broader dump claims about HR and vendor files prove accurate. Billing vendors concentrate PHI from many clinics; one successful ransomware intrusion becomes a multi-practice disclosure.

Compare the pattern to other 2025–2026 healthcare vendor events in our catalog, including Xsolis and Centers Laboratory. PEAR also appears on an unverified Carient Heart & Vascular leak-site claim—useful context for the actor, not proof those rows share files.

Timeline

  • Sept 22–26, 2025: Unauthorized access window per MCBS forensics
  • ~Sept 25, 2025: MCBS detects unauthorized activity and contains
  • Late Sept 2025: PEAR claims MCBS and advertises ~3 TB
  • May 28, 2026: MCBS completes determination that personal/health data may be in files
  • 2026: HHS OCR lists 1,261,464 individuals
  • July 27, 2026: SecurityWeek covers the company notice and PEAR claim

What was not claimed by MCBS

MCBS did not publish a full forensic malware family analysis in the consumer notice. It did not assert that every client database was copied in full. It did not confirm PEAR’s terabyte figure as an official metric. Absence of those details is normal in HIPAA-style notices; it is not a green light to ignore SSN exposure.

Action items

  1. If you get an MCBS or practice letter, call the number on the letter—or MCBS at (844) 959-7135 (8:00 a.m.–5:30 p.m. CT)—before trusting any SMS that “confirms” your breach status.
  2. Place a one-year fraud alert and consider a credit freeze at Equifax, Experian, and TransUnion—SSNs were in scope for some people.
  3. Enroll in any complimentary credit monitoring the notice offers; keep the enrollment codes offline.
  4. Review Explanation of Benefits and medical bills for services you did not receive.
  5. Treat “update your radiology portal password” emails that arrive the same week as the news as high-risk phishing.
  6. Use unique passwords and MFA on email accounts tied to healthcare portals—credential reuse turns one PHI leak into inbox takeover.

Why medical billing breaches hit harder

Revenue-cycle platforms store the identifiers insurers need to pay claims: names, DOBs, member IDs, and often SSNs for eligibility. Attackers prefer that package because it supports both classic identity theft and medical fraud. Patients rarely choose the billing vendor; the clinic does. That asymmetry is why business-associate breaches dominate large HHS rows even when hospital brands stay out of the headline.

PEAR’s mid-2025 emergence and triple-digit victim listings on leak trackers show a group hunting mid-market professional and healthcare services. MCBS is the rare case where company confirmation, an OCR headcount, and a named ransomware claim align in public reporting.

How this compares inside BreachHistory

At roughly 1.26 million people, MCBS sits in the same order of magnitude as other major 2026-reported healthcare vendor events such as Xsolis (~1.4M). It is smaller than the expanding DentaQuest notification wave (15M+), and larger than many single-clinic ransomware notices. Scale alone does not rank harm—SSN plus diagnosis data is high-impact even at lower counts.

Canonical record and sources

Full catalog entry: https://breachhistory.com/mcbs/mcbs-pear2025. Primary sources: MCBS notice, SecurityWeek, and the HHS OCR breach portal.

If MCBS or HHS later revises the individual count or names additional covered entities, BreachHistory will update the catalog row. Until then, treat 1,261,464 as the attested population and PEAR’s 3 TB claim as actor-reported context.

Reading an MCBS letter without panicking

Breach letters are dense on purpose. Look for three lines first: the date range of unauthorized access, the data elements that apply to you, and the enrollment code for monitoring. If the letter names one of the seven covered entities, that is your clinic relationship—even if you only visited once for imaging or a pathology consult.

Do not mail your SSN to a callback number you googled from a social post. Use the URL on the letter or the MCBS site path above. Scammers clone PEAR headlines within hours of SecurityWeek posts and ask victims to “verify identity” on lookalike domains.

For clinic and compliance teams

Covered entities that used MCBS should map which of the seven named organizations match their corporate tree, confirm BA agreements, and document OCR/state AG obligations already triggered by MCBS’s filing. Ask MCBS for a data-element matrix by client rather than relying only on the public bullet list. Preserve logs that show when claims files last synced before September 22, 2025.

Procurement teams evaluating future billing vendors should add ransomware tabletop scenarios that assume the BA—not the EHR—is the blast radius. Ask for evidence of segmented file shares, immutable backups, and how quickly the vendor can produce an individual-level impact list after containment.

Medical identity theft after a billing breach

When diagnosis and insurance identifiers travel with SSNs, fraudsters can open utility accounts, file false claims, or build synthetic identities. Watch for collection notices for procedures you never received, pharmacy claims for medications you do not take, and insurer letters about benefits used in another state. Dispute early; medical credit problems linger longer than retail card fraud.

If you are a caregiver managing records for a minor or elderly relative who visited one of the named practices, request credit freezes for them as well where available and keep a folder of EOBs from the September 2025 window forward.

PEAR in the wider 2025–2026 healthcare picture

Ransomware groups increasingly monetize double extortion against specialty practices and their vendors rather than only Fortune 500 brands. PEAR’s public claims against medical and professional-services victims fit that shift. Verified cases like MCBS are more useful for risk scoring than raw leak-site tallies because they attach regulator counts and named data types.

Still, an unverified PEAR listing somewhere else should not be ignored by a clinic’s IR team—it should trigger hunts for the same initial-access patterns while remaining labeled unverified in public catalogs until a notice or OCR row exists.

Practical checklist for the next 30 days

  1. Confirm whether any household member used the named Georgia practices.
  2. Enroll monitoring codes from legitimate letters within the enrollment window.
  3. Freeze credit; lift temporarily only for known applications.
  4. Set transaction alerts on bank and credit cards.
  5. Screenshot and file any suspicious “MCBS refund” or “radiology portal” emails for your bank’s fraud team.
  6. Ask your insurer’s fraud unit to flag your member ID if you see anomalous claims.

BreachHistory will keep the MCBS PEAR ransomware catalog page synchronized with new regulator figures and practice-level notices as they appear.

How business-associate breaches show up in your mailbox

Patients often expect a letter on hospital letterhead. BA breaches break that expectation. You may see MCBS branding, a practice name you barely remember, or both. Some states require the covered entity to notify even when the BA sends the operational letter. Keep every envelope until you confirm enrollment codes work.

If two letters arrive—one from MCBS and one from a radiology group—compare the listed data elements. Use the more inclusive list when deciding whether to freeze credit. Duplicate monitoring enrollments are annoying; missing an SSN flag is worse.

Separating verified facts from leak-site theater

PEAR’s screenshots and “3 TB” claims are useful threat intelligence. They are not a substitute for the HHS individual count. Catalogs that only mirror leak sites inflate noise; catalogs that wait for notices alone miss early warning. BreachHistory records both layers with labels: MCBS is company-confirmed with an OCR denominator, while PEAR’s dump narrative stays attributed to the actor.

That distinction also protects journalists and SOC teams from circular citations. When a class-action site repeats only the PEAR claim, check whether a company URL or OCR row exists. For MCBS, both now do.

Georgia specialty practices and concentrated risk

The seven named organizations cluster around radiology, pathology, nuclear medicine, dermatopathology, and vascular imaging—specialties that generate high volumes of referral PHI and insurance identifiers. Patients may visit once for a biopsy read or interventional procedure and still land in a billing vendor’s long-retention archive.

If you moved out of Georgia years ago, do not assume you are clear. Billing archives often retain claims history far longer than portal passwords stay active. A 2023 imaging visit can still appear in a 2025 BA theft.

Technical lessons for mid-market healthcare IT

Four-day access windows like September 22–26 suggest either rapid detection or a short burst of exfiltration tooling. Either way, segmented file servers and least-privilege service accounts limit what four days can steal. Immutable backups and offline copies reduce the extortion lever even when data leaves.

Email remains a common path into billing environments because staff handle attachments from many clinics. Phishing-resistant MFA on admin paths, just-in-time access for remote support vendors, and monitoring for bulk archive creation are cheaper than notifying 1.2 million people.

What regulators will likely examine

OCR will look at whether MCBS and the covered entities met breach-notification timelines, whether risk analyses covered the BA relationship, and whether access controls matched the sensitivity of claims files. State AGs may focus on SSN handling and the clarity of consumer letters. Civil litigators will argue damages from anxiety and monitoring time even without proven fraud—standard in large PHI cases.

None of that changes the immediate patient checklist: freeze credit, enroll monitoring, and distrust opportunistic phishing.

Related BreachHistory reading

For other large healthcare vendor incidents with attested counts, see Xsolis, Centers Laboratory, and the updated DentaQuest notification wave. For PEAR as an actor label without company confirmation, see the Carient leak-site claim.

If you never got a letter

Not receiving mail does not prove you were excluded. Addresses go stale; some populations are notified by substitute notice. Check the MCBS notice page periodically, ask the named practices’ privacy officers, and monitor credit anyway if you had imaging or pathology work in their networks during the years MCBS handled billing.

Employees of the seven covered entities should also ask HR whether workforce data sat on the same file shares PEAR claimed. Consumer letters focus on patients; internal HR exposure may be handled separately.

Closing

The MCBS incident is a textbook mid-market healthcare BA ransomware event: short confirmed access window, large OCR population, sensitive mixed PII/PHI, and a named extortion group amplifying the story. Use the company notice and HHS count as your facts. Use PEAR’s claims as context. Then freeze credit, enroll monitoring, and assume phishing will ride the headlines.

Start here for the structured record: MCBS PEAR ransomware — 1,261,464 individuals.

Key takeaways

  • MCBS confirmed unauthorized access September 22–26, 2025; data determination completed May 28, 2026.
  • HHS lists 1,261,464 individuals—use that number, not PEAR’s terabyte marketing, for population scale.
  • SSNs, insurance IDs, and medical/diagnosis details may be in scope depending on the person.
  • Seven Georgia-area specialty practices are named on the MCBS notice.
  • Call (844) 959-7135 or the number on your letter; freeze credit; enroll monitoring; expect phishing.