Medical Billing Firm MCBS Breach Exposes 1.2 Million Patient Records to PEAR Ransomware
A significant data breach at **Medical Computer Business Services (MCBS)**, a medical billing and practice-management company, has compromised the sensitive information of over 1.2 million individuals. The incident, attributed to the **PEAR ransomware group**, involved unauthorized network access and the exfiltration of extensive patient data, including Social Security numbers and medical histories.
Healthcare data aggregator **MCBS** has confirmed a network breach that occurred between September 22 and 26, 2025. The incident, first disclosed in late June, has now been reported to the U.S. Department of Health and Human Services, indicating that **1,261,464** individuals have been affected.
**MCBS**, headquartered in Augusta, Georgia, provides critical billing, coding, and administrative services to healthcare organizations, making it a central repository for vast amounts of patient data.
### Scope of the Compromise
Following an extensive investigation completed on May 28, the company determined that a wide range of personal and protected health information (PHI) may have been exposed. This includes:
* Full name
* Physical address
* Social Security number
* Date of birth
* Health plan beneficiary number
* Health insurance policy number
* Subscriber identification number
* Medical history
* Mental and physical condition
* Medical treatment information
* Diagnosis information
The specific data exposed varies per individual, depending on the services rendered by the affected healthcare providers. **MCBS** acts as a business associate for several "covered entities," including **South Georgia Radiology Consultants**, **SkinPath Solutions**, and **Stephen W. Brown and Radiology Associates**, whose patient data was handled by the compromised systems.
### Ransomware Group Claims Responsibility
The **PEAR ransomware group** has publicly claimed responsibility for the attack, asserting that they exfiltrated **3.3 terabytes** of data from **MCBS**'s systems. Beyond the client data acknowledged by **MCBS**, **PEAR** also claims to possess human resources data, business operation details, payment information, email correspondence, and various databases.

### Recommendations for Affected Individuals
**MCBS** is advising potentially impacted individuals to take proactive measures to protect themselves against identity theft and fraud. These recommendations include placing a fraud alert and considering a security freeze on their credit files.
Patients who have received medical services in Georgia are encouraged to contact their healthcare providers to ascertain whether their data was processed by **MCBS** and potentially affected by this incident. This breach underscores the persistent and evolving threat landscape faced by healthcare-adjacent organizations that handle sensitive patient information.