Medical Billing Firm MCBS Suffers 2025 Data Breach, Exposing 1.3 Million Patients’ Sensitive Health Data
In late June 2025, Medical Computer Business Services (MCBS), a medical billing company, disclosed a September 2025 data breach that compromised the protected health information of 1,261,464 individuals. The incident occurred between September 22–26, 2025, when an unauthorized third party gained access to MCBS’s network, though the company provided limited details on the attack’s method.
While MCBS did not confirm whether data was exfiltrated, BleepingComputer reported that a ransomware group known as PEAR (Pure Extraction and Ransom) has since leaked the stolen data on the dark web. The exposed files available for download include full names, addresses, dates of birth, health plan details (including policy numbers), and comprehensive medical records, such as diagnoses, treatments, and billing information.
MCBS, which partners with multiple HIPAA-covered healthcare providers including C&C MD PC, Nuclear Medicine and Pathology Associates, Radiation Oncology Associates, and others stated it is working with cybersecurity experts to assess the breach’s scope and has pledged to strengthen its security measures. The company’s servers store sensitive data from numerous medical entities, all of which were affected by the incident.
C+Y Medical PC cybersecurity rating report: https://www.rankiteo.com/company/cymedicalpc
"id": "CYM1785408051",
"linkid": "cymedicalpc",
"type": "Breach",
"date": "9/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1,261,464 individuals',
'industry': 'Healthcare',
'name': 'Medical Computer Business Services (MCBS)',
'type': 'Medical Billing Company'},
{'industry': 'Healthcare',
'name': 'C&C MD PC',
'type': 'Healthcare Provider'},
{'industry': 'Healthcare',
'name': 'Nuclear Medicine and Pathology Associates',
'type': 'Healthcare Provider'},
{'industry': 'Healthcare',
'name': 'Radiation Oncology Associates',
'type': 'Healthcare Provider'}],
'customer_advisories': 'Issued',
'data_breach': {'data_exfiltration': 'Yes (leaked on dark web)',
'number_of_records_exposed': '1,261,464',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (Protected Health Information)',
'type_of_data_compromised': ['Full names',
'Addresses',
'Dates of birth',
'Health plan details (including '
'policy numbers)',
'Medical records (diagnoses, '
'treatments, billing '
'information)']},
'date_detected': '2025-06-01',
'date_publicly_disclosed': '2025-06-01',
'description': 'In late June 2025, Medical Computer Business Services (MCBS), '
'a medical billing company, disclosed a September 2025 data '
'breach that compromised the protected health information of '
'1,261,464 individuals. The incident occurred between '
'September 22–26, 2025, when an unauthorized third party '
'gained access to MCBS’s network. A ransomware group known as '
'PEAR (Pure Extraction and Ransom) leaked the stolen data on '
'the dark web, including full names, addresses, dates of '
'birth, health plan details, and medical records.',
'impact': {'brand_reputation_impact': 'Likely significant',
'data_compromised': 'Protected health information of 1,261,464 '
'individuals',
'identity_theft_risk': 'High',
'legal_liabilities': 'Potential HIPAA violations',
'systems_affected': 'MCBS’s network and servers'},
'initial_access_broker': {'data_sold_on_dark_web': 'Yes'},
'investigation_status': 'Ongoing',
'motivation': 'Financial Gain',
'post_incident_analysis': {'corrective_actions': 'Strengthening security '
'measures'},
'ransomware': {'data_exfiltration': 'Yes',
'ransomware_strain': 'PEAR (Pure Extraction and Ransom)'},
'references': [{'source': 'BleepingComputer'}],
'regulatory_compliance': {'regulations_violated': ['HIPAA']},
'response': {'communication_strategy': 'Public disclosure and advisories',
'incident_response_plan_activated': 'Yes',
'remediation_measures': 'Strengthening security measures',
'third_party_assistance': 'Cybersecurity experts'},
'threat_actor': 'PEAR (Pure Extraction and Ransom)',
'title': 'Medical Billing Firm MCBS Suffers 2025 Data Breach, Exposing 1.3 '
'Million Patients’ Sensitive Health Data',
'type': 'Data Breach'}