Think Big Health Care Solutions: Medical billing firm MCBS warns 300,000+ patients of data breach

Think Big Health Care Solutions: Medical billing firm MCBS warns 300,000+ patients of data breach

MCBS Data Breach Exposes Over 300,000 Patients’ Sensitive Information in Ransomware Attack

Medical billing firm Medical Computer Business Services (MCBS) has confirmed a September 2025 data breach affecting at least 309,309 individuals, with the majority 295,625 residing in South Carolina. Additional victims include 13,302 in Texas and 382 in Massachusetts, though figures from MCBS’s home state of Georgia remain undisclosed, suggesting the total could rise as more states report.

The breach compromised highly sensitive data, including names, Social Security numbers, medical histories, treatment and diagnosis details, health insurance information, dates of birth, and addresses. MCBS disclosed that unauthorized access occurred between September 22 and 26, 2025, following an investigation into network intrusions detected on September 25. Notably, the company has not offered free credit monitoring or identity theft protection to affected individuals.

The ransomware group PEAR (Pure Extraction and Ransom) claimed responsibility for the attack on September 30, 2025, asserting it stole 3.3 TB of data from MCBS. However, MCBS has not acknowledged PEAR’s involvement, and the group’s claims remain unverified. Details about the attack vector, ransom demands, or whether a payment was made are still unknown.

Who Is PEAR?

PEAR is a data extortion-focused ransomware group that emerged in August 2025, distinguishing itself by stealing data without encrypting systems. Unlike traditional ransomware operations, PEAR relies solely on threatening to leak stolen information to extort victims. Since its inception, the group has claimed 98 attacks, with 20 confirmed by targeted organizations, exposing over 1.5 million records.

Healthcare has been PEAR’s primary target, with nine confirmed attacks on U.S. healthcare entities, including hospitals, clinics, and third-party vendors like MCBS, Think Big Health Care Solutions, and VirMedice. The MCBS breach is the largest healthcare attack attributed to PEAR, surpassing previous incidents at Tri-Century Eye Care (200,000 victims) and Western Orthopaedics (113,300 victims) both also occurring in September 2025. As of 2026, PEAR remains active, having claimed 43 attacks this year, four of which have been confirmed.

Broader Impact on U.S. Healthcare

The MCBS breach ranks as the third-largest attack on non-direct-care healthcare businesses in 2025, according to Comparitech researchers. The year’s two largest breaches involved:

  • Episource (January 2025): 5.4 million records exposed by unknown attackers.
  • Insightin Health (September 2025): 1.1 million records compromised, with the Medusa ransomware group demanding $500,000.

In 2026, nine additional confirmed attacks on healthcare businesses have exposed 18,765 records, including recent incidents at Clinical Registry Solutions (Akira ransomware, April 2026), Park Dental Research Group (Interlock, April 2026), and Sierra Management Group (Genesis, December 2025). Comparitech is tracking 70 unconfirmed attack claims from 2025 and 70 more from 2026, indicating the true scale of breaches may be significantly higher.

About MCBS

Medical Computer Business Services (MCBS), based in Augusta, Georgia, provides billing and revenue cycle management services to hospitals and clinics nationwide. The company has not disclosed whether it has implemented additional security measures following the breach.

Source: https://www.comparitech.com/news/medical-billing-firm-mcbs-warns-300000-patients-of-data-breach/

Rethink cybersecurity rating report: https://www.rankiteo.com/company/rethink

"id": "RET1783010603",
"linkid": "rethink",
"type": "Ransomware",
"date": "9/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '309,309',
                        'industry': 'Healthcare',
                        'location': 'Augusta, Georgia, USA',
                        'name': 'Medical Computer Business Services (MCBS)',
                        'type': 'Medical billing firm'}],
 'data_breach': {'data_encryption': 'No',
                 'data_exfiltration': 'Yes',
                 'number_of_records_exposed': '309,309',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Names',
                                              'Social Security numbers',
                                              'Medical histories',
                                              'Treatment and diagnosis details',
                                              'Health insurance information',
                                              'Dates of birth',
                                              'Addresses']},
 'date_detected': '2025-09-25',
 'description': 'Medical billing firm Medical Computer Business Services '
                '(MCBS) confirmed a September 2025 data breach affecting at '
                'least 309,309 individuals. The breach compromised sensitive '
                'data, including names, Social Security numbers, medical '
                'histories, treatment and diagnosis details, health insurance '
                'information, dates of birth, and addresses. The ransomware '
                'group PEAR claimed responsibility for the attack, asserting '
                'it stole 3.3 TB of data from MCBS.',
 'impact': {'data_compromised': '3.3 TB', 'identity_theft_risk': 'High'},
 'investigation_status': 'Ongoing',
 'motivation': 'Data extortion',
 'ransomware': {'data_encryption': 'No',
                'data_exfiltration': 'Yes',
                'ransomware_strain': 'PEAR'},
 'references': [{'source': 'Comparitech'}],
 'threat_actor': 'PEAR (Pure Extraction and Ransom)',
 'title': 'MCBS Data Breach Exposes Over 300,000 Patients’ Sensitive '
          'Information in Ransomware Attack',
 'type': 'Data Breach, Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.