MCBS and Xsolis: Vendors caused most of June's biggest health data breaches

MCBS and Xsolis: Vendors caused most of June's biggest health data breaches

Healthcare Data Breaches Surge as Third-Party Vendors Become Prime Targets

In the first half of 2026, third-party vendors known as business associates were involved in 43% of all large healthcare data breaches reported to U.S. regulators, a sharp rise from the 20% average seen between 2009 and 2017. This trend reflects the growing concentration of sensitive patient data within vendor systems, making them high-value targets for cyberattacks.

June alone saw 66 major healthcare breaches, exposing the protected health information (PHI) of 4.5 million individuals. The two largest incidents both targeting business associates compromised data for over 2.6 million people. Among them:

  • Xsolis, a Tennessee-based AI-powered utilization management firm, suffered a phishing attack in January that granted attackers four days of network access, exposing 1.4 million records.
  • MCBS, a Georgia-based billing and revenue cycle management company, fell victim to the PEAR extortion group, which stole files containing Social Security numbers, medical histories, and insurance details for 1.25 million individuals.

These breaches highlight a critical shift: vendor-side incidents now dominate healthcare data exposure, surpassing traditional breaches at hospitals or health plans. Under HIPAA, covered entities (such as employers with group health plans) remain liable if they fail to ensure vendors comply with security requirements even if the breach occurs at the vendor level.

The Spencer Gifts LLC case underscored this risk. In June, the HHS Office for Civil Rights (OCR) settled a $450,000 HIPAA violation fine with the retailer’s benefits plan after a 2021 ransomware attack exposed data for 10,023 members. Investigators found the plan had no risk analysis or HIPAA-compliant policies in place. The enforcement action marked OCR’s 20th ransomware-related settlement and served as a warning to employers that group health plans regardless of industry must adhere to HIPAA Security Rule requirements.

The year-to-date breach victim count through June reached 34 million, a decline from 2024 and 2025, though still elevated compared to historical averages. However, hacking accounted for 89.7% of affected individuals in June, reinforcing the need for continuous vendor security assessments rather than one-time compliance checks.

As healthcare data becomes increasingly centralized in third-party systems, the cascading impact of vendor breaches grows affecting not just the compromised company but every covered entity in its client network. The trend shows no signs of slowing, with business associate involvement in breaches nearly doubling over the past decade.

Source: https://www.insurancebusinessmag.com/us/news/benefits/vendors-caused-most-of-junes-biggest-health-data-breaches-589010.aspx

Xsolis cybersecurity rating report: https://www.rankiteo.com/company/xsolis

Mcbs Llc cybersecurity rating report: https://www.rankiteo.com/company/mcbs-llc

"id": "XSOMCB1788870784",
"linkid": "xsolis, mcbs-llc",
"type": "Ransomware",
"date": "1/2021",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '1.4 million records exposed',
                        'industry': 'Healthcare',
                        'location': 'Tennessee, USA',
                        'name': 'Xsolis',
                        'type': 'Business Associate (AI-powered utilization '
                                'management firm)'},
                       {'customers_affected': '1.25 million individuals',
                        'industry': 'Healthcare',
                        'location': 'Georgia, USA',
                        'name': 'MCBS',
                        'type': 'Business Associate (Billing and revenue cycle '
                                'management company)'},
                       {'customers_affected': '10,023 members',
                        'industry': 'Retail/Healthcare',
                        'name': 'Spencer Gifts LLC (Group Health Plan)',
                        'type': "Covered Entity (Retailer's benefits plan)"}],
 'attack_vector': ['Phishing', 'Extortion'],
 'data_breach': {'data_exfiltration': 'Yes (PEAR extortion group stole files)',
                 'number_of_records_exposed': ['1.4 million (Xsolis)',
                                               '1.25 million (MCBS)',
                                               '10,023 (Spencer Gifts LLC)'],
                 'personally_identifiable_information': 'Yes (SSNs, medical '
                                                        'data)',
                 'sensitivity_of_data': 'High (PHI, SSNs, medical data)',
                 'type_of_data_compromised': ['Protected Health Information '
                                              '(PHI)',
                                              'Social Security numbers',
                                              'Medical histories',
                                              'Insurance details']},
 'date_publicly_disclosed': '2026-06',
 'description': 'In the first half of 2026, third-party vendors known as '
                'business associates were involved in 43% of all large '
                'healthcare data breaches reported to U.S. regulators. June '
                'alone saw 66 major healthcare breaches, exposing the '
                'protected health information (PHI) of 4.5 million '
                'individuals. The two largest incidents both targeting '
                'business associates compromised data for over 2.6 million '
                'people. Vendor-side incidents now dominate healthcare data '
                'exposure, surpassing traditional breaches at hospitals or '
                'health plans.',
 'impact': {'data_compromised': 'Protected Health Information (PHI), Social '
                                'Security numbers, medical histories, '
                                'insurance details',
            'financial_loss': '$450,000 (HIPAA fine for Spencer Gifts LLC)',
            'identity_theft_risk': 'High (exposure of SSNs and medical data)',
            'legal_liabilities': ['HIPAA violations'],
            'operational_impact': 'Cascading impact on covered entities in '
                                  'vendor client networks'},
 'initial_access_broker': {'entry_point': 'Phishing attack (Xsolis)',
                           'reconnaissance_period': '4 days (Xsolis)'},
 'lessons_learned': 'Vendor-side incidents now dominate healthcare data '
                    'exposure, and covered entities remain liable for vendor '
                    'breaches under HIPAA. Continuous vendor security '
                    'assessments are critical, not just one-time compliance '
                    'checks.',
 'motivation': ['Data Theft', 'Extortion'],
 'post_incident_analysis': {'corrective_actions': ['HIPAA-compliant policies',
                                                   'Continuous vendor security '
                                                   'assessments',
                                                   'Risk analysis '
                                                   'implementation'],
                            'root_causes': ['Lack of risk analysis (Spencer '
                                            'Gifts LLC)',
                                            'Insufficient vendor security '
                                            'assessments',
                                            'Phishing vulnerabilities']},
 'ransomware': {'data_exfiltration': 'Yes (PEAR extortion group)'},
 'recommendations': 'Employers with group health plans must ensure HIPAA '
                    'compliance, conduct risk analyses, and implement security '
                    'policies. Enhanced monitoring and network segmentation '
                    'are recommended for third-party vendors.',
 'references': [{'source': 'HHS Office for Civil Rights (OCR)'}],
 'regulatory_compliance': {'fines_imposed': ['$450,000 (Spencer Gifts LLC)'],
                           'legal_actions': ['20th ransomware-related '
                                             'settlement by HHS OCR'],
                           'regulations_violated': ['HIPAA Security Rule']},
 'response': {'enhanced_monitoring': 'Continuous vendor security assessments '
                                     'recommended'},
 'threat_actor': ['PEAR extortion group'],
 'title': 'Healthcare Data Breaches Surge as Third-Party Vendors Become Prime '
          'Targets',
 'type': ['Data Breach', 'Phishing Attack', 'Ransomware']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.