Medical Computer Business Services never treated a single patient — it just processed the bill. That was enough for the PEAR ransomware group to walk off with Social Security numbers, diagnoses and 3.3 terabytes of data.
You've probably never heard of Medical Computer Business Services. Neither had 1,261,464 people, until a ransomware group calling itself PEAR broke into the Augusta, Georgia billing vendor, stole 3.3 terabytes of data, and started publishing it on its dark-web leak site. MCBS doesn't treat patients. It processes the paperwork behind the treatment — which turned out to be just as valuable to steal.
How the breach unfolded — and why disclosure took nine months
MCBS breach timeline
Sep 22–26, 2025
Attackers access MCBS systems and begin exfiltrating data, per the company's breach notice.
Early 2026
The PEAR ransomware group claims responsibility and lists MCBS on its dark-web leak site.
May 28, 2026
MCBS completes its internal forensic investigation into the full scope of the exposure.
Late June 2026
MCBS files public disclosure and begins notifying the 1,261,464 affected individuals.
Aug 2026
The breach ranks seventh-largest of 384 health data incidents reported to HHS so far this year.
Under HIPAA, the clock for notifying affected individuals is 60 days — but that clock starts at discovery, not at the moment of the attack. A breach that happened in September 2025 but wasn't fully understood until a forensic investigation wrapped the following May can legitimately end up disclosed the following June, even though it looks, from the outside, like a nine-month cover-up. That gap is a real weakness in how these rules work, not evidence of bad faith on its own — though it's cold comfort to the 1.26 million people who spent most of a year unaware their diagnoses were sitting on a leak site.
Full name, physical address, Social Security number, date of birth
Health plan beneficiary number and related insurance identifiers
Diagnoses, treatment information, and mental and physical condition records
HR data, business operations details, payment information and email correspondence
Freezing credit is the single most effective step after a breach that exposes Social Security numbers. · Unsplash
Why 'just a billing vendor' is exactly the problem
MCBS is a case study in third-party healthcare risk. A billing vendor aggregates protected health information across every provider it serves, which makes it a single point of failure covering far more patients than any one clinic — usually with a fraction of a hospital system's security budget. It's the same structural weakness behind this year's wave of exploited enterprise software, from ServiceNow's pre-auth RCE to the ongoing SharePoint exploitation wave: attackers increasingly go after the software connecting organizations together, not the organizations themselves, because one hole reaches everyone downstream.
1
Check the list of client providers on MCBS's breach notice — if your provider isn't named, you're likely not affected.
2
Enroll in the credit monitoring MCBS is offering — check the official notice for the exact offer and enrollment deadline.
3
Place a security freeze with all three credit bureaus — the exposed SSNs and dates of birth make this the highest-value protection available.
4
Watch for medical identity theft specifically: fraudulent claims filed under your name, which credit monitoring alone won't catch. Request an Explanation of Benefits review from your insurer.
Quick answers
Was my data in the MCBS breach?
Only if a healthcare provider that uses MCBS for billing had your records on file during the September 22–26, 2025 breach window. MCBS's notification lists the affected client providers — check it, or contact your provider directly.
Has the PEAR ransomware group's data actually been verified?
Not independently. PEAR has published the cache on its leak site, but as with most ransomware leaks, outside researchers haven't fully validated its authenticity — treat the claim as credible but unconfirmed in full.
Why did it take so long for MCBS to disclose this?
MCBS says its internal investigation into exactly what was taken wasn't complete until May 28, 2026 — about eight months after the breach. Under HIPAA, the 60-day notification clock starts at discovery, not at the moment of the attack, which is how a breach from September ends up disclosed the following June.
What's the single most important thing to do if I'm affected?
Freeze your credit with all three bureaus. A Social Security number plus a date of birth is close to the full kit needed for new-account fraud, and a freeze blocks that regardless of what else the attackers do with the data.
The pattern that actually matters here isn't MCBS specifically — it's that healthcare's weakest link keeps being the vendors no patient ever hears of. A billing company holds the same diagnosis codes a hospital does, usually with a smaller security budget and no brand reputation on the line to make it a priority. Until insurers start pricing that risk into which providers get to outsource billing, and to whom, expect this exact headline again within the year.