A billing company most patients never heard of just leaked 1.26 million people's medical records

Medical Computer Business Services never treated a single patient — it just processed the bill. That was enough for the PEAR ransomware group to…

Aliteq
Priya Nair · Software & Systems Editor

Key point

MCBS, a medical billing and practice-management vendor in Augusta, Georgia, confirms a breach affecting 1,261,464 individuals.

Key point

The intrusion happened between September 22–26, 2025; MCBS's internal investigation into the full scope wasn't complete until May 28, 2026, with public disclosure following in late June 2026.

Key point

The PEAR ("Pure Extraction and Ransom") ransomware group claims it exfiltrated 3.3 terabytes and has published the full cache on its leak site.

Key point

Exposed data includes full names, Social Security numbers, dates of birth, health plan beneficiary numbers, diagnoses and treatment records.

Key point

It ranks as the seventh-largest health data breach reported to HHS's Breach Reporting Tool so far in 2026, out of 384 filed.

The number that should worry you more than the SSNs

Social Security numbers get most of the headlines because identity theft is the fear people understand. But this dataset reportedly includes diagnoses and treatment history tied to real names — data…

Aliteq

Read the full story

A billing company most patients never heard of just leaked 1.26 million people's medical records

Read the full story on Aliteq