ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Over 300,000 affected as MCBS reveals sensitive data was compromised

Revenue cycle management company MCBS said a data security incident it suffered last year exposed the sensitive personal data of more than 300,000 individuals.

 

Headquartered in Augusta, Georgia, Medical Computer Business Services is a revenue cycle management company that provides billing, medical coding, claims processing, accounts receivable management, and other administrative services to healthcare providers. The company helps hospitals and physician practices streamline financial operations by managing insurance claims, payments, and reimbursements.

 

In a data security incident notice published on its website, MCBS said that on September 25, it identified unauthorised access within its internal network. The healthcare service provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.

 

It also took steps to secure the affected systems and notified relevant law enforcement authorities about the same.

 

“After an extensive forensic investigation, we discovered that between September 22, 2025, and September 26, 2025, an unauthorised user may have accessed or removed some of our files. We conducted a thorough manual review of the potentially impacted data, and on May 28, 2026, we determined that the files may have contained some personal information,” MCBS said.

 

The compromised data included names, addresses, Social Security numbers, dates of birth, health plan beneficiary numbers, health insurance policy numbers or subscriber identification numbers, other health insurance information, medical history, mental or physical condition, medical treatment information, and diagnosis information.

 

According to filings with state regulators, the breach affected 295,625 individuals in South Carolina, 13,302 in Texas, and 382 in Massachusetts. MCBS identified several affected healthcare providers, including C&C MD PC, Nuclear Medicine and Pathology Associates, Radiation Oncology Associates, SkinPath Solutions, South Georgia Radiology Consultants, Stephen W. Brown & Radiology Associates of Augusta, and Vascular Radiology Associates.

 

While MCBS found no evidence of the compromised information being misused, it advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.

 

x

 

 

In September, the Pear ransomware group claimed responsibility for the cyber attack on MCBS and listed the healthcare service provider as a victim on its data leak site. The group claimed that it had exfiltrated 3.3 TB of confidential data and threatened to publish the entire database unless its ransom demands were satisfied.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543