U.S.-based healthcare billing company Medical Computer Business Services (MCBS) has confirmed that a cyberattack on its network has compromised the sensitive personal and medical information of more than 1.26 million individuals
Medical Billing Firm MCBS Confirms Data Breach Impacting Over 1.26 Million Patients

The disclosure significantly expands on an earlier breach notification issued by the company late last month, when MCBS acknowledged a cybersecurity incident but did not reveal how many individuals had been affected. A subsequent filing with the U.S. Department of Health and Human Services (HHS) now confirms that 1,261,464 people were impacted by the breach.
Regional Healthcare Service Provider
Headquartered in Augusta, Georgia, Medical Computer Business Services is a privately owned healthcare billing and practice-management company. It provides a range of administrative services—including medical billing, coding, accounts receivable management, financial reporting, and practice administration—to hospitals, physician groups, and other healthcare providers across the United States.
Because MCBS manages sensitive patient and financial records on behalf of healthcare organizations, the breach has raised concerns about the security of third-party healthcare service providers that handle protected health information (PHI).
What Happened?
According to the company’s disclosure, attackers gained unauthorized access to MCBS’s internal network during a cybersecurity incident in 2025. While the company has not publicly disclosed the exact method used by the attackers or whether ransomware was involved, investigators determined that confidential information stored on company systems may have been accessed.
The breach was initially reported without specifying the scale of the incident. However, following a comprehensive forensic investigation, MCBS updated federal regulators with the confirmed number of affected individuals.
Information Potentially Exposed
Although MCBS has not released a complete list of compromised data elements, healthcare breaches of this nature often involve sensitive personal and medical information, including:
- Full names
- Dates of birth
- Mailing addresses
- Medical record numbers
- Health insurance information
- Billing and claims data
- Social Security numbers (for some individuals)
- Financial account information, where applicable
The exact categories of exposed information may vary depending on the healthcare provider associated with each patient.
Investigation Underway
MCBS says it has launched an internal investigation with the assistance of cybersecurity experts to determine the full scope of the attack and assess the impact on affected clients and patients.
The company has also notified relevant healthcare organizations and federal regulators, as required under U.S. healthcare privacy laws, including the Health Insurance Portability and Accountability Act (HIPAA).
Officials are continuing to examine how the attackers gained access to the company’s systems, how long they remained inside the network, and whether any patient information has been misused.
Growing Threat to the Healthcare Sector
The breach highlights the continued targeting of healthcare organizations and their third-party vendors by cybercriminals. Medical billing companies are increasingly attractive targets because they store large volumes of valuable personal, financial, and medical information.
Cybersecurity experts warn that stolen healthcare records can be used for identity theft, insurance fraud, financial fraud, phishing campaigns, and other forms of cybercrime.
Healthcare organizations have experienced a steady rise in ransomware attacks and data breaches in recent years, prompting regulators to encourage stronger cybersecurity practices across the sector.
Guidance for Affected Individuals
Individuals who may have been affected are encouraged to:
- Review any notification letters received from MCBS or their healthcare provider.
- Monitor bank accounts and insurance statements for suspicious activity.
- Watch for unexpected medical bills or insurance claims.
- Consider placing fraud alerts or credit freezes with major credit reporting agencies if sensitive financial information was exposed.
- Remain cautious of phishing emails or phone calls claiming to be related to the breach.
Outlook
With more than 1.26 million individuals now confirmed as victims, the MCBS cyberattack ranks among the largest healthcare data breaches disclosed in 2025. As forensic investigations continue, additional details regarding the attack method, the nature of the compromised information, and any potential legal or regulatory actions are expected in the coming months.









