MCBS Medical Billing Breach Exposes 1.26M Records
Healthcare billing firm Medical Computer Business Services disclosed a 2025 network breach affecting over 1.26 million individuals. Sensitive healthcare PII exposed.
Medical Computer Business Services (MCBS), a healthcare billing firm, has disclosed that a 2025 network intrusion exposed sensitive information belonging to more than 1.26 million people.
Source: BleepingComputer.
What’s confirmed
- Affected individuals: 1,260,000+
- Intrusion: occurred in 2025; exact date not specified in public disclosures
- Disclosure date: July 28, 2026
- Data type: healthcare billing PII — name, address, insurance information; full data scope not yet enumerated publicly
- Attacker: unknown — no threat actor has claimed responsibility
Confidence: medium. Early-stage disclosure; limited technical detail is public.
Impact
Medical billing data is high-value. It typically includes name, date of birth, home address, insurance ID, and provider information — and sometimes Social Security numbers. HIPAA breach notification requirements apply; MCBS or covered healthcare entities are required to notify affected individuals directly.
No ransomware claim and no regulatory enforcement action observed at time of writing.
If you’re downstream
If your organization transmits billing data through MCBS or a third-party intermediary that routes through them, assess your exposure now. Rotate credentials for any systems with shared access to MCBS environments until the intrusion vector is public. Follow the official breach notification if you receive one — it will carry specific guidance on what data was involved for your records.
Found this useful? Share it.


