MCBS Data Breach: 1,261,464 People Exposed in Medical Billing Ransomware Attack
A medical billing vendor most patients have never heard of held their Social Security numbers, diagnoses and insurance data. The breach is officially reported, litigation has started, and no settlement exists.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened
Medical Computer Business Services (MCBS) is a medical billing company — the kind of vendor that holds patient data on behalf of healthcare providers without most patients ever knowing its name. The breach has been officially reported as affecting 1,261,464 individuals. Attackers had access between September 22 and 26, 2025; the PEAR ransomware group claimed responsibility and reportedly leaked roughly 3.3 terabytes of stolen data. Exposed categories reported include names, addresses, Social Security numbers, dates of birth, health insurance information and medical data — the full combination that makes both financial and medical identity theft possible.
Case Details
The breach was reported to the U.S. Department of Health and Human Services Office for Civil Rights in June 2026, with broad public reporting following in late July 2026. At least one federal class action has been reported as filed; we have not been able to verify the specific case caption and docket number, so we are not going to print one we cannot confirm. There is no settlement administrator and no claims site — none exists. This page tracks the case from here.
Current Status — Verified August 22, 2026
Who Is Affected
1,261,464 individuals per the official report — patients whose billing data was processed by MCBS on behalf of healthcare providers. The difficulty here is characteristic of vendor breaches: most affected people have never heard of MCBS and have no memory of any relationship with it, because their relationship was with a doctor or hospital that used MCBS for billing. The reliable signal is a notification letter, which may come from MCBS or from the provider. Keep it — it is your proof of membership in any future class.
What Could This Pay? (Honest Answer)
Case Timeline
- 1
September 22–26, 2025: The intrusion
Attackers have access to MCBS systems for roughly four days. The PEAR ransomware group later claims responsibility.
- 2
Reportedly 3.3 TB leaked
The attackers publish stolen data — meaning this is not a case where information was merely accessed; it was taken and released.
- 3
June 2026: Official report — 1,261,464 affected
The breach is reported to HHS Office for Civil Rights, roughly nine months after the intrusion, putting an official number on the exposure.
- 4
Late July 2026: Wide public reporting
Security press coverage brings the breach to public attention. For most affected patients, this is the first they hear of a company they never chose to do business with.
- 5
2026: Litigation begins
At least one federal class action has been reported as filed. Expect additional filings and likely consolidation — the standard path for a breach of this size.
Medical Breach Scams
When diagnosis and insurance data leak together, the resulting scams are unusually convincing because the caller knows real medical details.
Fake medical bills for care you never received
The signature of medical identity theft. Do not pay — demand written validation, check your Explanation-of-Benefits statements, and report it to your insurer and to the FTC. Unpaid fraudulent bills can reach collections and damage your credit.
“MCBS settlement claim” portals
No settlement exists. Any claim form for this breach today is fraudulent. A real claims process would appear in court filings first — and on this page.
Calls quoting your real medical details
With 3.3 TB leaked, a caller may know genuine information about your care. That is evidence they have the stolen data, not evidence they are legitimate. Verify through your provider's known phone number, never through a number the caller supplies.
MCBS Data Breach FAQs
I have never heard of MCBS — how could my data be there?
MCBS is a medical billing vendor. Your relationship was with a doctor or hospital that used MCBS to process billing, which is how your data ended up in a company you never chose. This is the defining feature of vendor breaches and why they catch people by surprise.
Is there a settlement?
No. As of August 22, 2026 there is no settlement, no administrator and no fund. At least one class action has been reported as filed; litigation of this size typically takes years.
What exactly was exposed?
Reported categories include names, addresses, Social Security numbers, dates of birth, health insurance information and medical data. That combination enables both financial identity theft and medical identity theft, which are handled differently.
Why did it take from September 2025 to June 2026 to be reported?
Forensic investigations after ransomware take time, and determining exactly whose data was in an exfiltrated 3.3 TB dataset is genuinely difficult. That said, notification delay is a standard allegation in breach litigation, precisely because the delay is time in which victims cannot protect themselves.
What is medical identity theft and how do I detect it?
It is when someone uses your identity to obtain medical care or prescriptions, which pollutes your medical record and generates bills. Detect it by reading Explanation-of-Benefits statements from your insurer for services you never received, and by requesting your medical records if something looks wrong.
What should I do right now?
Enroll in any monitoring offered in your notice, freeze your credit at all three bureaus, review every Explanation-of-Benefits statement, keep the notification letter, and document anything suspicious with dates.
Do I need to hire a lawyer?
Not to be covered by a future class settlement — that would reach affected people through a claims process. Individual counsel matters mainly if you suffer concrete losses traceable to this breach, particularly medical identity theft that proves hard to unwind.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.