A cyberattack on medical billing company Medical Computer Business Services (MCBS) exposed personal, insurance, and medical information belonging to patients of seven healthcare organizations.

 

What happened

MCBS, a Georgia-based medical billing and practice management company, has disclosed a data breach affecting 1,261,464 individuals.

According to MCBS’s breach notice, the company detected unauthorized access to its network on or around September 25, 2025. MCBS contained the incident and hired cybersecurity specialists to investigate.

The investigation found that an unauthorized user may have accessed or removed files between September 22 and September 26, 2025. After a forensic investigation and manual review, MCBS determined on May 28, 2026, that the files may have contained personal and protected health information.

The HHS breach portal lists MCBS as a business associate and reports that 1,261,464 individuals were affected. The incident was reported to HHS on June 26, 2026, as a hacking or IT incident involving a network server.

 

What was said

“We have no evidence of any identity theft related to this incident,” MCBS stated in its notification.

The company said it continually evaluates and modifies its practices to strengthen the security and privacy of the information it maintains.

 

Why it matters

The HHS defines a business associate as a person or organization that uses or discloses protected health information while performing services for a HIPAA covered entity. The HHS specifically identifies billing, claims processing, data analysis, and practice management as business associate functions.

Business associates are not protected from HIPAA responsibility simply because they are vendors. HHS says business associates are directly liable for certain HIPAA requirements, including compliance with the Security Rule and the obligation to notify covered entities of a breach. The risk is not theoretical; Paubox’s 2026 Healthcare Email Security Report found that vendor and business associate exposure accounted for 28% of email-related healthcare breaches reported in 2025. Although the MCBS incident involved a network server rather than email, the statistic shows how often third-party relationships contribute to healthcare organizations’ broader breach exposure.

The seven affected healthcare organizations also depend on MCBS to provide enough information to identify patients and issue accurate notifications. Under the HIPAA Breach Notification Rule, a business associate must notify affected covered entities without unreasonable delay and no later than 60 days after discovering a breach.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQs

Why did a billing company have medical information?

Medical billing depends on information about the patient, insurer, diagnosis, and treatment being billed.

 

What is the difference between a security incident and a data breach?

A security incident is any event that threatens a system or its information. It becomes a data breach when protected information is accessed, acquired, used, or disclosed without authorization.

 

Why can it take months to notify people about a breach?

Investigators may need to review thousands of files manually to identify what information was involved, who it belonged to, and which healthcare organizations must issue notices.

 

Does ‘no evidence of misuse’ mean the information is safe?

No, it means the organization has not identified misuse so far. It does not prove that information was never copied, sold, or retained.