
Medical Computer Business Services (MCBS), a regional medical billing and practice-management firm based in Augusta, Georgia, has disclosed that a ransomware attack in September 2025 exposed the sensitive personal and medical information of more than 1.26 million people. MCBS works as a business associate for multiple healthcare providers, handling billing, coding, and administrative records — making it a high-value target because a single breach can expose data from patients across many separate practices.
Attackers gained access to MCBS networks between September 22 and 26, 2025. The company completed its investigation in May 2026 and determined the breach exposed a wide range of data: full names, physical addresses, Social Security numbers, dates of birth, health plan and insurance policy numbers, subscriber IDs, medical history, mental and physical condition information, diagnosis details, and treatment records. The PEAR ransomware group has claimed responsibility and alleges it exfiltrated 3.3 terabytes of data, which it says it has fully leaked online. The breach was reported to the U.S. Department of Health and Human Services, with 1,261,464 affected individuals listed.
How to check if you’re affected
Affected products include medical billing records handled by MCBS as a business associate for covered healthcare providers. If you received services from South Georgia Radiology Consultants, SkinPath Solutions, or Stephen W. Brown and Radiology Associates, your records may have been included. MCBS recommends placing a fraud alert on your credit file and considering a full credit freeze. Anyone who received healthcare in Georgia should contact their provider to confirm whether MCBS handled their billing records.
