Ransomware attack on medical billing company results in data on 1.3M leaked to dark web
A 2025 data breach on a medical billing company, first revealed in late June, exposed sensitive protected health data on 1.3 million people to hackers.
In an announcement, Medical Computer Business Services (MCBS) said the September 2025 incident stemmed from an unauthorized third party gaining access to its network, though it revealed few details about the nature of the attack, saying online that personal information on individuals stored on its network may have been “accessed or removed.”
Soon after, an updated filing with the U.S. Department of Health and Human Services’ Office of Civil Rights Healthcare Data Breach Tracker showed the official number of victims, meaning that hackers at the very least accessed files on 1,261,464 patients.
The company did not confirm that files were moved offsite. However, BleepingComputer reports—complete with a screenshot from the dark web—that a data trove from the incident is available online, with a ransomware group called PEAR (Pure Extraction and Ransom) taking credit.
The data is available for download, which typically means a ransom wasn’t paid.
The trove was discovered by researchers at the outlet sometime this week.
Stolen information is said to include full names, addresses, dates of birth, health plan details including policy numbers; and detailed medical history on patients, all necessary for billing. This includes details on diagnoses, treatments and more.
In announcing the breach, said to have taken place over the course of four days between September 22-26, 2025, MCBS said it worked with a cybersecurity firm on the investigation to learn more about the scope of the cyberattack and to determine what data was taken.
The company said it “continually evaluates and modifies its practices to enhance the security and privacy of the personal information it maintains.”
Its servers contain a lot of information from HIPAA-covered entities, mainly providers, including C&C MD PC, Nuclear Medicine and Pathology Associates, Radiation Oncology Associates, SkinPath Solutions, South Georgia Radiology Consultants, Stephen W. Brown & Radiology Associates of Augusta, and Vascular Radiology Associates—all of whom are listed as impacted by the incident.
A dark web download
MCBS is located in Georgia and provides regional medical billing and coding services to get medical claims reimbursed.
It said it has no evidence of any identity theft associated with the breach to date, but urges patients who receive a notice to monitor their credit history.
The data trove taken by cybercriminals is huge, with PEAR alleging it to be 3.3 terabytes in size. Anyone can now access and download the entire set on the dark web, where it is publicly available.
HealthExec reached out to MCBS for comment.
