Utopia Tech
Healthcare1 min read

MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals

MCBS, LLC, an Augusta, Georgia-based healthcare management and revenue cycle management company, has announced a major data incident involving the protected health information of 1,261,464 patients of its HIPAA-covered entity clients. Unauthorized network access was detected on or around September 25, 2025. Steps were immediately taken to contain the incident and investigate th

UT

Utopia Tech

July 27, 2026 · 1 min read

Share

MCBS, LLC, an Augusta, Georgia-based healthcare management and revenue cycle management company, has announced a major data incident involving the protected health information of 1,261,464 patients of its HIPAA-covered entity clients. Unauthorized network access was detected on or around September 25, 2025. Steps were immediately taken to contain the incident and investigate the unauthorized access, with third-party cybersecurity experts engaged to help with the investigation.

They confirmed that there had been unauthorized network access between September 22 and September 25, 2025, and files containing protected health information may have been viewed or exfiltrated from its network. The review of the affected data was completed on May 28, 2026, and confirmed that the information potentially compromised in the incident included names, addresses, dates of birth, Social Security numbers, medical histories, mental/physician condition information, diagnosis information, medical treatment information, health plan beneficiary information, health insurance policy numbers/subscriber numbers, and other health insurance information.

MCBS said it continually assesses and enhances its security policies and procedures and will continue to do so. The following HIPAA-covered entities have been affected: C&C MD PC Nuclear Medicine and Pathology Associates Radiation Oncology Associates, LLP SkinPath Solutions, LLC South Georgia Radiology Consultants PC Stephen W. Brown & Radiology Associates of Augusta, LLP Vascular Radiology Associates II, LLP While the threat group behind the attack was not disclosed by MCBS in the data breach notice, the PEAR threat group claimed responsibility for the attack.

PEAR, which stands for Pure Extortion and Ransom, engages in data theft and extortion and does not use ransomware to encrypt files. PEAR claimed to have exfiltrated 3 TB of data in the attack and published the stolen data on its data leak site when the ransom was not paid. The post MCBS Announces Cybersecurity Incident Impacting 1.

26M Individuals appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content