Medical Computer Business Services (MCBS), a medical practice management and billing company, filed a breach notification confirming 1,261,464 individuals were affected when the PEAR ransomware group hit its systems — with data from seven separate healthcare organizations that MCBS served compromised in a single attack.
PEAR Ransomware Claims 3 TB Stolen From MCBS’s Seven Healthcare Clients
PEAR ransomware operators asserted they stole more than 3 TB of files from MCBS systems, including partner and vendor data. The group claimed responsibility for the attack and has listed the incident among its victims on its dark web leak site. PEAR emerged in mid-2025 and has listed over 100 alleged victims, with a documented focus on healthcare and medical services sector targets. The MCBS attack fits that targeting pattern: medical billing and practice management firms aggregate patient records across multiple downstream clients, creating a concentrated data repository that amplifies the breach impact beyond any single provider.
How MCBS’s Billing Intermediary Role Exposed Seven Healthcare Organizations in One Attack
MCBS’s function as a medical practice management and billing firm meant that patient records from seven distinct healthcare organizations resided in its systems at the time of the attack. A ransomware breach of a billing intermediary propagates across every covered entity it serves simultaneously. The 1,261,464 individuals formally notified represent patients of those seven healthcare organizations, none of whom were individually breached — their data was exposed because their healthcare providers used MCBS for billing and records management. The breach notification does not identify the seven healthcare organizations by name.
Patient PII, PHI, HR Documents, and Financial Records Among the Stolen Data Categories
MCBS’s notification filing disclosed a broad set of compromised data categories: patient names, addresses, Social Security numbers, dates of birth, health insurance information, medical records, and patient personally identifiable and protected health information. Administrative records were also taken, including company and client financial documents, human resources documents, payment details, and email communications. The inclusion of HR documents and internal financial records alongside patient PHI indicates MCBS’s attackers accessed systems beyond clinical record storage, moving laterally into administrative infrastructure.
Ten Months Between the September 2025 Breach and the July 2026 Notification
MCBS’s notification filing states the ransomware attack occurred September 22-26, 2025, with public disclosure arriving approximately ten months later. HIPAA’s breach notification rule requires covered entities to notify affected individuals within 60 days of discovering a breach, and requires business associates — vendors like MCBS that handle protected health information on behalf of covered entities — to notify the covered entities they serve promptly after discovering a breach, so those entities can meet their own notification obligations.
A ten-month gap between discovery and public notification is at the outer limit of this framework and raises questions about when MCBS notified the seven healthcare organizations it served, since those organizations’ own HIPAA notification obligations depend on receiving timely notice from their business associate. MCBS did not disclose the initial access vector or technical details of the attack in its notification filing, leaving the full attack chain undocumented in the public record. PEAR’s ability to exfiltrate more than 3 TB before detection was confirmed also suggests the group had sustained access to MCBS systems during the September 2025 intrusion window, though the duration of that access was not specified in the filing. PEAR’s claim of more than 3 TB removed from a single billing intermediary — encompassing records from seven distinct healthcare organizations — points to attackers traversing multiple storage systems and archives rather than conducting a targeted extraction from one database. Had MCBS failed to promptly notify the covered healthcare entities it served upon discovering the breach, those organizations would have had no basis to start their own 60-day HIPAA patient notification clocks, compressing the time available to warn affected individuals about the exposure of their medical records.
