A breach at a medical billing vendor becomes a multi-provider exposure because the vendor sits between healthcare organizations and the records it processes. The standard response would treat this as one company’s incident; the real blast radius is the downstream patient, insurance, and business data now tied to seven clients and more than 1.26 million people.
MCBS says attackers had access to its systems from September 22 to September 26, 2025. Public reporting and HHS’s breach tracker put the impact at 1,261,464 individuals, and MCBS’s notice names seven healthcare organizations whose data was compromised. The data described includes names, addresses, SSNs, dates of birth, health insurance information, and medical information.
PEAR also claimed theft of more than 3 TB and said the haul included patient PII and PHI, payment details, and business records. That makes the vendor the concentration point for records that span multiple customers, so the breach reaches far beyond MCBS’s own network.