The MCBS 2025 data breach was an unauthorized-access incident in the network of MCBS, LLC, a billing and practice-management vendor for healthcare organizations, from September 22 through September 26, 2025. The company detected the activity around September 25 and secured the network. The current record maintained by the US Department of Health and Human Services Office for Civil Rights shows that 1,261,464 people were affected.
MCBS is not a healthcare provider but a business associate that processes patient information for customers. The incident therefore involved personal and protected health information connected with seven healthcare organizations. Contents varied by person; LeakData imports no stolen records and importedRecordCount is zero.
How Was the Breach Confirmed?
MCBS confirmed in its own public notice that its network experienced unauthorized access. A forensic investigation conducted with cybersecurity specialists determined that an unauthorized user was present in systems between September 22 and September 26. This confirmed network compromise was reported in the federal HHS portal as a Hacking/IT Incident involving a Network Server.
The company said some files may have been accessed or removed; it did not state that exfiltration was a definitive finding. This record therefore confirms a genuine, reported breach without presenting data theft as certain. HIPAA Journal likewise reports the same forensic window and possible acquisition of information.
What Was the Incident and Review Timeline?
The breachDate field uses September 22, 2025, the beginning of the access window established by the forensic review. MCBS detected unauthorized activity around September 25, contained the event, and opened an investigation; the window ended on September 26. The detection date is not substituted for the earlier start date.
The company manually reviewed potentially affected files and determined on May 28, 2026 that they may have contained personal and health information. The event was submitted to HHS OCR on June 26, 2026 and later appeared on the federal list with a scope of 1,261,464 people. The lengthy review reflects the work of matching files from different customers to people and data fields.
What Identity and Insurance Information Was Affected?
The disclosed identity fields were names, physical addresses, dates of birth, and Social security numbers. Health-plan beneficiary numbers, health-insurance policy numbers or subscriber identification numbers, and other insurance information were also potentially involved. Because not every victim had every field, dataClasses does not guarantee the contents of any individual's file.
Social security numbers and birth dates are long-lived identifiers, and their combination with insurance identifiers may increase the risk of new-account fraud, false medical claims, or targeted phishing. The company said it had no evidence of identity theft related to the incident. An absence of detected misuse does not mean that exposure creates no future risk.
What Medical Information Was Potentially Involved?
The medical data classes were medical histories, mental or physical conditions, medical treatment information, and diagnosis information. These categories can expose sensitive context about both past care and an ongoing health condition. The sources do not separately confirm laboratory results, prescriptions, images, or medical record numbers, so those fields are not inferred and added.
MCBS performs billing and management services for healthcare providers. That role explains why identity and insurance fields could appear in the same file set as clinical information. HHS classifies the company as a Business Associate; the affected covered entities are not presented as if each experienced a separate attack.
How Should the 1,261,464-Person Scope Be Read?
pwnCount and totalRecords use the federal total of 1,261,464 people in the current HHS OCR public row. MCBS's initial public notice did not state a count, and the HIPAA Journal report in early July said the total was not yet known. The regulator's subsequently published number is the verified current figure that replaces that earlier uncertainty in this entry.
The company lists C&C MD PC, Nuclear Medicine and Pathology Associates, Radiation Oncology Associates, SkinPath Solutions, South Georgia Radiology Consultants, Stephen W. Brown & Radiology Associates of Augusta, and Vascular Radiology Associates II as covered entities. The federal total is not redistributed among them, counted seven times, or split into invented subtotals.
What Should Affected People Do?
In its public notice, MCBS advised people to review financial-account activity regularly and consider a complimentary one-year fraud alert or a security freeze. HIPAA Journal reported that affected people were offered 12 months of credit monitoring and identity-theft protection. Notice recipients should follow the enrollment route and specific scope stated in their letter.
In addition to credit reports, people should inspect health-insurance explanations for unfamiliar services, providers, or claims. Unexpected payment or identity-verification requests made in the name of MCBS or an associated provider should be checked through a known official channel. LeakData publishes no personal, medical, or insurance data; it documents only verified incident metadata.