[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feCP6MAiN0sGqFWvdZfedBxD4_Ukqt2W4NFacWVfzRWo":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":32,"source":33,"isVerified":4,"isSpamList":34,"isSensitive":4,"processingStatus":35,"logoUrl":36,"contentUpdatedAt":16,"hasEnglishDescription":4,"severity":37},"6a674ee1ee1e4546c1f285b8","MidMichiganMedicalBilling2025","Mid Michigan Medical Billing Service 2025 Data Breach","mid-michigan-medical-billing-2025","mmmbs.net",{"name":12,"sector":13,"country":14,"website":10},"Mid Michigan Medical Billing Service","Healthcare","United States","2025-03-27T00:00:00.000Z","2026-07-27T12:28:17.925Z",28185,[19,20,21,22,23,24,25,26,27,28,29,30,31],"Names","Dates of birth","Driver’s license or government-issued identification numbers","Medicare or Medicaid identification numbers","Diagnosis and treatment information","Medical record or patient account numbers","Health insurance information","Payment card numbers","Employer identification numbers","Passport numbers","Treating or referring provider names","Biometric data","Social Security numbers in limited circumstances","\u003Cp>\u003Cstrong>The Mid Michigan Medical Billing Service 2025 data breach\u003C\u002Fstrong> involved the revenue-cycle and billing support company determining that an unknown person accessed its IT network March 27, 2025 and copied and potentially viewed files. The affected information consisted of patient and administrative data MMMBS had received from healthcare business partners.\u003C\u002Fp>\n\u003Cp>The official HHS Office for Civil Rights breach portal reports 28,185 affected people and classifies the event as a network-server hacking\u002FIT incident. pwnCount and totalRecords carry that verified public population. importedRecordCount is zero because no person-level file or account was transferred into LeakData.\u003C\u002Fp>\n\u003Ch2>How Was the Mid Michigan Medical Billing Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is MMMBS's Cyber Security Event notice dated January 2, 2026. It confirms March 27, 2025 network access, copying and potential viewing of files, completion of data review around December 2, 2025, affected categories, federal law-enforcement and regulator notification, and the assistance line at 833-303-3875.\u003C\u002Fp>\n\u003Cp>The second source is the official HHS\u002FOCR row dated January 5, 2026, which lists 28,185 people, business associate, hacking\u002FIT incident, and network server. ClaimDepot preserves a document copy and HHS link after the provider page began returning 404. Its secondary actor and ransom claims are excluded because they are absent from the provider notice.\u003C\u002Fp>\n\u003Ch2>What Happened on March 27, 2025?\u003C\u002Fh2>\n\u003Cp>MMMBS became aware of suspicious activity in its IT network, took systems offline, and opened an investigation. The investigation determined that an unknown person entered the network March 27 and that files were copied and potentially viewed. The company conducted a detailed review to identify the information and people associated with the accessed files.\u003C\u002Fp>\n\u003Cp>The data review finished around December 2, 2025. MMMBS notified the associated business partners and worked with them to provide notice to potentially affected people. The public document does not disclose the initial-entry method, account or vulnerability used, exact duration of access, or threat-actor identity.\u003C\u002Fp>\n\u003Ch2>What Identity and Financial Information Was Involved?\u003C\u002Fh2>\n\u003Cp>Fields that varied by person and MMMBS client were names, dates of birth, driver's license or government-issued identification numbers, passport numbers, employer identification numbers, and biometric data. Payment card numbers were also involved. Social Security numbers were present only in limited circumstances.\u003C\u002Fp>\n\u003Cp>Identity and financial fields can increase impersonation, new-account, payment, and targeted-phishing risk. “Biometric data” appears as a broad category in the provider notice; this entry does not infer an unreported subtype such as a face template or fingerprint. A recipient with card data involved can inspect transactions through a known bank channel.\u003C\u002Fp>\n\u003Ch2>What Health and Insurance Information Was Involved?\u003C\u002Fh2>\n\u003Cp>Health fields were Medicare or Medicaid identification numbers, diagnosis and treatment information, medical record numbers, patient account numbers, health-insurance information, and treating or referring provider names. These categories can expose medical-billing and provider context.\u003C\u002Fp>\n\u003Cp>Notice recipients can inspect explanations of benefits, patient and insurance-account activity, unfamiliar treatment or providers, and unexpected billing messages. Even a communication containing a real medical record, account, or provider name is not automatically legitimate; verify it separately using a known healthcare or insurance channel.\u003C\u002Fp>\n\u003Ch2>How Should the 28,185 Figure Be Interpreted?\u003C\u002Fh2>\n\u003Cp>The 28,185 figure is the affected population reported to HHS\u002FOCR and is the current official public total. It is not an asserted volume of files copied from the MMMBS network or a number of searchable accounts or rows loaded into LeakData. pwnCount and totalRecords are 28,185, while importedRecordCount is zero.\u003C\u002Fp>\n\u003Cp>Because MMMBS is a business associate, the information may relate to several healthcare-provider clients. Any future client or state subtotals must not be added again to the nationwide HHS figure. Even if the same event appears in notices from different providers, a second duplicate entry is not created for the central MMMBS incident.\u003C\u002Fp>\n\u003Ch2>How Did MMMBS Respond and What Should Recipients Do?\u003C\u002Fh2>\n\u003Cp>MMMBS said it responded to the activity, assessed and secured the network, notified associated entities and individuals, reviewed existing policies and procedures, and enhanced security measures. It notified federal law enforcement and regulators. The 833-303-3875 assistance line is listed for weekdays from 8:00 a.m. to 8:00 p.m. Eastern.\u003C\u002Fp>\n\u003Cp>Based on fields in their own letter, a recipient can consider a credit freeze and fraud alert for an SSN or government ID, transaction review for a payment card, and benefits and patient-record review for health information. Do not share a password, full SSN, payment, or one-time code in an unexpected message using the MMMBS, provider, or insurer name.\u003C\u002Fp>","MMMBS Cyber Security Event notice, HHS\u002FOCR report, and source-linked document copy",false,"completed","\u002Fuploads\u002Flogo\u002Fmmmbs_net.jpg","Medium"]