MCBS Discloses 2025 Data Breach Affecting 1M Patients
Medical Computer Business Services (MCBS), a medical billing firm, has disclosed a 2025 data breach affecting over 1 million patients, per HHS filings. The intrusion occurred over four days in September 2025 but was only acknowledged recently, almost a year later. A ransomware group called PEAR has taken credit, and a 3.3 TB trove of stolen data is now openly downloadable from the dark web. Exposed data includes names, addresses, dates of birth, health plan policy numbers, and detailed medical histories. Affected providers include C&C MD PC, Nuclear Medicine and Pathology Associates, and Radiation Oncology Associates, among others.
The case illustrates the vendor-driven exposure that now dominates healthcare breach headlines. A single billing intermediary becomes a concentration point for the most sensitive PHI, and one intrusion cascades into notification obligations for every covered entity it serves. The nine-month gap between compromise and disclosure is also representative: without deep forensic visibility into those four days in September, investigators had to reconstruct scope after the fact while attackers had already staged and exfiltrated 3.3 TB. By disclosure, the data was already public.
Closing that gap is where an AI-native and agentic SOC model matters. Traditional detection depends on analysts pivoting across disconnected tools to piece together what happened; an agentic approach turns the same investigative logic into AI-driven workflows that continuously mine full-fidelity evidence against a single retained record. When an alert lands, the questions that used to take weeks — what was accessed, by whom, and how much left the network — can be answered quickly because the evidence was already indexed and correlated. Platforms like NIKSUN — with a unified data lake that agentic analytics can query directly — give healthcare vendors the ability to discover and block the attack before it perpetrates. Read more about this story on our LinkedIn page
We use cookies to offer you a better browsing experience and to analyze site traffic. By using our site, you consent to our use of cookies.
Essential Cookies
Site Analytics
Essential Cookies
These cookies are necessary for certain areas of the site to function. They are used for access to secure areas of the website and to help us comply with legal requirements like GDPR.
Site Analytics
These cookies are used to collect information about how users use our site. We use these to improve how our website works.