# Your Healthcare Provider's Billing Company Got Hacked. Your SSN Has Been Online for Months.
When MCBS sent breach notifications this week, the letter told 1.2 million Americans something they had a right to know back in October 2025.
The Atlanta-based medical revenue cycle management firm was breached on September 22, 2026. Attackers had four days inside the network before being evicted on September 26. By late that month, the PEAR ransomware group had already posted a claim on their leak site, announcing they'd walked out with over 3 terabytes of files — patient PII, Social Security numbers, dates of birth, health insurance details, payment records, and clinical information from at least seven healthcare organizations that trusted MCBS to handle their billing.
That data is not "potentially at risk." It has been available for download since roughly October 2025. The breach notification, filed with HHS and posted to MCBS's website, arrives nearly ten months after the theft.
## The Billing Company Problem
Revenue cycle management sits at one of healthcare's worst attack surfaces: it holds both financial and clinical data, it connects to multiple provider organizations simultaneously, and it's treated as back-office infrastructure rather than a primary security priority. A hospital might spend millions hardening its EHR. Its billing vendor runs a different calculus.
That's the multiplier PEAR exploited. One successful intrusion at MCBS yielded data from seven separate healthcare organizations. The attackers didn't need to breach a hospital — they breached the company the hospital outsourced its sensitive work to. This is the same logic behind attacks on Change Healthcare (February 2024), which disrupted claims processing across the country, and the broader wave of third-party medical billing breaches that have dominated HHS's breach tracker for two consecutive years.
MCBS's notification lists exactly what was taken: names, addresses, Social Security numbers, dates of birth, health insurance information, and medical information. For identity theft purposes, that's a complete package. SSN plus DOB plus medical context enables fraudulent insurance claims — a category of fraud that's harder to detect and slower to surface than financial account takeover.
## A Ransomware Group on a Healthcare Run
PEAR emerged in mid-2025 and has wasted no time. Their leak site currently lists over 100 claimed victims, and their pattern skews heavily toward healthcare and adjacent industries. Before MCBS, they claimed Motility Software Solutions (766,000 individuals affected) and Tri-Century Eye Care (200,000 individuals). Three healthcare-adjacent targets, over two million people total, in under a year of operation.
That's not coincidence. Healthcare organizations consistently rank among the slowest to patch, the most likely to pay ransoms to restore clinical operations, and the least likely to have mature incident detection. PEAR appears to understand that. Their operational tempo — targeting billing and software vendors rather than hospitals directly — suggests a deliberate strategy of hitting the connective tissue of healthcare infrastructure where security investment is lowest and data density is highest.
Unlike some ransomware groups that primarily encrypt and extort, PEAR is a full data exfiltration operation. They steal first, threaten second, and publish when payment doesn't materialize. The MCBS data being publicly downloadable is the outcome of that playbook running to completion.
## What Nearly Ten Months of Silence Costs
HIPAA's Breach Notification Rule requires covered entities and their business associates to notify affected individuals without unreasonable delay and no later than 60 days following discovery of a breach. The MCBS attack was discovered in September 2025. Notifications appear to be going out in late July 2026.
There will be regulatory scrutiny of that timeline. But for the 1.2 million people whose records are involved, the timeline problem is more immediate: they've had no reason to monitor their credit, freeze their Social Security numbers, or check for fraudulent insurance claims during the window when their data was most actively being exploited.
Identity thieves don't wait for breach notifications. They work the data while it's fresh.
## What Defenders Should Do
For healthcare organizations using third-party revenue cycle or billing vendors, this is the checklist that matters right now:
For individuals receiving an MCBS notification: freeze your credit at all three bureaus immediately, file a report with the FTC, and call your insurance provider to flag your account for suspicious claims activity. Do not wait.
---
## HackWire Analysis
The MCBS breach is a case study in what happens when healthcare's third-party vendor risk isn't taken seriously — and when breach notification timelines become de facto cover for organizations to quietly contain the reputational damage before the public knows.
The ten-month gap is the story that's getting less attention than it deserves. PEAR published their claim in September 2025. Security researchers and threat intelligence teams tracking ransomware groups almost certainly flagged the MCBS listing within days. Healthcare IT administrators who monitor threat actor leak sites — a basic threat intelligence practice — had months to alert their leadership, review vendor access, and warn patients. The question isn't just whether MCBS failed; it's whether the downstream healthcare organizations whose patient data was compromised were watching.
The deeper pattern here is structural. The Change Healthcare attack exposed how catastrophically the healthcare sector depends on centralized billing infrastructure. MCBS is a smaller-scale version of the same problem: a single vendor, with access to the records of seven organizations and over a million patients, with security posture insufficient to stop a ransomware group that didn't even exist a year ago.
PEAR's healthcare focus is worth tracking carefully. Groups that find a productive vertical tend to stay in it. Their victim count is growing faster than most new ransomware operations at comparable stages, and their willingness to publish data signals they're not primarily an extortion-first operation — they're building a data broker model alongside the ransomware playbook. That's a different risk profile than a group that encrypts and negotiates quietly.
Healthcare CISOs who've been focused on EHR security and clinical device hardening should be asking hard questions about every vendor in their revenue cycle chain right now. The attackers already are.
— HackWire Editorial
---
*Healthcare providers should review their vendor security posture and third-party data sharing agreements — for health information resources, visit [VitaGuia](https://vitaguia.com) or [Lake Nona Medical Services](https://nonamedicalservices.com).*
---
## Related Coverage