If you received a letter from Medical Computer Business Services (MCBS), your Social Security number, medical records, and health insurance data may be circulating on the dark web. About 1.26 million patients were affected by the PEAR ransomware attack disclosed in June 2026. Freeze your credit today, enroll in the offered monitoring, and remove your address from data broker sites so criminals can't tie the leaked identity data to a current location.
What Happened in the MCBS Breach?
Medical Computer Business Services (MCBS), a Colorado-based medical billing software vendor, disclosed a serious data breach that affected 1,261,464 patients across multiple healthcare providers. According to breach notifications filed with the U.S. Department of Health and Human Services on June 26, 2026, attackers gained unauthorized access to MCBS systems between September 22 and 26, 2025.
The PEAR (Pure Extraction and Ransom) ransomware group claimed responsibility, alleging it exfiltrated roughly 3.3 terabytes of data from MCBS servers. Because MCBS handles billing for many separate practices, patients of clinics they never directly heard of may still be included in the breach.
What Data Was Exposed?
The compromised information is the worst-case combination for identity theft — enough to open credit lines, file fraudulent tax returns, or commit medical identity theft:
- Full names and physical addresses
- Social Security numbers
- Dates of birth
- Health plan beneficiary numbers
- Health insurance policy and subscriber IDs
- Medical histories and diagnosis information
- Mental and physical condition details
- Medical treatment records
Why medical breaches are worse than card breaches
You can cancel a credit card in an hour. You cannot change your Social Security number, birthday, or medical history. Records from breaches like MCBS often resurface on dark web marketplaces years later, powering synthetic identity fraud and targeted phishing long after news cycles move on.
Are You Affected?
MCBS is mailing written notifications to affected individuals — but the letters can take weeks, and many patients don't realize MCBS handles their provider's billing. If you were treated at any hospital or clinic that uses MCBS between 2020 and September 2025, assume you may be affected until you can confirm otherwise. You can also check the HHS Office for Civil Rights breach portal for the latest updates.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Immediate Steps to Take Right Now
1. Freeze your credit at all three bureaus
A credit freeze is free, takes about 15 minutes, and stops criminals from opening new accounts in your name — the single most effective action after an SSN exposure. Freeze at Equifax, Experian, and TransUnion. Consider freezing at ChexSystems too — it screens new checking accounts.
2. Enroll in the free identity protection MCBS is offering
MCBS is providing complimentary access to identity protection services through a third-party provider. Enroll — it's free and typically includes credit monitoring and identity theft insurance. Note the enrollment deadline in your notification letter.
3. Watch for medical identity theft specifically
Because medical records were exposed, criminals can file fraudulent insurance claims or receive treatment under your name — which can corrupt your medical file with someone else's blood type, allergies, or prescriptions. Request an Explanation of Benefits (EOB) from your insurer for every claim and review it. Contest anything unfamiliar within 60 days.
4. File taxes early
SSN exposure enables tax refund fraud. File as early as possible next tax season, and request an IRS Identity Protection PIN (IP PIN) at irs.gov. Without a valid IP PIN, no return can be filed under your SSN.
5. Change passwords on your patient and insurance portals
Even though passwords weren't in the leak, attackers combine leaked details with credential-stuffing attacks. Use unique passwords and turn on two-factor authentication on every healthcare and insurance account.
Remove Your Address From Data Broker Sites
Here is what most breach guides skip: the exposed SSN and DOB in this breach are only actionable to criminals if they can also find your current address, phone number, and family members. Those come from data broker sites like Spokeo, BeenVerified, and Whitepages — 100+ services that sell your personal info for a few dollars a lookup.
Removing yourself from those sites breaks the connection between the leaked identity data and your current life, dramatically reducing your risk of targeted phishing, SIM-swap attacks, and physical stalking. PrivacyOn scans 100+ major data brokers and handles removal for you, then keeps monitoring so your info doesn't reappear.
Why PrivacyOn matters after this breach
PrivacyOn removes your personal information from 100+ data broker sites, includes 24/7 dark web monitoring for your SSN and email, and covers up to 5 family members from $8.33/month. Run a free scan to see where your data is exposed right now — the whole point after a breach like MCBS is to shrink your digital footprint before criminals connect the dots.
Long-Term Protection Steps
- Order your annual credit reports at AnnualCreditReport.com and review for unfamiliar accounts
- Set up transaction alerts on all bank and credit cards for any charge over $1
- Use dark web monitoring to get notified if your SSN, email, or medical record IDs appear in new leaks
- Be skeptical of "MCBS breach settlement" calls — post-breach phishing spikes hard; class-action settlements are announced in writing, never by phone
- Save your notification letter — you may need it as proof of exposure for insurance claims or a future settlement
Frequently Asked Questions
Who is Medical Computer Business Services (MCBS)?
MCBS is a US-based software vendor that provides electronic medical billing and practice-management services to healthcare providers. Because they handle billing for many separate practices, patients whose own doctor's office never had a breach can still be affected if that office used MCBS.
Is there a class action lawsuit for the MCBS data breach?
As of July 2026, multiple law firms have announced investigations into potential class actions over the MCBS breach. If a suit is certified, notice will arrive by mail or from the court's official settlement site — never by phone. Keep your notification letter as proof of standing.
How long will my data be at risk after the MCBS breach?
Indefinitely. Unlike a credit card, you cannot change your SSN, date of birth, or medical history. Leaked identity data typically recirculates on dark web markets for years, which is why long-term monitoring and a shrunken public data footprint matter more than any one-time action.
Should I use the free identity monitoring MCBS is offering?
Yes — take the free service. But understand it only alerts you after fraud has already appeared on credit reports. It does not stop criminals from finding your address, phone, or relatives on data broker sites. Pair it with data broker removal to actually reduce your exposure going forward.
What is the best identity protection after a medical data breach?
The strongest defense is a combination: a permanent credit freeze at all three bureaus, an IRS IP PIN, and continuous data broker removal so your leaked identity data cannot be tied to your current address. PrivacyOn handles the removal and monitoring side for $8.33/month, covering up to 5 people — the missing piece MCBS's free monitoring does not provide.
Can I sue MCBS over the breach?
You may be able to join a class action if one is certified. Individual lawsuits are possible but rarely economical unless you can document actual fraud loss tied to the breach. In the meantime, save all notifications and screenshots of any fraudulent activity — that documentation is what future claims will hinge on.