Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people.
Commenting on this is Rebecca Moody, Head of Data Research at Comparitech:
“This is another prime example of why third-party healthcare companies, like medical billing providers, have become a prime target for ransomware groups. By targeting one entity, they’re gaining access to multiple healthcare providers and their data. Our recent H1 healthcare ransomware report found a 35 percent uptick in attacks on these types of companies (those that specialize within the healthcare sector but don’t provide direct care). This breach becomes the second-largest on a third-party healthcare business following a ransomware attack in the last 18 months.”
The report that was linked is a very good one, and I encourage you to read it if you get a chance.
UPDATE: Additional commentary comes via Seemant Sehgal, Founder & CEO, BreachLock:
“A breach that ran for four days in September 2025 and surfaced in a public disclosure eight months later tells you something about how difficult incident response and forensic review are in environments that handle data across multiple providers simultaneously. The data types here, Social Security numbers, insurance details, medical information, are the combination that makes downstream fraud viable for years, which means the harm timeline for affected individuals extends well beyond the notification date. Eight months is a long time for that data to be in motion before patients knew to watch for it.”
John Strand, Owner, Black Hills Information Security, Inc.:
“One of the things I absolutely hate about stories like this is that the default response is almost always complimentary identity protection services. Yes, those services can detect some types of fraud, but they don’t come close to addressing the full range of risks created by a data breach. They have value, but they’re far from a complete solution.
“I’ve started calling this the information security equivalent of thoughts and prayers. It’s the absolute bare minimum a company can offer after a breach without making meaningful changes to improve security or reduce future risk. The reality is that only a fraction of affected people will ever enroll in those services, and even those who do aren’t protected against every way their information can be abused. It’s frustrating because organizations can suffer a major breach, offer a year of identity protection, and too often that’s treated as an adequate response instead of a starting point for real accountability.”
Damon Small, Board of Directors, Xcape, Inc.:
“Third-party healthcare billing breaches create massive regulatory exposure and systemic supply chain liability when basic detection and response controls fail. The intrusion at Medical Business Office Systems, known as MCBS, allowed attackers to dwell for days and exfiltrate over three terabytes of sensitive patient and insurance data undetected, exposing non-existent data loss prevention and egress monitoring capabilities.
“Furthermore, an eight-month delay before patient notification, justified by waiting for internal investigation completion, highlights severely flawed incident response processes. Security leaders must mandate continuous network egress monitoring, enforce strict data loss controls on revenue cycle aggregators, and require business associates to report material intrusions within days rather than waiting for post-forensic completion.
“Critical Takeaways
- Monitor large-scale data egress: Deploy continuous network monitoring and data loss prevention tools to detect abnormal outbound traffic before terabytes leave the perimeter.
- Accelerate incident response SLAs: Mandate that third-party vendors establish tight notification timelines rather than withholding breach disclosures for months while conducting internal reviews.
- Enforce vendor risk accountability: Require revenue cycle partners to submit to regular security telemetry audits and maintain strict field-level data controls for sensitive patient records.
“If it takes eight months to realize three terabytes of patient data walked out the door, your incident response plan is a post-mortem, not a defense.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“MCBS had a regulatory shortcut available that would have made this entire disclosure unnecessary. The Health Insurance Portability and Accountability Act (HIPAA) includes a breach notification safe harbor for properly encrypted data, meaning if those 1.26 million Social Security numbers had been encrypted at the field level, the stolen files would have been useless ciphertext and the breach wouldn’t have triggered notification requirements. The encryption was always the cheapest fix. MCBS chose not to implement it when the rule calls encryption “addressable” rather than mandatory.
“The Department of Health and Human Services proposed eliminating that flexibility in January 2025, making AES-256 encryption at rest mandatory for all electronic protected health information. That rule hasn’t been finalized, and final action has been pushed to July 2027. Encryption remains “addressable” today, and every healthcare billing company that reads “addressable” as “optional” is sitting on the same exposure MCBS had.
“Credit monitoring as a remedy tells you what the breach responders think the threat model is, and they’re thinking too narrowly. PEAR (Pure Extraction and Ransom) exfiltrated 3.3 terabytes from MCBS, including medical histories, mental health conditions, and diagnosis information. That data enables targeted blackmail, insurance manipulation, and employment discrimination. A credit freeze catches none of it.
“Under the EU’s General Data Protection Regulation (GDPR) Article 82, affected individuals can claim compensation directly from the company that lost their data. The US gives 1.26 million people a year of free credit monitoring instead. A $4 trillion industry can afford field-level encryption, and it can afford direct liability to patients when it skips it.”
July Ransomware Attacks: Up 19% from June Says Comparitech
Posted in Commentary with tags Comparitech on August 5, 2026 by itnerdWith ransomware attacks plaguing businesses and individuals around the world, Comparitech have released their Ransomware Roundup for July 2026, finding that last month saw nearly 26 ransomware attacks per day.
The research looks into attacks by sector, most prolific groups and attacks by country.
Key findings include:
You can find the full research here: https://www.comparitech.com/news/ransomware-roundup-july-2026/
Commenting on this is Rebecca Moody, Head of Data Research at Comparitech:
“If we needed a reminder of how dominant a threat ransomware attacks remain, July’s figures provide us with just that. Figures reached the third-highest level in the last 17 months and The Gentlemen and Qilin continued to add hundreds of victims to their data-leak sites. We’ve already logged over 100 victims during the first four days of August 2026, too.
July also saw some of the year’s most significant ransomware attacks. This includes the attack on the Romanian government’s land registry agency, which saw an entire database being wiped, the crippling attacks on AnMed and Fairlife in the US, and the attack on The Craneware Group, which looks set to have resulted in an extensive data breach.
These attacks highlight how ransomware groups hit organisations in various different ways — taking down key systems, stealing troves of data, and even deleting massive datasets. Never has it been more important for organisations to ensure they’re carrying out regular backups (and backups of their backups!) so they can reset systems and restore data as quickly as possible if the worst does happen.”
I would put aside some time to give this a read as it will help you to structure your defenses.
Leave a comment »