A cyberattack on Medical Computer Business Services, a third-party vendor serving healthcare organizations, may have exposed the personal and medical information of 1,261,464 people in the United States.
Breach tied to healthcare services vendor
The incident appears on the U.S. Department of Health and Human Services Office for Civil Rights breach portal as a hacking and IT incident. According to the company, attackers gained access to the MCBS computer network, affecting data tied to hospitals, private practices and medical groups that rely on the vendor for administrative, financial and other back-office services.
MCBS functions as a business associate for healthcare providers, meaning it handles records and operational tasks on behalf of outside medical organizations. That role can place large volumes of patient and insurance-related information in one system, increasing the scale of exposure when a breach occurs.
Timeline of the intrusion
MCBS said it first learned of unauthorized access to its systems in September 2025 and began an investigation immediately. The company said it worked with outside cybersecurity specialists during a forensic review of the incident.
According to its notice, the review later determined that certain files containing personal information may have been acquired without authorization during a window between about September 22, 2025 and September 26, 2025. MCBS said it discovered on or about May 28, 2026 that those files may have been subject to unauthorized acquisition.
What information may have been exposed
The company said the compromised files may have contained a wide range of sensitive information. Depending on the individual, that data may include names, addresses, Social Security numbers, dates of birth, health plan beneficiary numbers, health insurance policy numbers or subscriber identification numbers, as well as other medical records.
The combination of identity details, insurance information and health-related records makes the incident particularly significant, although MCBS said the exact data elements involved can vary from person to person.
Response and current status
MCBS said it notified affected individuals after completing its review and is offering complimentary identity protection services as a precaution. The company also said it has not, at this time, identified misuse of affected individuals’ personal or health information.
That statement does not rule out future harm, but it indicates the company says it has not yet observed evidence that the exposed information has been used improperly. The reported total of 1,261,464 affected people makes the breach one of the larger healthcare-related data exposure events disclosed through federal reporting channels.
Healthcare breaches involving outside vendors continue to draw scrutiny because a single incident can affect multiple providers and patient populations at once. In this case, the available disclosures point to a late-September 2025 intrusion that was later tied to files potentially containing highly sensitive personal and insurance data, with notifications and protective services following after the company’s investigation.
Source: dailyhodl.com