Summary
- Environment: Date MCBS says it learned that an unauthorized individual may have gained access to its network.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
Personal and health information in files MCBS obtained from covered entities for medical billing services. [4][5][6]
Documented data types include:
- Health insurance information [4]
- Clinical information — Texas lists medical information and Massachusetts marks medical records as breached. [4]
- Dates of birth [4]
- Contact information — Texas’s report lists addresses among the affected personal-information types. [4]
- Social Security numbers — Texas and Massachusetts regulator reports mark Social Security numbers as breached. [4]
- Names [4]
A cited record reports 1,261,464 individuals (Individuals in the HHS OCR incident report; regulator-reported and not independently verified; as of 2026-08-08). [4][5][6]
A cited record reports 13,302 individuals (Texas residents affected according to Texas Attorney General report BR-0005146; not a national total; as of 2026-06-30). [4][5][6]
A cited record reports 1,241,154 individuals (Total individuals affected according to Texas Attorney General report BR-0005146; regulator-reported and not independently verified. This differs from the HHS OCR count and is retained separately; as of 2026-06-30). [4][5][6]
A cited record reports 383 individuals (Massachusetts residents affected according to incident report 2026-1037; not a national total; as of 2026-06-26). [4][5][6]
At the time of notice, MCBS said it was not aware of misuse or fraudulent activity relating to personal or health information as a result of the incident. [1]
MCBS said an unauthorized individual may have gained access to its network; it did not identify the person or access method in the notices reviewed. [1]
Timeline
Activity began
Approximate start of the unauthorized-acquisition interval identified by MCBS.
[3]Discovery
Date MCBS says it learned that an unauthorized individual may have gained access to its network.
[1]Documented activity ended
Approximate end of the unauthorized-acquisition interval identified by MCBS.
[3]Documented event
Date MCBS says its forensic investigation and document review determined that files containing personal information may have been subject to unauthorized acquisition.
[1]Public disclosure
Date reported to Massachusetts OCA and HHS OCR; the redacted sample letters do not expose an addressee-specific mailing date.
[5]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
The Massachusetts notice offered 24 months of complimentary identity-protection services as a precaution. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]
