MCBS network data incident

Unauthorized access to MCBS's network and potential unauthorized acquisition of files used for medical billing services. Personal and health information in files MCBS obtained from covered entities for medical billing services.

Last modified

Summary

  • Environment: Date MCBS says it learned that an unauthorized individual may have gained access to its network.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to MCBS’s network and potential unauthorized acquisition of files used for medical billing services. [1][3]

Impact

Personal and health information in files MCBS obtained from covered entities for medical billing services. [4][5][6]

Documented data types include:

  • Health insurance information [4]
  • Clinical information — Texas lists medical information and Massachusetts marks medical records as breached. [4]
  • Dates of birth [4]
  • Contact information — Texas’s report lists addresses among the affected personal-information types. [4]
  • Social Security numbers — Texas and Massachusetts regulator reports mark Social Security numbers as breached. [4]
  • Names [4]

A cited record reports 1,261,464 individuals (Individuals in the HHS OCR incident report; regulator-reported and not independently verified; as of 2026-08-08). [4][5][6]

A cited record reports 13,302 individuals (Texas residents affected according to Texas Attorney General report BR-0005146; not a national total; as of 2026-06-30). [4][5][6]

A cited record reports 1,241,154 individuals (Total individuals affected according to Texas Attorney General report BR-0005146; regulator-reported and not independently verified. This differs from the HHS OCR count and is retained separately; as of 2026-06-30). [4][5][6]

A cited record reports 383 individuals (Massachusetts residents affected according to incident report 2026-1037; not a national total; as of 2026-06-26). [4][5][6]

At the time of notice, MCBS said it was not aware of misuse or fraudulent activity relating to personal or health information as a result of the incident. [1]

MCBS said an unauthorized individual may have gained access to its network; it did not identify the person or access method in the notices reviewed. [1]

Timeline

  1. Activity began

    Approximate start of the unauthorized-acquisition interval identified by MCBS.

    [3]
  2. Discovery

    Date MCBS says it learned that an unauthorized individual may have gained access to its network.

    [1]
  3. Documented activity ended

    Approximate end of the unauthorized-acquisition interval identified by MCBS.

    [3]
  4. Documented event

    Date MCBS says its forensic investigation and document review determined that files containing personal information may have been subject to unauthorized acquisition.

    [1]
  5. Public disclosure

    Date reported to Massachusetts OCA and HHS OCR; the redacted sample letters do not expose an addressee-specific mailing date.

    [5]
  6. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The Massachusetts notice offered 24 months of complimentary identity-protection services as a precaution. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]