---
title: "MCBS network data incident"
description: "Evidence-backed account of MCBS network data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/mcbs-network-data-incident-2025"
markdown_url: "https://www.ally.security/incidents/mcbs-network-data-incident-2025.md"
stix_url: "https://www.ally.security/incidents/mcbs-network-data-incident-2025/stix.json"
---

# MCBS network data incident

Unauthorized access to MCBS's network and potential unauthorized acquisition of files used for medical billing services. Personal and health information in files MCBS obtained from covered entities for medical billing services.

Last modified Aug 9, 2026 · 6 sources

## Summary

- **Environment:** Date MCBS says it learned that an unauthorized individual may have gained access to its network.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to [MCBS](https://www.mcbs.com/)'s network and potential unauthorized acquisition of files used for medical billing services. [1](#source-1) [3](#source-3)

## Impact

Personal and health information in files MCBS obtained from covered entities for medical billing services. [4](#source-4) [5](#source-5) [6](#source-6)

Documented data types include:

- Health insurance information [4](#source-4)
- Clinical information — Texas lists medical information and Massachusetts marks medical records as breached. [4](#source-4)
- Dates of birth [4](#source-4)
- Contact information — Texas's report lists addresses among the affected personal-information types. [4](#source-4)
- Social Security numbers — Texas and Massachusetts regulator reports mark Social Security numbers as breached. [4](#source-4)
- Names [4](#source-4)

A cited record reports 1,261,464 individuals (Individuals in the HHS OCR incident report; regulator-reported and not independently verified; as of 2026-08-08). [4](#source-4) [5](#source-5) [6](#source-6)

A cited record reports 13,302 individuals (Texas residents affected according to Texas Attorney General report BR-0005146; not a national total; as of 2026-06-30). [4](#source-4) [5](#source-5) [6](#source-6)

A cited record reports 1,241,154 individuals (Total individuals affected according to Texas Attorney General report BR-0005146; regulator-reported and not independently verified. This differs from the HHS OCR count and is retained separately; as of 2026-06-30). [4](#source-4) [5](#source-5) [6](#source-6)

A cited record reports 383 individuals (Massachusetts residents affected according to incident report 2026-1037; not a national total; as of 2026-06-26). [4](#source-4) [5](#source-5) [6](#source-6)

At the time of notice, MCBS said it was not aware of misuse or fraudulent activity relating to personal or health information as a result of the incident. [1](#source-1)

MCBS said an unauthorized individual may have gained access to its network; it did not identify the person or access method in the notices reviewed. [1](#source-1)

## Timeline

### September 22, 2025 — Activity began

Approximate start of the unauthorized-acquisition interval identified by MCBS. [3](#source-3)

### September 25, 2025 — Discovery

Date MCBS says it learned that an unauthorized individual may have gained access to its network. [1](#source-1)

### September 26, 2025 — Documented activity ended

Approximate end of the unauthorized-acquisition interval identified by MCBS. [3](#source-3)

### May 28, 2026 — Documented event

Date MCBS says its forensic investigation and document review determined that files containing personal information may have been subject to unauthorized acquisition. [1](#source-1)

### June 26, 2026 — Public disclosure

Date reported to Massachusetts OCA and HHS OCR; the redacted sample letters do not expose an addressee-specific mailing date. [5](#source-5)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

The Massachusetts notice offered 24 months of complimentary identity-protection services as a precaution. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/mcbs-network-data-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### MCBS notice of data incident — California sample

official · MCBS, LLC

<https://oag.ca.gov/system/files/MCBS%20L1%20Adult%20CM%20Redacted%20for%20State%20AG%20Notice%2838517914.1%29%2839005181.2%29.pdf>

<a id="source-2"></a>

### MCBS notice of data incident — Massachusetts filing

official · MCBS, LLC

<https://www.mass.gov/doc/2026-1037-mcbs-llc/download>

<a id="source-3"></a>

### Submitted breach notification sample — MCBS, LLC

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-625528>

<a id="source-4"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-5"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<a id="source-6"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Discovered At · 100% confidence · current**  
   September 2025 MCBS network incident: 2025-09-25
2. **Exposed Data Category · 100% confidence · current**  
   MCBS medical-billing data exposure: Health insurance information
3. **Exposed Data Category · 100% confidence · current**  
   MCBS medical-billing data exposure: Clinical information
4. **Affected Individual Count · 100% confidence · current**  
   MCBS medical-billing data exposure: 1,261,464 individual
5. **Ended At · 100% confidence · current**  
   September 2025 MCBS network incident: 2025-09-26
6. **Occurred At · 100% confidence · current**  
   MCBS medical-billing data exposure: 2026-05-28
7. **Affected Individual Count · 100% confidence · current**  
   MCBS medical-billing data exposure: 13,302 individual
8. **Exposed Data Category · 100% confidence · current**  
   MCBS medical-billing data exposure: Dates of birth
9. **Affected Organization · 100% confidence · current**  
   September 2025 MCBS network incident: MCBS, LLC
10. **Resulted In · 100% confidence · current**  
   September 2025 MCBS network incident: MCBS affected-individual notification
11. **Resulted In · 100% confidence · current**  
   MCBS affected-individual notification: At the time of notice, MCBS said it was not aware of misuse or fraudulent activity relating to personal or health information as a result of the incident.
12. **Exposed Data Category · 100% confidence · current**  
   MCBS medical-billing data exposure: Contact information
13. **Affected Individual Count · 100% confidence · current**  
   MCBS medical-billing data exposure: 1,241,154 individual
14. **Resulted In · 100% confidence · current**  
   September 2025 MCBS network incident: MCBS medical-billing data exposure
15. **Began At · 100% confidence · current**  
   September 2025 MCBS network incident: 2025-09-22
16. **Exposed Data Category · 100% confidence · current**  
   MCBS medical-billing data exposure: Social Security numbers
17. **Affected Individual Count · 100% confidence · current**  
   MCBS medical-billing data exposure: 383 individual
18. **Resulted In · 100% confidence · current**  
   MCBS affected-individual notification: The Massachusetts notice offered 24 months of complimentary identity-protection services as a precaution.
19. **Disclosed At · 100% confidence · current**  
   September 2025 MCBS network incident: 2026-06-26
20. **Exposed Data Category · 100% confidence · current**  
   MCBS medical-billing data exposure: Names
21. **Resulted In · 100% confidence · current**  
   September 2025 MCBS network incident: MCBS said an unauthorized individual may have gained access to its network; it did not identify the person or access method in the notices reviewed.

</details>
