Healthcare organizations increasingly depend on third-party medical billing and revenue cycle management (RCM) companies to process claims, manage accounts receivable, communicate with payers, and handle large volumes of sensitive patient information. A recently disclosed cybersecurity incident involving medical billing and RCM company MCBS demonstrates why cybersecurity and HIPAA compliance must extend far beyond the walls of hospitals and physician practices.
MCBS disclosed that unauthorized access to its network resulted in the compromise of personal and health information belonging to approximately 1.26 million individuals.
The incident is another powerful reminder that protecting patient information is not simply an IT responsibility. It is a healthcare-wide responsibility involving providers, billers, coders, RCM professionals, compliance teams, administrators, vendors, and every workforce member who interacts with protected health information.
What Happened?
According to the company’s breach disclosure, MCBS detected unauthorized activity within its network on or about September 25, 2025. Its investigation later determined that unauthorized access occurred between approximately September 22 and September 26, 2025.
Following forensic investigation and a manual review of potentially affected information, MCBS stated that it determined on May 28, 2026 which information was involved.
The compromised information varied depending on the individual but reportedly could include:
- Names and addresses
- Social Security numbers
- Dates of birth
- Health plan beneficiary numbers
- Health insurance policy or subscriber identification numbers
- Medical history
- Diagnosis information
- Treatment information
The incident reportedly affected patients associated with multiple healthcare organizations served by MCBS, including radiology and imaging practices.
MCBS stated that it had no evidence that the affected information had been used for identity theft at the time of its notice and recommended that individuals remain vigilant by reviewing financial accounts and statements for suspicious activity.
The ransomware group PEAR, or Pure Extortion and Ransom, claimed responsibility for the attack and alleged that approximately 3.3 terabytes of information had been exfiltrated, according to BleepingComputer. MCBS did not address that claim in its public breach notice.
Why RCM Companies Are Attractive Cyberattack Targets
Medical billing and RCM organizations may process information from thousands—or even millions—of patients across multiple healthcare clients.
A single RCM vendor may receive patient demographics, insurance information, diagnoses, procedure information, claim data, payment information, and other information necessary for reimbursement.
That concentration of information creates significant cybersecurity exposure.
An attack against one vendor can potentially affect patients from multiple hospitals, physician groups, imaging centers, or other healthcare organizations simultaneously.
This is why healthcare cybersecurity can no longer be viewed only as hospital cybersecurity.
It must also include vendor cybersecurity.
HIPAA Does Not Stop at the Hospital Door
The HIPAA Security Rule establishes standards for protecting electronic protected health information, or ePHI, created, received, maintained, or transmitted by covered entities and their business associates.
HHS requires appropriate administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of ePHI. (HHS.gov)
Medical billing and RCM organizations that perform functions involving PHI for covered entities may operate as HIPAA business associates. HIPAA business associate arrangements are therefore not merely paperwork. Contracts must address permitted uses and disclosures and require appropriate safeguards for PHI. (HHS.gov)
The HIPAA Breach Notification Rule also establishes notification obligations following breaches of unsecured PHI. Business associates have responsibilities to notify covered entities when applicable breaches occur. (HHS.gov)
HIPAA Compliance Is More Than Signing a BAA
A Business Associate Agreement is important, but a signed document alone cannot protect patient information.
Healthcare organizations and RCM vendors need a culture in which privacy and security are incorporated into everyday operations.
That includes appropriate access controls, workforce training, security risk analysis, incident-response planning, password and authentication practices, system monitoring, secure handling of patient information, vendor management, and procedures for identifying and responding to suspected security incidents.
HHS guidance specifically states that business associates must identify and respond to suspected or known security incidents, mitigate harmful effects where practicable, and document security incidents and their outcomes. (HHS.gov)
Cybersecurity is therefore inseparable from modern healthcare compliance.
Every Medical Coder and Biller Needs HIPAA Knowledge
HIPAA education should not be limited to compliance officers.
Medical coders routinely review diagnoses, operative reports, laboratory findings, pathology results, physician documentation, and other highly sensitive clinical information.
Medical billers work with patient demographics, insurance information, claims, payment information, denials, authorizations, and payer communications.
RCM professionals may have access to thousands of patient records.
One employee clicking a malicious attachment, sharing credentials, sending PHI to the wrong recipient, using an insecure system, or failing to report suspicious activity can create substantial organizational risk.
Healthcare professionals therefore need to understand not only what HIPAA is, but also how privacy and security principles apply to their daily work.
The Bigger Lesson for Healthcare Organizations
The MCBS incident should encourage healthcare organizations to ask important questions:
Who has access to our patient data?
Which third-party vendors receive PHI?
Do workforce members understand HIPAA requirements?
Are security incidents recognized and reported quickly?
Are access privileges appropriate for each employee’s job responsibilities?
Do our vendors have appropriate safeguards and incident-response procedures?
Cybersecurity cannot be delegated completely to an outside vendor simply because billing or RCM operations have been outsourced.
The data may move outside the organization, but the importance of protecting the patient does not.
HHS has also emphasized the growing cybersecurity threat facing healthcare. In discussing proposed updates to the HIPAA Security Rule, OCR reported major increases in large breaches and in the number of individuals affected, with hacking and ransomware playing a significant role. (HHS.gov)
PMBAUSA Offers Free HIPAA & GDPR Certificate Course
Education is one of the foundations of healthcare privacy and security.
To support healthcare professionals in strengthening their understanding of patient privacy, data protection, and compliance responsibilities, PMBAUSA LLC offers a FREE HIPAA & GDPR Certificate Course.
The program is designed for medical coders, medical billers, RCM professionals, auditors, CDI specialists, healthcare administrators, students, and other professionals who handle healthcare information.
The goal is simple:
Understand the rules. Protect patient information. Reduce compliance risk. Build a stronger culture of privacy and security.
A certificate alone does not make an individual or organization HIPAA compliant. Compliance requires ongoing organizational policies, safeguards, risk management, training, monitoring, and appropriate action. But education gives healthcare professionals the knowledge needed to recognize their responsibilities and make safer decisions.
Final Message
The MCBS breach affecting approximately 1.26 million individuals is more than another cybersecurity headline.
It is a reminder that modern healthcare is interconnected.
A physician documents the patient’s condition.
A coder converts documentation into codes.
A biller creates the claim.
An RCM company processes the information.
A payer receives the data.
At every point in that chain, patient information must be protected.
HIPAA is not only the responsibility of the compliance department. Protecting patient information is everyone’s responsibility.
Learn HIPAA. Understand data privacy. Protect the patient.
PMBAUSA LLC — Advancing Professional Excellence in Medical Coding, Billing, Compliance, and Healthcare Education.
Educational Disclaimer: This article is provided for general educational and professional awareness purposes and does not constitute legal, cybersecurity, or regulatory advice. Organizations should consult qualified legal, compliance, privacy, and cybersecurity professionals regarding their specific obligations.
Refrences – · MCBS Official Data Breach Notice:
MCBS Data Breach 2025
· HHS Office for Civil Rights — Breach Portal:
HHS OCR Breach Portal
· BleepingComputer — MCBS Breach Report:
Data breach at medical billing firm MCBS affects 1.26 million people
· HHS — HIPAA Security Rule:
HIPAA Security Rule Guidance
· HHS — HIPAA Breach Notification Rule:
HIPAA Breach Notification Rule
· HHS — Business Associate Agreements:
Business Associate Agreement Guidance
· PMBAUSA:
PMBAUSA LLC

