Medical Billing Vendor MCBS LLC Breach Exposes 1.3 M Patient Records to Extortion Group PEAR
What Happened — In September 2025, threat actors identified as the PEAR extortion gang gained unauthorized access to MCBS LLC’s network and exfiltrated roughly 3.3 TB of data, including protected health information (PHI) for 1.3 million patients served by seven healthcare practices. The gang is now advertising the stolen data on a dark‑web site.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a classic third‑party risk failure: a vendor’s inadequate security controls led to a PHI breach that directly impacts your organization’s compliance obligations.
- SOC 2 requires documented vendor‑risk management (CC6.1, CC6.2) and continuous evidence that third‑party controls are monitored, tested, and remediated.
- The incident provides a concrete audit‑ready evidence point for the “Vendor Management” criteria and for breach‑notification procedures under the Security and Privacy principles.
Who Is Affected — Healthcare providers that use MCBS for billing, the medical‑billing SaaS vendor itself, and the 1.3 M patients whose PHI was exposed.
Recommended Actions
- Immediately review and update your vendor‑risk assessment for MCBS, mapping its controls to SOC 2 CC6 requirements.
- Collect and archive evidence of due‑diligence (contracts, security questionnaires, continuous monitoring logs) to satisfy audit reviewers.
- Initiate a breach‑response plan that includes notification timelines, PHI handling, and remediation verification.
Technical Notes — Unauthorized network access was detected on 25 Sept 2025; investigators believe files were accessed or removed between 22‑26 Sept 2025. Exfiltrated data includes names, addresses, SSNs, health‑plan numbers, medical histories, and additional HR/financial records. PEAR does not encrypt the stolen data, increasing exposure risk. Source: DataBreachToday