MCBS, LLC, a company that provides medical billing services on behalf of a healthcare provider it refers to as a covered entity, has notified affected individuals that an unauthorized individual may have gained access to its network. The company says it learned of the issue around September 25, 2025, and later confirmed through a forensic investigation completed in May 2026 that certain files containing personal information may have been accessed or acquired without authorization between approximately September 22, 2025 and September 26, 2025. This falls under hacking or system intrusion, meaning someone outside the organization got into MCBS’s systems rather than the exposure being caused by a lost device or an internal mistake.
The letter is addressed to individuals whose information MCBS received from the covered healthcare entity in order to handle billing on that provider’s behalf. MCBS has not stated a specific number of people affected in the portion of the letter provided to BreachLetter, so we cannot confirm the total scope of this incident here.
What information was exposed?
- The specific data elements involved were left blank in the version of this letter that MCBS filed with regulators, so BreachLetter cannot confirm exactly which personal details were affected.
- Given that MCBS is a medical billing provider, and the letter dedicates significant space to explaining medical identity theft protections, information related to healthcare billing and insurance may be involved, but this is not stated outright in the notice.
MCBS says it is not aware of any actual misuse of anyone’s personal or health information at this time. As a precaution, the company is offering complimentary identity protection services, though the exact duration of coverage and the steps to enroll were not filled in on the copy of the letter that was filed.
What should you do now?
- Watch for a follow-up communication from MCBS with the specific enrollment link or code for the complimentary identity protection service, and sign up as soon as it’s available.
- Consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, especially since the exact data exposed here hasn’t been fully detailed.
- Request your free credit reports at annualcreditreport.com and review them for accounts or inquiries you don’t recognize.
- Place a fraud alert with one of the three credit bureaus (Equifax, Experian, or TransUnion) — once one bureau is notified, they will alert the other two.
- Consider placing a security freeze on your credit file with all three bureaus, which restricts access to your credit report without your written permission.
- Review any Explanation of Benefits statements from your health insurer for services you don’t recognize, and follow up with your provider or insurer on anything that looks off.
- Keep any correspondence from MCBS about this incident, and check back for updates if this notice is later corrected or supplemented with more specific details.
If you have questions, MCBS can be reached by mail at 1125 Troupe St, Augusta, GA 30904; the letter references a dedicated toll-free response line, but the phone number was not included in the copy provided to BreachLetter.