MCBS, LLC
bd_32aaf81428502adc · schema v1 · pii pii-v1
Full breach record for MCBS, LLC →2 incidents on fileMCBS, LLC, a medical billing services provider, notified the California Attorney General of an unauthorized access incident. An unauthorized individual gained access to the network between September 22 and September 26, 2025. MCBS learned of the incident on September 25, 2025, and confirmed data exfiltration on May 28, 2026. Affected data includes PHI, health records, and PII (including SSNs). The company engaged forensic investigators and is offering identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 22, 2025
Begins
Sep 25, 2025
Discovered
Jun 26, 2026
Filed
vs. sector median
+27 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitepearbd_fbca2f8d470dced22025-09-25 · +274dVerified by operator
Regulatory filings (5) · sorted by filing gap
- HHS OCRbd_8ed31a4b32add53a2026-06-26Verified by operator
- New Hampshire State AGbd_8f3ea50c0a24e40c2026-06-29 · +3dVerified by operator
- Texas State AGbd_51bebdfc54a78a9b2026-06-30 · +4dVerified
- South Carolina State AGbd_bf3c11705b24a8a62026-07-01 · +5dVerified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- Illinois State AGbd_bf98d272641890612026-07-01 · +5dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Jun 26 (GA), last Jul 1 (IL) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.