MCBS, LLC, a medical billing services provider, notified the California Attorney General of an unauthorized access incident. An unauthorized individual gained access to the network between September 22 and September 26, 2025. MCBS learned of the incident on September 25, 2025, and confirmed data exfiltration on May 28, 2026. Affected data includes PHI, health records, and PII (including SSNs). The company engaged forensic investigators and is offering identity protection services.