Medical Computer Business Services (MCBS), a healthcare billing and practice-management company based in Augusta, Georgia, is notifying 1,261,464 individuals that their personal and health information was compromised.

The timeline is the substance of the story:

  • 22–26 September 2025 — unauthorised access to MCBS systems.
  • 28 May 2026 — MCBS completes its investigation.
  • Late June 2026 — notification letters begin.
  • July 2026 — the PEAR extortion group’s claim and leak receive wider reporting.

That is roughly eight months from intrusion to the completion of the investigation, and nine months to individual notification.

The compromised data includes names, addresses, Social Security numbers, dates of birth, health insurance policy and beneficiary numbers, and clinical information — medical histories, diagnoses, treatment details, and mental and physical health conditions.

The named affected practices include South Georgia Radiology Consultants, SkinPath Solutions, and Stephen W. Brown and Radiology Associates, with at least four further covered entities not publicly identified.

PEAR — the extortion group that claimed the intrusion — alleges it exfiltrated 3.3 terabytes covering human resources data, business operations, payment information, email correspondence, and databases, and reports indicate the cache was published in full.

The 60-day clock does not start when the investigation ends

This is the compliance question that MCBS’s timeline puts directly in issue, and it is the one most business associates get wrong.

45 CFR § 164.410 governs breach notification by business associates. A business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days after discovery of the breach.

Discovery is defined at § 164.410(a)(2), incorporating the standard at § 164.404(a)(2): a breach is treated as discovered on the first day on which the breach is known to the business associate, or, by exercising reasonable diligence, would have been known.

That second limb is the operative one. Discovery is not the date the forensic report is signed. It is the date the entity knew — or should have known, exercising reasonable diligence — that a breach had occurred.

For MCBS, the questions OCR would ask are specific and answerable from the record:

  • When did MCBS first detect anomalous activity? Intrusions spanning 22–26 September 2025 typically generate authentication anomalies, endpoint alerts, or performance effects.
  • When did it become aware of the PEAR claim or the leak-site listing? A public extortion claim is unambiguous notice.
  • When did it engage forensic counsel? Retention of an incident response firm is strong evidence that the entity had reason to believe a breach had occurred.

If discovery is established at any point in autumn 2025, the 60-day outer limit expired well before the May 2026 investigation completion — and separately, the “without unreasonable delay” obligation is an independent requirement that the 60-day cap does not satisfy. OCR’s consistent position, stated in the Breach Notification Rule preamble, is that 60 days is a ceiling, not a safe harbour. An entity that takes 55 days to do work that reasonably required 20 has violated the delay standard while nominally meeting the deadline.

The most common defensible explanation for a long gap is genuine: the forensic work to determine which individuals had data in the affected environment, from unstructured file shares and legacy billing systems, is slow and expensive. That is a real constraint and OCR recognises it. What OCR does not accept is treating the entire period as a single undifferentiated investigation. The expected pattern is to notify the covered entities promptly on knowing a breach occurred, and to supply the individual-level scope as it firms up — not to hold everything until the analysis is complete.

The covered entities inherit a problem they did not create

Here is the structural consequence that every physician practice, radiology group, and small hospital should understand.

MCBS is a business associate. The seven-plus practices are covered entities. Under § 164.404, the duty to notify affected individuals sits with the covered entity — the practices — not with MCBS.

And under the federal common law of agency, where a business associate acts as the covered entity’s agent, the covered entity is deemed to have discovered the breach when the business associate discovered it. OCR addressed this explicitly in the Breach Notification Rule preamble.

Whether an agency relationship exists turns on the right to control the business associate’s conduct — not on what the contract calls the relationship. A billing vendor operating under detailed practice direction on how to perform the service is more likely to be an agent than one exercising independent professional judgment.

The practical consequence for a small radiology practice: if MCBS was its agent, the practice’s own 60-day clock started in autumn 2025, and the practice was in violation of § 164.404 for months before it learned there was anything to notify. The practice made no error of its own. It selected a vendor and signed a business associate agreement.

This is the same structural exposure documented in the Pinnacle Financial and Mercadien CPA breach on the banking side, and in the Conduent breach that reached 62.2 million individuals in healthcare. The entity carrying the legal duty is repeatedly not the entity that was breached, and it learns of its own default retrospectively.

What a business associate agreement should say, and usually does not

Most BAAs are a reproduction of the § 164.504(e) minimum with the statutory 60-day period copied in as the notification term. That is a contractual failure, because 60 days is the outer regulatory limit for the entire chain — and if the business associate consumes all of it, the covered entity has zero days.

Terms that materially change the outcome:

Notification in hours, not days. Notice of a suspected security incident affecting PHI within 24 hours of the business associate becoming aware. This is not the regulatory duty; it is the contractual one, and it is the only mechanism by which the covered entity gets usable time.

A standing duty to update. An obligation to provide written status updates at defined intervals — weekly is reasonable during an active investigation — until the affected-individual determination is final. The absence of this term is why practices learn nothing for months.

A committed date for the individual-level list. Not “as soon as practicable.” A date, with a mechanism for extension that requires written justification.

Right to conduct or participate in the forensic investigation, including access to the forensic report rather than a summary. Business associates resist this; it is negotiable, particularly at contract renewal.

Preservation obligations. Logs, images, and forensic artefacts preserved for a defined period and made available. Covered entities routinely find that the evidence they need to establish their own reasonable-diligence position was rotated out.

Allocation of notification cost and regulatory liability. These are separate and both should be addressed. Indemnity for notification and credit-monitoring costs is common; indemnity for the covered entity’s own regulatory penalties is rarer and worth pursuing.

Security requirements with a right to audit or to receive a current third-party attestation. SOC 2 Type II or HITRUST, current, reviewed rather than filed.

Termination rights on a material security failure, with transition assistance obligations.

The RCM concentration problem

MCBS is a small regional company in Augusta, Georgia, holding the records of 1.26 million people because it aggregates billing for multiple practices. That aggregation is the risk.

Revenue cycle management vendors have a structural characteristic that makes them high-value targets and difficult to secure:

They hold everything. Billing requires demographics, insurance identifiers, diagnosis and procedure codes, and often clinical documentation supporting medical necessity. A billing vendor’s data set is frequently more complete than any individual practice’s.

They aggregate across clients. A practice with 30,000 patients presents a modest target. A vendor serving forty such practices holds 1.2 million records — with, typically, the security budget of a company its own size rather than the aggregate of its clients’ risk.

Their clients cannot meaningfully assess them. A three-physician radiology practice does not have the capability to evaluate a vendor’s security programme. It asks whether the vendor is “HIPAA compliant,” receives a yes, and signs.

Switching costs are high. Billing integration with practice management and EHR systems makes vendor replacement genuinely difficult, which weakens the client’s negotiating position on security terms.

The mitigations available to a small practice are limited but not zero:

  • Require a current SOC 2 Type II report and read the exceptions section, not the opinion. Ask about any qualified findings.
  • Ask what data the vendor actually holds and for how long. Many billing vendors retain full clinical documentation indefinitely when they need it only for the claim adjudication period. Reducing retention reduces your exposure directly.
  • Ask whether the vendor holds data on servers segregated by client. Shared environments mean one client’s compromise is every client’s compromise.
  • Confirm MFA on all remote access and administrative accounts. Ask for evidence.
  • Pool negotiating power. Practices in the same specialty society or IPA using the same vendor can negotiate BAA terms collectively that none could obtain individually. This is the single most effective step available to small covered entities and it is rarely taken.

OCR’s current enforcement posture

Two features of OCR’s enforcement programme are directly relevant.

The Risk Analysis Initiative. OCR has been resolving a sustained series of enforcement actions focused specifically on failure to conduct an accurate and thorough risk analysis under § 164.308(a)(1)(ii)(A). The pattern is consistent: an entity reports a breach, OCR investigates, and the resolution centres on the absence of a compliant, enterprise-wide risk analysis rather than on the breach itself. For a business associate holding 1.26 million records, the existence and adequacy of that risk analysis is the first document OCR will request.

Business associates are directly liable. Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for compliance with the Security Rule and specified Privacy Rule provisions, and OCR can and does impose civil monetary penalties on them directly. See our coverage of the HIPAA Omnibus Rule’s expansion to business associates.

Civil monetary penalties are tiered by culpability, with the top tier — wilful neglect not corrected — carrying the highest per-violation amounts and annual caps. A delayed notification, standing alone, has supported six- and seven-figure settlements.

The published data set and what patients face

PEAR’s claim of 3.3 terabytes, reportedly published in full, means this is not a theoretical exposure. The combination at risk — name, date of birth, Social Security number, insurance beneficiary number, diagnosis and treatment detail — supports:

  • Financial identity theft, addressed by credit freezes rather than monitoring.
  • Medical identity theft, where a fraudster obtains care under the victim’s insurance. This corrupts the victim’s medical record with another person’s clinical data, which is both a safety risk and extremely difficult to correct. Patients should request and review their Explanation of Benefits statements and their insurer’s claims history for services not received.
  • Highly credible social engineering. An attacker who can name your radiology practice, your visit date, and your insurance ID is convincing. The Abbott and Exact Sciences vishing campaign demonstrated exactly this progression from breach data to targeted fraud.

The nine-month gap compounds all of it. Individuals notified in June 2026 about a September 2025 intrusion had no opportunity to freeze credit or monitor claims during the period when the data was most actionable.

Actions

For covered entities using billing or RCM vendors:

  1. List every business associate with access to PHI, with the data categories and volume each holds. Most practices cannot produce this today.
  2. Read the notification clause in each BAA. If it says 60 days, it needs renegotiating at renewal.
  3. Ask each vendor, in writing, for its most recent SOC 2 Type II and its breach notification procedure. The quality of the response is itself information.
  4. Determine whether each vendor is your agent. If so, its discovery is your discovery, and your compliance depends entirely on its detection capability.
  5. Reduce what you send. Vendors frequently receive more clinical documentation than the billing function requires.

For business associates:

  1. Fix the discovery date question now. Document, contemporaneously, when you knew and what you did. That record is your defence.
  2. Notify covered entities on knowledge of the breach, not on completion of scoping. Supply the individual list as a second deliverable.
  3. Ensure you have a current, enterprise-wide risk analysis meeting § 164.308(a)(1)(ii)(A). It is the first thing OCR asks for.
  4. Retain logs long enough to scope an intrusion discovered months later. Thirty-day retention makes an eight-month investigation unavoidable.

Conclusion

The intrusion at MCBS lasted five days in September 2025. The consequences of it are still being distributed in July 2026, to 1.26 million people who never chose MCBS, through at least seven practices that had no visibility into the vendor’s security or its investigation.

HIPAA’s architecture assumes a covered entity that knows what happened to its patients’ data. When the data sits with an aggregator holding forty practices’ records, that assumption fails — and the failure is not corrected by a business associate agreement that reproduces the regulatory minimum and calls the job done.

The one term that changes the outcome is the notification clock. Sixty days is what the regulation permits the entire chain. A covered entity that gives its vendor all sixty has, by contract, made its own compliance impossible.

This article is provided for informational purposes only and does not constitute legal advice.