SecurityWeek reported on July 27 that a data breach at Medical Computer Business Services, a medical revenue cycle management and billing company, affects more than 1.2 million individuals. MCBS says unauthorized access occurred around September 25, 2025, and that an unauthorized user may have accessed or removed files between September 22 and September 26. The company later determined that some files may have contained names, addresses, Social Security numbers, insurance information, medical history, treatment information, and diagnosis information.
For healthcare practices, this is not only a headline about one vendor. It is a business associate breach story about where patient and billing records go after they leave the front desk. A small practice may have strong internal habits and still depend on outside billing, revenue-cycle, claims, credentialing, imaging, laboratory, or portal vendors that hold sensitive data on its behalf.
The business risk is vendor visibility
The HHS breach portal lists MCBS as a business associate hacking/IT incident involving a network server and 1,261,464 affected individuals. MCBS also named multiple covered entities whose data was compromised. That matters because patients often know the practice, doctor, lab, or radiology provider more than they know the billing company behind the paperwork.
The owner decision is straightforward: can the practice explain which vendors hold protected health information, what data each vendor receives, what the contract requires after a security incident, and who coordinates patient communication? If the answer is scattered across old agreements, email threads, and assumptions, the practice has a records problem before it has a technology problem.
What owners should ask after a medical billing vendor breach
Healthcare practice leaders do not need to become forensic investigators. They do need a clean set of questions for the vendor, IT provider, privacy officer, attorney, or internal manager responsible for the relationship:
- Data scope: Which patient, insurance, billing, clinical, and employee records did the vendor store or process for the practice?
- Access evidence: What systems were involved, what dates are known, and what logs or forensic findings support the answer?
- Contract duties: What does the business associate agreement require for notice timing, cooperation, indemnity, security controls, and subcontractors?
- Patient communication: Who sends notices, who handles patient calls, and who approves public wording?
- Insurance notice: Does the practice or vendor need to notify cyber insurance, professional liability, or another carrier?
- Corrective action: What changed after the incident: access controls, monitoring, backups, segmentation, multifactor authentication, or vendor oversight?
Those questions should be documented, not handled only by phone. In a healthcare IT risk review, the useful artifact is often a short written record of who answered, what evidence was provided, what remains unknown, and what follow-up is due.
Vendor trust needs a current inventory
Many small organizations treat vendor reviews as a renewal task. Healthcare practices need a more current inventory because patient information can move through billing platforms, claims clearinghouses, statement vendors, payment processors, transcription tools, cloud storage, and support portals. Each handoff creates a different accountability path.
A practical vendor inventory does not have to be complicated. It should list the vendor name, service provided, system owner, data types, access method, contract location, renewal date, breach-contact process, and whether protected health information is involved. For New Jersey healthcare practices and other regulated SMBs, that list becomes the map for faster decisions when a vendor disclosure arrives.
A practical next step
If your organization uses outside billing or revenue-cycle services, start with one review meeting. Pull the vendor list, identify which companies touch patient or customer records, and confirm that each high-risk vendor has a current contract, business associate agreement when required, breach notification contact, and documented access controls.
Then ask your IT provider or internal team to compare the vendor list against the accounts, portals, file transfers, and integrations actually in use. The gap between the contract list and the real access list is where surprises usually live. The MCBS data breach puts that gap back on the exam table, and it is worth checking before the next vendor notice forces the question.
Sources and further reading