HIPAA Business Associate Settles with HHS OCR Following Alleged PHI Breach to the Dark Web

Saul Ewing LLP
Contact

Saul Ewing LLP

On March 5, 2026, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a settlement with MMG Fusion, LLC (MMG). MMG is a Maryland software company that was the subject of a complaint filed with OCR in January 2023 based upon an unreported HIPAA security incident. Although MMG, a HIPAA business associate, admitted no wrongdoing as part of the OCR settlement, OCR noted that MMG had potentially violated provisions in the HIPAA Privacy, Security, and Breach Notification Rules. OCR's investigation of MMG's December 2020 incident was related to a person accessing MMG's information system and disclosing PHI, including names, phone numbers, mailing addresses, email addresses, dates of birth, and dates and times of medical appointments for MMG's HIPAA-covered entity clients.

According to the OCR press release announcing the settlement, MMG may have: 

  • Impermissibly disclosed the PHI of approximately 15 million individuals, which ended up on the 'dark web';
  • Failed to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the ePHI it held; and
  • Failed to notify covered entities affected by the incident of the breach. 

As a result of the OCR settlement, MMG agreed to pay $10,000 and enter into a three-year corrective action plan (CAP) with HHS. Despite the quantity of the PHI that was exposed, it appears the settlement amount was slight due to MMG's financial condition.

As part of the CAP, MMG agreed to:

  • conduct a "comprehensive, accurate and thorough analysis of the potential risks and vulnerabilities to the confidentiality, integrity and availability" of the electronic PHI held by MMG and timely provide the risk analysis to HHS; 
  • review and revise its HIPAA policies and procedures for HHS' review and approval and then distribute the same to members of its workforce; 
  • include 11 specific policies addressing HIPAA Privacy Rule and Security Rule provisions; 
  • provide HHS with its breach risk assessment of the December 2020 incident; 
  • provide workforce training; and
  • prepare an implementation report and annual reports for the duration of the CAP.

This MMG settlement is OCR's 12th enforcement action as part of its risk analysis initiative. The MMG Resolution Agreement can be reviewed here. HIPAA-covered entities and business associates should carefully review each of the announced OCR settlements and be sure that their HIPAA, privacy, security, and breach notification policies and procedures are current and are adhered to.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Saul Ewing LLP

Written by:

Saul Ewing LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA

  • Increased readership
  • Actionable analytics
  • Ongoing writing guidance

Join more than 70,000 authors publishing their insights on JD Supra

Start Publishing »

Saul Ewing LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide