The $10,000 Fine Behind a 15-Million-Record Breach: MMG Fusion and HIPAA's Weakest Link
A Maryland software vendor exposed the protected health information of roughly 15 million people, never told the healthcare providers who trusted it with that data, and ultimately settled with federal regulators for $10,000. The math is the story. When the Department of Health and Human Services’ Office for Civil Rights (OCR) announced its resolution agreement with MMG Fusion, LLC, the headline figure was not the penalty — it was the gap between the scale of the harm and the scale of the accountability, and what that gap says about how breaches at business associates quietly become everyone else’s problem.
What happened
MMG Fusion is a business associate: a company that handles protected health information (PHI) on behalf of covered entities such as dental and medical practices. According to OCR, in December 2020 an unauthorized actor infiltrated MMG’s systems and accessed PHI that included names, phone numbers, mailing addresses, email addresses,...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE