The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a settlement with MMG Fusion, LLC, a Maryland-based software provider to oral healthcare organizations acting as a HIPAA business associate, over alleged violations of the HIPAA Privacy, Security, and Breach Notification Rules tied to an unreported breach impacting approximately 15 million individuals. OCR’s investigation found that an unauthorized actor accessed MMG’s internal systems in December 2020, obtained protected health information (PHI)—including names, phone numbers, mailing and email addresses, dates of birth, and appointment dates/times—and that the data was exfiltrated and later posted on the dark web; OCR opened the case after receiving a complaint in early 2023 rather than a breach report from MMG.
According to OCR’s findings, MMG Fusion allegedly failed to perform a comprehensive risk analysis prior to the incident and did not provide required breach notifications to affected covered entities. Under the resolution agreement, MMG agreed to a corrective action plan (with OCR monitoring for three years) and paid $10,000, with OCR noting MMG’s financial condition as a factor in the settlement amount. Separate HIPAA compliance guidance content on designated record sets is not part of the enforcement action and does not add incident-specific details.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On March 5, 2026, OCR announced a settlement over the MMG Fusion breach, requiring a $10,000 payment and a corrective action plan monitored for three years. OCR alleged failures including inadequate risk analysis, impermissible disclosure of PHI, and failure to notify affected covered entities, with HiQOR Dental signing as successor-in-interest.
In March 2023, OCR formally opened an investigation into MMG Fusion following the complaint about the unreported breach and dark web exposure of PHI. The investigation examined possible violations of the HIPAA Privacy, Security, and Breach Notification Rules.
In January 2023, HHS' Office for Civil Rights received a complaint alleging that MMG Fusion had not reported the security incident and that PHI had been exposed. The complaint triggered federal scrutiny of the company’s breach handling.
After the 2020 intrusion, the stolen PHI from MMG Fusion was posted on the dark web. OCR later cited the dark web posting as part of the unreported security incident.
On December 21, 2020, an unauthorized actor accessed MMG Fusion's internal network and exfiltrated protected health information. The incident ultimately affected about 15 million individuals, with exposed data including contact details, appointment information, and in some reports dates of birth.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcehipaajournal.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.