Imagine you run a mid-size dental group. You never touched the software that got breached. You never wrote a line of its code, never managed its servers, never saw its incident logs. And yet, when a scheduling and marketing platform your practice relied on exposed patient records, the patients affected are yours. The letters go out under your name. The trust you spent years building takes the hit.
That is the uncomfortable center of the MMG Fusion story, and it is worth every healthcare leader’s attention this week.
According to HHS.gov, the Department of Health and Human Services’ Office for Civil Rights has settled a HIPAA investigation tied to a breach at MMG Fusion, LLC that affected roughly 15 million individuals. HHS OCR investigates covered entities and their business associates when protected health information is exposed, and a settlement of this size signals that the agency found real gaps in how sensitive data was safeguarded.
What actually happened
MMG Fusion is a technology vendor that serves healthcare and dental practices. When a business associate like that suffers a breach, the exposure does not stay contained to the vendor. It flows downstream to every practice that shared patient data with them. According to HHS.gov, the OCR investigation ended in a settlement over a breach affecting about 15 million individuals, which places it among the larger healthcare data events regulators have acted on.
The number matters, but so does the mechanism. A single vendor with weak controls can create liability for hundreds of practices at once. That is the part most owners underestimate. You can run a tight ship internally and still end up in a breach notification because a company you handed data to did not.
Why this matters to your practice
HIPAA does not let you outsource accountability. When you sign a Business Associate Agreement with a vendor, you are affirming that they will protect patient data to the same standard you are held to. If they fail, you are not simply a bystander. You are a covered entity whose patients were harmed, and OCR expects you to have done reasonable diligence before you ever shared a record.
For a medical or dental practice, the fallout is not abstract. It is patient notification letters, potential state attorney general interest, reputational damage in a community where word travels, and the quiet erosion of the trust that makes patients comfortable sharing their history with you. Ransomware and third-party breaches have become the dominant way patient data leaves healthcare organizations, and the vendor supply chain is where a lot of that exposure now lives.
The practices that came through the MMG Fusion situation in the best shape are the ones that could answer three questions before OCR ever asked: Which vendors hold our patient data? What does our agreement with each of them actually require? And when did we last confirm they were doing it?
Most practices cannot answer all three. That is the real gap this settlement exposes.
What to do now
You do not need a compliance overhaul to act on this. You need to close the distance between what you assume about your vendors and what you can verify.
Start with an inventory. List every third-party tool that touches patient data: scheduling, billing, marketing, imaging, EHR add-ons, patient communication platforms. Most practices are surprised by how long the list gets.
Then pull the Business Associate Agreement for each one. If you cannot find it, that is your first finding. A vendor handling PHI without a signed BAA is a HIPAA problem regardless of whether they ever get breached.
Next, ask each vendor for evidence, not assurances. A current SOC 2 report, a summary of their security controls, confirmation of encryption at rest and in transit, and a clear breach notification commitment. “We take security seriously” is marketing. Documentation is diligence.
Finally, put a date on it. Vendor review is not a one-time project. Set a recurring review so that the answers you have today do not quietly go stale.
Common Questions
Are we liable if a vendor causes a HIPAA breach? You can be. As a covered entity, you are responsible for reasonable diligence in selecting and monitoring business associates. A signed Business Associate Agreement is required before you share PHI, and OCR expects you to verify that vendors uphold their obligations.
What is a Business Associate Agreement and do we need one for every vendor? A BAA is a contract that binds a vendor handling protected health information to HIPAA’s safeguards. You need one with any vendor that creates, receives, maintains, or transmits PHI on your behalf. If you do not have one on file, that is a gap to close immediately.
How do we know if a vendor’s security is actually good? Ask for evidence. A current SOC 2 Type II report, documentation of encryption in transit and at rest, defined access controls, and a written breach notification process. Claims without documentation do not meet the standard of diligence OCR looks for.
How often should we review our vendors? At least annually, and any time a vendor changes ownership, has a security incident, or takes on a new type of data. Vendor risk changes over time, so a review from three years ago tells you very little today.
centrexIT has been the IT team Healthcare organizations across the West have trusted since 2002. If you are not sure which of your vendors hold patient data or whether your agreements would hold up under an OCR review, that is exactly the kind of gap worth finding on your own terms. Take the 2-Minute Cybersecurity Assessment: https://centrexit.com/cyber-security-readiness-assessment/
Sources
- HHS OCR settled a HIPAA investigation over the MMG Fusion, LLC breach affecting approximately 15 million individuals: HHS.gov, “HHS’ Office for Civil Rights Settles HIPAA Investigation of MMG Fusion, LLC Breach Affecting 15 Million Individuals” (2026), https://news.google.com/rss/articles/CBMidEFVX3lxTE5ZaWl4cXlRajhUa1pRNGpuOWRMWXhTVy0tc3pzMjgtLWFxSGRtZEloc1prekxvM0ttRUFJdXdmbjNKTS05UVI5dWdsaG8xWmEyUVlIWmVrdFlXZ0pub2t2OERpUUhVVmd3R0JQSlhYSG5UNUpU?oc=5
The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.
Meet Our Team