Urgent.News

What's breaking now, across thousands of outlets.

Tech

The $10,000 Fine Behind a 15-Million-Record Breach: MMG Fusion and HIPAA's Weakest Link

The MMG Fusion HIPAA settlement exposed 15M records for a $10,000 fine — what it means for healthcare vendors and business-associate breach risk.

The $10,000 Fine Behind a 15-Million-Record Breach: MMG Fusion and HIPAA's Weakest Link

In a recent case, a Maryland software vendor, MMG Fusion LLC, was found responsible for a massive breach of protected health information (PHI) affecting roughly 15 million individuals. Despite the severity of the breach, MMG settled with federal regulators for a mere $10,000. This outcome highlights the disconnect between the scale of the harm and the accountability imposed on the company.

MMG, as a business associate, handles PHI on behalf of healthcare providers. In December 2020, an unauthorized actor accessed PHI, including names, phone numbers, mailing addresses, email addresses, dates of birth, and appointment dates, which later surfaced on the dark web. The Department of Health and Human Services' Office for Civil Rights (OCR) only learned about the breach in March 2023 through a complaint and dark web posting, not through the required HIPAA notification process.

The breach violated HIPAA Privacy, Security, and Breach Notification Rules, and MMG failed to notify affected covered entities about the incident. HIPAA mandates that business associates must notify covered entities when they suffer a breach to allow those providers to notify their patients and regulators. The $10,000 settlement is symbolic, and the real cost lies in the three-year corrective action plan MMG must follow, which includes conducting an accurate risk analysis, updating policies and procedures, training personnel, and providing notifications to affected covered entities.

The incident underscores the importance of rigorous risk analysis and identity and access management to prevent breaches in healthcare.

Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hackernoon.com →

More in Tech

How the IO-Link IODD checksum works

Every IODD (IO Device Description) file carries a checksum near the end: <Stamp crc= "1462814215" > <Checker name= "IODD-Checker V1.1.1" version= "V1.1.1.0" /> </Stamp> It is mandatory.

Air-con not needed to cool a building

Alternative cooling technologies can reduce a building’s energy use for cooling by up to 48 per cent.

  • Alternative cooling methods reduce energy use by up to 48%
  • Hybrid cooling combines air conditioning with fans
  • Passive displacement cooling uses ceiling coils to lower air temperature

More from Sunday 9 August →