

Part 2 of 3. In March 2026, OCR settled a breach affecting fifteen million people for roughly the price of a used car. If your first reaction to that number is relief, this post is for you — because it says something very different from what it appears to say, and because the delayed Security Rule is about to change what every company that touches ePHI on someone else’s behalf owes its customers.
On March 5, 2026, the HHS Office for Civil Rights announced a resolution with MMG Fusion, a software company serving oral healthcare practices.
The numbers, in order:
OCR cited three failures: impermissible disclosure of PHI, failure to conduct an accurate and thorough risk analysis, and failure to notify the covered entities of the breach (HHS; HIPAA Journal).
Ten thousand dollars for fifteen million people. If your first reaction is relief — so this is what enforcement actually looks like, we can live with that — read the rest of this section carefully.
OCR stated the amount reflected consideration of the company’s financial condition.
That is the whole story. The penalty was not small because the conduct was minor. It was small because there was almost nothing left to collect from. The fine is not a price list. It is a tombstone.
And look at who was left holding the consequences. The dental practices that trusted MMG Fusion with their patients’ data were never told. Their patients’ information sat on the dark web while those practices went on answering “yes” on their own compliance attestations. OCR Director Paula M. Stannard’s statement went directly to that point: “When a breach occurs, business associates must notify affected covered entities without unreasonable delay and within 60 calendar days of discovery.”
The corrective action plan runs three years. Risk analysis, risk management plan, written policies and procedures, workforce training, and a retroactive breach risk assessment with notification to every affected entity — five years after the fact.
If you build software that touches protected health information, MMG Fusion is not a cautionary tale about a bad actor. It is a cautionary tale about a company that almost certainly believed a breach was an IT problem rather than a regulatory one, and found out otherwise on a five-year delay.
For most of HIPAA’s history, breaches were something that happened at healthcare organizations. That has quietly, structurally inverted.
| Period | Share of healthcare breaches involving a business associate |
|---|---|
| 2017 | 13% |
| 2018–2026 average | 34% |
| First half of 2026 | 43% |
The concentration of impact is starker still. In 2015, 5% of individuals affected by healthcare breaches were affected at a business associate. By 2025, that figure was 65% (HIPAA Journal).
Two incidents explain much of that: Change Healthcare in 2024 and Conduent in 2025, together affecting roughly 255 million individuals. But the trend line does not depend on the outliers. OCR has now penalized a steady run of business associates — Consociate, MMG Fusion, BST & Co. CPAs, Comstar, Health Fitness Corporation, USR Holdings, Virtual Private Network Solutions, and Elgon Information Systems among them.
A note on rigor, because it matters in this particular market. You will see claims that “72%” or “89%” of healthcare breaches involve third-party vendors. Both circulate widely in vendor marketing. Both trace back to loose readings of a 2023 industry report, and neither reconciles with OCR’s own breach portal. The figures above come from breach portal data and are more than alarming enough. If a security partner quotes you the 89%, ask them where it came from.
Part 1 of this series covered why the Security Rule’s slip from May 2026 to July 2027 is not the reprieve the industry is treating it as. For business associates, the argument is even more direct, because several of the proposed requirements are not internal hygiene. They are recurring obligations you owe your customers — and the moment your customers know they are coming, those obligations start showing up in contracts, well before the rule is final.
From the HHS fact sheet on the proposed rule (primary source):
Read the first three again with a product engineering hat on. A 24-hour notification obligation on contingency plan activation is not a policy document. It is an on-call rotation, a defined trigger threshold, a customer contact database that is actually current, and a decision-maker reachable on a Saturday. A 24-hour access-change notification is a provisioning integration. A 72-hour restoration commitment is a tested recovery architecture with a number attached to it.
None of those get built in the quarter a deal is closing.
Most founders treat this as compliance cost. It is more accurately a revenue mechanic, and reframing it that way changes where it sits on the roadmap.
Security review is now a gating stage in the enterprise healthcare sales cycle, not a formality after the handshake. Health systems, payers, and PE-backed platforms run vendor diligence before contract. The pattern I see most often in health tech is not a company that fails the review — it is a company that stalls in it: weeks of back-and-forth on a questionnaire nobody owns internally, a pen test that has to be scheduled from scratch, an architecture diagram that does not exist yet, a subprocessor list assembled by asking around.
That delay lands at the worst possible moment: late in a quarter, late in a runway, with a champion on the buyer’s side losing momentum.
The certifications follow the same logic. SOC 2 has become the price of entry for a first serious enterprise logo. HITRUST is what gets asked for once you are handling meaningful volumes of ePHI or selling into risk-averse systems. Neither is worth pursuing because a competitor has one. Both are worth pursuing when your actual pipeline is asking for them — and the sequence matters, because a certification built on top of an unknown asset inventory fails expensively and publicly.
The expensive version of this work is retrofitting controls into shipped product at Series B under a contractual deadline. The inexpensive version is architecting for it before Series A, when changing how data flows still costs a sprint instead of a quarter.
AI adoption in clinical documentation, revenue cycle, and analytics depends on large data volumes and increasingly complex vendor chains — frequently layered onto legacy systems that were never built for it.
Your customers know this. Vendor questionnaires now carry AI-specific sections: which model providers you use, what your data retention terms are, whether customer data trains anything, who your subprocessors are, and where a human sits in the loop. “We use a third-party API” is not an answer that survives a health system’s security review anymore.
Under the proposed rule, your covered-entity customers will be required to obtain written verification from you. That obligation flows downhill into your contracts whether or not you have prepared for it.
And the mirror risk sits inside your own company. Shadow AI now accounts for 43% of security incidents, at an average breach cost of $5.39 million, with one in five resulting in a regulatory fine (IBM Cost of a Data Breach Report 2026). Your engineers are using AI coding assistants. Your support team is pasting tickets into chatbots. If ePHI is anywhere in those flows and it is not in your risk analysis, you have the MMG Fusion problem in embryo — an exposure you do not know you have, which is precisely the kind that goes unreported.
The sequence matters more than the speed. Skipping steps is what produces certifications that do not survive an incident.
Determine your role precisely — business associate, subcontractor, or both — and get the BAA chain right end to end, including every subprocessor. A surprising number of health tech companies have an incomplete map of who downstream of them touches ePHI.
Every OCR enforcement action discussed in this series cited the risk analysis. It is also the foundation the asset inventory, the network map, and every framework audit sit on. Do it first. A SOC 2 built on an inventory nobody trusts is an expensive document.
The 24-hour obligations are operational, not documentary. Define the trigger thresholds, name the on-call owner, maintain a current customer contact list, and run the drill once before you need it.
HIPAA compliance first, then SOC 2, then HITRUST if and when your buyers require it. Let the pipeline set the order, not the competitive landscape.
Model inventory, data flow mapping, subprocessor register, retention terms, and a written policy on what may and may not be put into a general-purpose tool. Your customers will ask. Increasingly, they will ask in writing. This is what an AI and third-party vendor risk assessment is built to produce.
Assemble the package once and maintain it: current SOC 2 report, penetration test summary, architecture and data-flow diagrams, subprocessor list, and pre-drafted responses to the standard questionnaires. The goal is that security review stops adding sixty days to every enterprise deal.
Not $10,000. That figure is an artifact of one company’s balance sheet at the end of a five-year investigation.
The number to remember is fifteen million — the people whose information ended up on the dark web because a software vendor did not conduct a risk analysis, and then did not tell anyone what had happened.
And the second number is 43%: the share of healthcare breaches that now run through a company like yours.
The Security Rule overhaul is not scheduled to be finalized until July 2027. Your customers’ procurement teams are not waiting for it, and neither is OCR.
Cybersecurity Advisory Group builds security programs for health tech and digital health companies at the stage where it is still inexpensive to do. SOC 2 and HITRUST readiness, AI and third-party vendor risk assessment, and complete security program builds for companies that do not yet have one — sized for a startup’s budget and sequenced against your actual sales pipeline.
Book a free 30-minute Security Clarity Session. We’ll go through where your controls stand today, which of the proposed business associate obligations you are furthest from meeting, and what your buyers are most likely to ask for next. No pressure, no jargon, and no homework before we talk.
Book Your Free 30-Minute Security Clarity Session →
Part 1 of this series — HIPAA’s Deadline Moved. OCR’s Didn’t. — covers what the delay means for provider organizations. Part 3 covers private equity and portfolio-wide risk.
Enforcement
Vendor and business associate breach data
Proposed Security Rule requirements
Cost and AI risk data
Melissa Thornton is the founder of Cybersecurity Advisory Group, providing virtual CISO and fractional cybersecurity leadership to healthcare organizations, startups, and SMBs. Based in White Plains, NY, serving clients remotely nationwide. sales@cyberadvisor.tech · +1 914-517-0022
This article is provided for general informational purposes and does not constitute legal advice.
Connect with Melissa Thornton on LinkedIn
