Security and compliance for healthcare and health tech startups.
MMG Fusion was breached in December 2020. Fifteen million individuals. The data reached the dark web. The company never reported it, and OCR only learned of it from a complaint filed in March 2023. The case settled in March 2026 for ten thousand dollars, because that reflected the company's financial condition by then.
The number to take from that case is not the ten thousand. It is the fifteen million, and the two years and three months during which nobody told anyone.
The exposure did not grow at hospitals. It moved to the companies serving them.
In 2015, business associates accounted for about five percent of the individuals affected by healthcare breaches. By 2025 that figure was roughly sixty-five percent (HIPAA Journal, derived from HHS breach portal data).
If you process, store or transmit protected health information on behalf of a covered entity, you are one of those companies, whether or not anyone at your company has used the phrase business associate this quarter.
You will be shown statistics claiming that 72% or 89% of healthcare breaches involve a third party. Both circulate widely in vendor marketing, both trace back to loose readings of a single 2023 report, and neither reconciles with OCR's own breach portal. If a security partner quotes you the 89%, ask them where it came from.
The answer to that question tells you more about the partner than the statistic tells you about your risk.
The pattern is not failing the review. It is stalling in it.
Weeks lost on a questionnaire nobody owns. A penetration test scheduled from scratch. An architecture diagram that does not exist. A subprocessor list assembled by asking around. That delay lands at the worst possible moment: late in a quarter, late in a runway, with a champion on the buyer's side losing momentum.
Under the proposal, business associates would notify covered entities within 24 hours of activating a contingency plan. That is an on-call rotation, a trigger threshold, and a customer contact list that is actually current.
Notification within 24 hours when a workforce member's access to ePHI is changed or terminated. That is a provisioning integration, not a policy document.
Written procedures to restore certain critical systems and data within 72 hours of a loss. That is a tested recovery architecture with a number attached to it.
None of those get built in the quarter a deal is closing.
Let the pipeline set the order, not the competitive landscape.
HIPAA first, because it is the legal obligation and it establishes the inventory everything else rests on. SOC 2 next, when a buyer asks for it. HITRUST only if and when buyers require it.
A SOC 2 built on an inventory nobody trusts is an expensive document.
Retrofitting controls into shipped product at Series B under a contractual deadline costs a quarter. Architecting for them before Series A, while changing how data flows still costs a sprint, does not. That difference is the entire argument for doing this early, and it is a commercial argument rather than a compliance one.
The mirror risk inside your own company
Your engineers are using AI coding assistants. Your support team is pasting tickets into chatbots. If protected health information is anywhere in those flows and it is not in your risk analysis, you have the MMG Fusion problem in embryo: an exposure you do not know you have, which is precisely the kind that goes unreported. That is what an AI and third-party vendor risk assessment is built to surface.
Frequently asked questions
We are pre-revenue. Is it too early for this?
The opposite. The cheapest moment to decide how data flows is before customers depend on it. The expensive version is a Series B retrofit against a signed contractual deadline.
Do we need SOC 2 or HIPAA first?
HIPAA, if you handle protected health information, because it is a legal obligation rather than a buyer preference. SOC 2 when a buyer asks for it. Building SOC 2 on top of an asset inventory nobody trusts produces a document rather than a program.
Can a compliance automation platform do this?
It can track evidence and it is worth having. It cannot decide your risk posture, negotiate a business associate agreement, answer a buyer's architecture question, or own the program in front of an auditor.
How fast can we be ready for an enterprise security review?
It depends entirely on what already exists. The companies that move fastest are the ones where someone owns the questionnaire before it arrives.
Is the security review holding up a deal right now?
Thirty minutes is usually enough to identify which part of it is actually blocking, and whether it is a document problem or a program problem.
