A $10,000 HIPAA Fine Is Worse News Than a $10 Million One

August 25, 2026
August 25, 2026
By Melissa Thornton, CISSP | Cybersecurity Advisory Group | cyberadvisor.tech
Bar chart: business associates were involved in 13% of healthcare breaches in 2017, 34% on average from 2018 to 2026, and 43% in the first half of 2026

Part 2 of 3. In March 2026, OCR settled a breach affecting fifteen million people for roughly the price of a used car. If your first reaction to that number is relief, this post is for you — because it says something very different from what it appears to say, and because the delayed Security Rule is about to change what every company that touches ePHI on someone else’s behalf owes its customers.

The settlement that should worry you most

On March 5, 2026, the HHS Office for Civil Rights announced a resolution with MMG Fusion, a software company serving oral healthcare practices.

The numbers, in order:

  • An unauthorized actor accessed the company’s systems in December 2020.
  • Protected health information belonging to approximately 15 million individuals was compromised — names, phone numbers, addresses, email addresses, dates of birth, appointment information.
  • That data appeared on the dark web.
  • The breach was never reported.
  • OCR did not learn of it from a breach notification. It opened an investigation in March 2023, after receiving a complaint.
  • The settlement was $10,000.

OCR cited three failures: impermissible disclosure of PHI, failure to conduct an accurate and thorough risk analysis, and failure to notify the covered entities of the breach (HHS; HIPAA Journal).

Ten thousand dollars for fifteen million people. If your first reaction is relief — so this is what enforcement actually looks like, we can live with that — read the rest of this section carefully.

OCR stated the amount reflected consideration of the company’s financial condition.

That is the whole story. The penalty was not small because the conduct was minor. It was small because there was almost nothing left to collect from. The fine is not a price list. It is a tombstone.

And look at who was left holding the consequences. The dental practices that trusted MMG Fusion with their patients’ data were never told. Their patients’ information sat on the dark web while those practices went on answering “yes” on their own compliance attestations. OCR Director Paula M. Stannard’s statement went directly to that point: “When a breach occurs, business associates must notify affected covered entities without unreasonable delay and within 60 calendar days of discovery.”

The corrective action plan runs three years. Risk analysis, risk management plan, written policies and procedures, workforce training, and a retroactive breach risk assessment with notification to every affected entity — five years after the fact.

If you build software that touches protected health information, MMG Fusion is not a cautionary tale about a bad actor. It is a cautionary tale about a company that almost certainly believed a breach was an IT problem rather than a regulatory one, and found out otherwise on a five-year delay.

You are no longer the bystander in this data

For most of HIPAA’s history, breaches were something that happened at healthcare organizations. That has quietly, structurally inverted.

PeriodShare of healthcare breaches involving a business associate
201713%
2018–2026 average34%
First half of 202643%

The concentration of impact is starker still. In 2015, 5% of individuals affected by healthcare breaches were affected at a business associate. By 2025, that figure was 65% (HIPAA Journal).

Two incidents explain much of that: Change Healthcare in 2024 and Conduent in 2025, together affecting roughly 255 million individuals. But the trend line does not depend on the outliers. OCR has now penalized a steady run of business associates — Consociate, MMG Fusion, BST & Co. CPAs, Comstar, Health Fitness Corporation, USR Holdings, Virtual Private Network Solutions, and Elgon Information Systems among them.

A note on rigor, because it matters in this particular market. You will see claims that “72%” or “89%” of healthcare breaches involve third-party vendors. Both circulate widely in vendor marketing. Both trace back to loose readings of a 2023 industry report, and neither reconciles with OCR’s own breach portal. The figures above come from breach portal data and are more than alarming enough. If a security partner quotes you the 89%, ask them where it came from.

What the delayed rule does to you specifically

Part 1 of this series covered why the Security Rule’s slip from May 2026 to July 2027 is not the reprieve the industry is treating it as. For business associates, the argument is even more direct, because several of the proposed requirements are not internal hygiene. They are recurring obligations you owe your customers — and the moment your customers know they are coming, those obligations start showing up in contracts, well before the rule is final.

From the HHS fact sheet on the proposed rule (primary source):

  • Annual written verification. Business associates must verify to covered entities, at least once every 12 months, that they have deployed the technical safeguards the Security Rule requires. This is not a signature on a BAA. Guidance indicates the verification must be validated by qualified cybersecurity personnel — an expertise bar, not an attestation checkbox.
  • 24-hour contingency plan notification. Business associates must notify covered entities — and subcontractors must notify business associates — upon activation of their contingency plans, without unreasonable delay and no later than 24 hours after activation.
  • 24-hour access-change notification. Notification within 24 hours when a workforce member’s access to ePHI or relevant systems is changed or terminated.
  • 72-hour restoration procedures. Written procedures to restore the loss of certain critical systems and data within 72 hours.
  • Asset inventory and network map showing how ePHI moves through your systems, maintained on an ongoing basis and refreshed at least every 12 months and on any material change.
  • Vulnerability scanning every six months; penetration testing every 12 months.
  • An annual compliance audit.
  • MFA and encryption at rest and in transit, with limited exceptions.
  • Elimination of the “addressable” category — the flexibility to document why you did not implement a safeguard goes away.

Read the first three again with a product engineering hat on. A 24-hour notification obligation on contingency plan activation is not a policy document. It is an on-call rotation, a defined trigger threshold, a customer contact database that is actually current, and a decision-maker reachable on a Saturday. A 24-hour access-change notification is a provisioning integration. A 72-hour restoration commitment is a tested recovery architecture with a number attached to it.

None of those get built in the quarter a deal is closing.

The commercial argument, which is the one that actually matters

Most founders treat this as compliance cost. It is more accurately a revenue mechanic, and reframing it that way changes where it sits on the roadmap.

Security review is now a gating stage in the enterprise healthcare sales cycle, not a formality after the handshake. Health systems, payers, and PE-backed platforms run vendor diligence before contract. The pattern I see most often in health tech is not a company that fails the review — it is a company that stalls in it: weeks of back-and-forth on a questionnaire nobody owns internally, a pen test that has to be scheduled from scratch, an architecture diagram that does not exist yet, a subprocessor list assembled by asking around.

That delay lands at the worst possible moment: late in a quarter, late in a runway, with a champion on the buyer’s side losing momentum.

The certifications follow the same logic. SOC 2 has become the price of entry for a first serious enterprise logo. HITRUST is what gets asked for once you are handling meaningful volumes of ePHI or selling into risk-averse systems. Neither is worth pursuing because a competitor has one. Both are worth pursuing when your actual pipeline is asking for them — and the sequence matters, because a certification built on top of an unknown asset inventory fails expensively and publicly.

The expensive version of this work is retrofitting controls into shipped product at Series B under a contractual deadline. The inexpensive version is architecting for it before Series A, when changing how data flows still costs a sprint instead of a quarter.

The AI problem is now your customer’s diligence problem

AI adoption in clinical documentation, revenue cycle, and analytics depends on large data volumes and increasingly complex vendor chains — frequently layered onto legacy systems that were never built for it.

Your customers know this. Vendor questionnaires now carry AI-specific sections: which model providers you use, what your data retention terms are, whether customer data trains anything, who your subprocessors are, and where a human sits in the loop. “We use a third-party API” is not an answer that survives a health system’s security review anymore.

Under the proposed rule, your covered-entity customers will be required to obtain written verification from you. That obligation flows downhill into your contracts whether or not you have prepared for it.

And the mirror risk sits inside your own company. Shadow AI now accounts for 43% of security incidents, at an average breach cost of $5.39 million, with one in five resulting in a regulatory fine (IBM Cost of a Data Breach Report 2026). Your engineers are using AI coding assistants. Your support team is pasting tickets into chatbots. If ePHI is anywhere in those flows and it is not in your risk analysis, you have the MMG Fusion problem in embryo — an exposure you do not know you have, which is precisely the kind that goes unreported.

What to do, in order

The sequence matters more than the speed. Skipping steps is what produces certifications that do not survive an incident.

1. Establish what you actually are

Determine your role precisely — business associate, subcontractor, or both — and get the BAA chain right end to end, including every subprocessor. A surprising number of health tech companies have an incomplete map of who downstream of them touches ePHI.

2. Risk analysis and asset inventory, before any certification

Every OCR enforcement action discussed in this series cited the risk analysis. It is also the foundation the asset inventory, the network map, and every framework audit sit on. Do it first. A SOC 2 built on an inventory nobody trusts is an expensive document.

3. Build the notification machinery now

The 24-hour obligations are operational, not documentary. Define the trigger thresholds, name the on-call owner, maintain a current customer contact list, and run the drill once before you need it.

4. Sequence certifications against your actual pipeline

HIPAA compliance first, then SOC 2, then HITRUST if and when your buyers require it. Let the pipeline set the order, not the competitive landscape.

5. Stand up AI governance

Model inventory, data flow mapping, subprocessor register, retention terms, and a written policy on what may and may not be put into a general-purpose tool. Your customers will ask. Increasingly, they will ask in writing. This is what an AI and third-party vendor risk assessment is built to produce.

6. Turn the evidence into a sales asset

Assemble the package once and maintain it: current SOC 2 report, penetration test summary, architecture and data-flow diagrams, subprocessor list, and pre-drafted responses to the standard questionnaires. The goal is that security review stops adding sixty days to every enterprise deal.

The number to remember

Not $10,000. That figure is an artifact of one company’s balance sheet at the end of a five-year investigation.

The number to remember is fifteen million — the people whose information ended up on the dark web because a software vendor did not conduct a risk analysis, and then did not tell anyone what had happened.

And the second number is 43%: the share of healthcare breaches that now run through a company like yours.

The Security Rule overhaul is not scheduled to be finalized until July 2027. Your customers’ procurement teams are not waiting for it, and neither is OCR.

Start with 30 minutes

Cybersecurity Advisory Group builds security programs for health tech and digital health companies at the stage where it is still inexpensive to do. SOC 2 and HITRUST readiness, AI and third-party vendor risk assessment, and complete security program builds for companies that do not yet have one — sized for a startup’s budget and sequenced against your actual sales pipeline.

Book a free 30-minute Security Clarity Session. We’ll go through where your controls stand today, which of the proposed business associate obligations you are furthest from meeting, and what your buyers are most likely to ask for next. No pressure, no jargon, and no homework before we talk.

Book Your Free 30-Minute Security Clarity Session →

Part 1 of this series — HIPAA’s Deadline Moved. OCR’s Didn’t. — covers what the delay means for provider organizations. Part 3 covers private equity and portfolio-wide risk.

Sources

Enforcement

Vendor and business associate breach data

Proposed Security Rule requirements

Cost and AI risk data

Melissa Thornton is the founder of Cybersecurity Advisory Group, providing virtual CISO and fractional cybersecurity leadership to healthcare organizations, startups, and SMBs. Based in White Plains, NY, serving clients remotely nationwide. sales@cyberadvisor.tech · +1 914-517-0022

This article is provided for general informational purposes and does not constitute legal advice.

Connect with Melissa Thornton on LinkedIn

Related Blogs

August 26, 2026
August 26, 2026

The Enforcement Lag Is Now Shorter Than Your Hold Period

Read More
Four-quarter roadmap for HIPAA Security Rule readiness during the twelve-month delay: establish ground truth, close the controls, build the testing cadence, vendors and evidence
August 25, 2026
August 25, 2026

HIPAA’s Deadline Moved. OCR’s Didn’t.

Read More
Healthcare executive reviewing a holographic dashboard showing cybersecurity infrastructure allocation, grant accessibility, and a multi-year vCISO roadmap
August 22, 2026
August 22, 2026

Modernize with Confidence: How Rural Hospitals Can Leverage New Funding for Stronger Cybersecurity

Read More