A Maryland software vendor exposed the protected health information of roughly 15 million people, never told the healthcare providers who trusted it with that data, and ultimately settled with federal regulators for $10,000. The math is the story. When the Department of Health and Human Services’ Office for Civil Rights (OCR) announced its resolution agreement with MMG Fusion, LLC, the headline figure was not the penalty — it was the gap between the scale of the harm and the scale of the accountability, and what that gap says about how breaches at business associates quietly become everyone else’s problem.What happenedMMG Fusion is a business associate: a company that handles protected health information (PHI) on behalf of covered entities such as dental and medical practices. According to OCR, in December 2020 an unauthorized actor infiltrated MMG’s systems and accessed PHI that included names, phone numbers, mailing addresses, email addresses, dates of birth, and the dates and times of patients’ medical appointments. That data later surfaced for sale on the dark web.OCR did not learn about the incident from MMG. It opened its investigation in March 2023 after receiving a complaint about an unreported security incident and the posting of PHI online. In other words, the breach came to light through a tip, not through the notification process HIPAA requires. By the time investigators finished, OCR concluded that MMG had potentially violated the HIPAA Privacy, Security, and Breach Notification Rules on three fronts: impermissibly disclosing the PHI of approximately 15 million individuals, failing to conduct an accurate and thorough risk analysis of the risks to the electronic PHI it held, and failing to notify the covered entities affected by the incident.That last failure is the one that should worry every practice that outsources part of its technology stack. Under HIPAA, when a business associate suffers a breach, it must notify the covered entities it serves so those providers can, in turn, notify affected patients and regulators. MMG’s alleged silence didn’t just violate a rule — it broke the chain of notification that the entire framework depends on, leaving covered entities unaware that their patients’ data was circulating on criminal markets.Why the penalty was so smallA $10,000 settlement for a 15-million-record breach looks almost like a rounding error, and it invites an obvious question: how? OCR’s civil monetary penalties are calibrated to a range of factors, including an organization’s size, financial condition, and ability to pay. A small software vendor does not have the balance sheet of a national health insurer, and regulators weigh the practical reality that a punitive fine large enough to bankrupt a company collects nothing and helps no one.The more meaningful part of the resolution is the corrective action plan (CAP) that comes with it. MMG agreed to a CAP that OCR will monitor for three years, requiring the company to conduct an accurate and thorough risk analysis, develop and implement a risk management plan, update its HIPAA policies and procedures, train its workforce, and complete a risk assessment of the 2020 breach while finally providing the notifications it owed to affected covered entities. The dollar figure is symbolic; the ongoing federal oversight is the real cost.The pattern: identity, access, and the business-associate blind spotThe technical anatomy of the MMG incident — an intruder getting in, reaching PHI, and exfiltrating it undetected for long enough to end up on the dark web — is the same anatomy behind most modern healthcare breaches. Investigators repeatedly find that the damaging incidents in this sector combine credential theft, lateral movement, and data exfiltration, frequently through third parties. The organizations that get burned are rarely the ones with a single dramatic zero-day; they are the ones that never had a clear, current picture of who and what could reach sensitive data.That is fundamentally an identity and access problem, and it is why a rigorous, recurring risk analysis is HIPAA’s most under-appreciated requirement. Knowing where PHI lives, which accounts and systems can touch it, and how quickly you’d notice anomalous access is the difference between a contained incident and a 15-million-record disclosure. The discipline of governing those relationships — mapping accounts to data, enforcing least privilege, and reviewing access continuously — sits at the heart of any defensible program, the same territory covered in Everykey’s identity and access management guide. Business associates that skip the risk-analysis step aren’t just cutting a compliance corner — they’re operating without a map of their own exposure.Healthcare’s third-party exposure is not hypothetical or rare. The same quarter that produced the MMG settlement also saw large downstream breaches at healthcare-adjacent vendors, including the DentaQuest breach that affected more than 23 million people as reported by The CyberSignal. Each of these follows the business-associate blind spot: a covered entity’s patients are harmed by a vendor most of those patients have never heard of.The compliance takeawayFor covered entities, the lesson is that a business associate agreement (BAA) on file is not the same as assurance. The BAA is a contract; it is not evidence that the vendor has actually done a risk analysis, implemented access controls, or built a working breach-notification process. Providers should ask vendors for proof of a current risk assessment, confirm that notification obligations and timelines are spelled out in writing, and treat a vendor’s inability to answer basic questions about who can access PHI as the red flag it is.For business associates, MMG is a warning that the notification rule has teeth even when the fine is small. The three-year corrective action plan — with its mandated risk analyses, policy overhauls, and federal monitoring — is a heavier long-term burden than the $10,000 payment, and it is the direct consequence of not reporting. Silence after a breach doesn’t make the problem disappear; it converts a security incident into a compliance failure that regulators will supervise for years.Compliance obligations in this space keep widening, and the notification piece increasingly overlaps with state privacy law, leaving organizations to satisfy HIPAA and overlapping regimes at once. The through-line is simple: HIPAA doesn’t just ask organizations to protect data, it asks them to know their own risk and to speak up when that data is exposed. MMG Fusion did neither, and 15 million people paid the price for a $10,000 lesson.Sources and further reading:HHS OCR resolution announcement;HIPAA Journal coverage of the MMG Fusion settlement;DataBreaches.net report.