HHS OCR Settles with Dental Software Company MMG Fusion, 15M PHI Records Exposed; FQHCs Using This Software Must Verify BAAs
Issue
HHS OCR settled with MMG Fusion LLC (dental practice management software) for an impermissible disclosure of PHI affecting approximately 15 million individuals — OCR's 11th enforcement action under its Security Risk Analysis Initiative at the time. Penalty: $10,000 + 3-year corrective action plan.
Any FQHC using MMG Fusion must verify its BAA and reassess vendor risk. Count update (verified 2026-07-31): the Initiative has moved well past 11. Nixon Peabody reports the June 18, 2026 Spencer Gifts LLC health-plan settlement ($450,000) as OCR's 20th ransomware action and 14th Risk Analysis Initiative action — note the analysis is dated July 21 but the settlement is June 18, which is the kind of gap that produces mis-dated items.
Separately, OCR announced a $552,250 ransomware settlement with OSF Healthcare System (an Illinois hospital system, NOT an FQHC) around July 29-30, 2026; the HHS press page 403s so that date is approximate. The OSF action is worth FQHC attention for one transferable reason: OCR charged failure to issue timely breach notification (45 C.F.R.
164.404(b), 164.408(b)) as its own violation alongside inadequate risk analysis — directly relevant to the two tracked FQHC breaches still under OCR review (Erie Family Health Centers, ~570,000 individuals; Community Health Center of Buffalo). The operating lesson is unchanged and now better evidenced: organizations without a documented annual security risk analysis face real enforcement risk, and the notification clock starts at detection.
Key points
- FQHCs using MMG Fusion dental software: verify your Business Associate Agreement immediately and conduct a vendor risk assessment
- OCR's Security Risk Analysis Initiative is accelerating — organizations without an annual documented SRA face increasing enforcement exposure
Sources for this story
HHS OCRSources for your board packet
This story's source plus 4 related stories and their sources, ready to print for your team or board.
Free. Unlocking the packet subscribes you to Intel Brief. You'll be subscribed right away, with no confirmation email. Unsubscribe with one click in any issue. If you unsubscribed before, we won't re-add you. We never sell your email. You can open each source above without an email.
Part of
- Enforcement: privacy, fraud and audits
Data breaches · HIPAA rules and OCR enforcement
FQHC Talent. (2026, March 5). HHS OCR Settles with Dental Software Company MMG Fusion, 15M PHI Records Exposed; FQHCs Using This Software Must Verify BAAs. Source: HHS OCR. Retrieved October 6, 2026, from https://www.fqhctalent.com/intel/ocr-hipaa-mmg-fusion-dental-software-2026
More in Risk & Compliance
Sep 29
HHS civil rights office says when states can use substance use records
Sep 25
CMS and 37 states pledge to judge Medicaid by health outcomes
Sep 24
Geiger Gibson review finds health centers expect a heavy work-rule frailty burden
Sep 24
CMS seeks input on Part D pharmacy contract terms, including 340B claims