Business Associate Settles Alleged HIPAA Violations Following 15-Million-record Data Breach
The Department of Health and Human Services’ Office for Civil Rights (OCR) has announced another settlement under its risk analysis enforcement initiative, although the settlement also resolves violations of other HIPAA provisions – The failure of the business associate to notify its HIPAA-covered entity clients about a data breach, and the impermissible disclosure of the protected health information of 15 million individuals.
OCR launched an investigation in March 2023 in response to a January 2023 complaint from an individual about a data breach at MMG Fusion that had not been reported. MMG Fusion is a Maryland software provider that offers software solutions to oral healthcare providers. According to the complainant, data stolen in the incident had been posted to the dark web. When a data breach occurs at a business associate of a HIPAA-covered entity, the business associate must notify each affected covered entity within 60 days. The covered entities then have 60 days to ensure that notifications are issued to OCR (if the breach affected more than 500 individuals), to the individuals whose PHI was exposed, and the media (if more than 500 individuals in a single jurisdiction were affected).
OCR’s investigation determined that a data breach occurred in December 2020, affecting around 15 million individuals. Data stolen in the incident included names, phone numbers, mailing addresses, email addresses, dates of birth, and appointment dates/times. The affected covered entities had not been notified about the data breach. In addition, OCR determined that MMG Fusion had not conducted an accurate and thorough risk analysis to identify potential risks and vulnerabilities to electronic protected health information (ePHI) as required by the HIPAA Security Rule, and there had been an impermissible disclosure of the ePHI of 15 million individuals, in violation of the HIPAA Privacy Rule.
OCR imposes penalties for each violation of a HIPAA provision. OCR considers the severity of each and the impact such a breach will have on victims. Due to the nature of the compromised data, it could not be used in isolation for identity theft; however, the theft and publication of email addresses on the dark web would put the individuals at risk of phishing attempts. Only this year, OCR settled a risk analysis violation with Top of the World Ranch Treatment Center, which included a £103,000 financial penalty for the risk analysis violation. MMG Fusion’s settlement only included a $10,000 financial penalty to resolve three alleged violations of the HIPAA Privacy Rule, HIPAA Security Rule, and the HIPAA Breach Notification Rule. OCR explained that when determining an appropriate settlement amount, consideration was given to the financial position of the company.
The settlement includes an extensive corrective action plan, requiring an accurate and thorough risk analysis, the development and implementation of a risk management plan, updating its HIPAA policies and procedures, and providing staff HIPAA training. MMG Fusion must also conduct a risk assessment of the 2020 security breach and provide notifications to each covered entity, and to the extent possible, provide each with a list of the affected individuals.
“When a breach occurs, business associates must notify affected covered entities without unreasonable delay and within 60 calendar days of discovery,” said OCR Director, Paula M. Stannard. “This timeliness is crucial for a covered entity to meet its own breach notification obligations, such as timely notification to HHS and to individuals. As hacking becomes more ubiquitous, HIPAA Security Rule requirements, such as the need to have an accurate and thorough HIPAA risk analysis, are imperative for strengthening cybersecurity before a breach occurs.”
