惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
小众软件
小众软件
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
Apple Machine Learning Research
Apple Machine Learning Research
月光博客
月光博客
人人都是产品经理
人人都是产品经理
大猫的无限游戏
大猫的无限游戏
V
V2EX
阮一峰的网络日志
阮一峰的网络日志
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - Franky
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
Hugging Face - Blog
Hugging Face - Blog
Jina AI
Jina AI
博客园 - 聂微东
S
SegmentFault 最新的问题
量子位
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园_首页

Privacy & Cybersecurity Law Blog

EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template
HHS’ Office for Civil Rights Settles HIPAA Investigation ...
2026-04-09 · via Privacy & Cybersecurity Law Blog

HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company

The U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) recently announced a settlement with MMG Fusion, LLC (“MMG”), a Maryland-based health care software company, to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

According to OCR’s announcement, MMG operates as a business associate that receives protected health information (“PHI”) from covered entities and provides software used to communicate directly with patients. The investigation was initiated in March 2023 following a complaint regarding an unreported security incident and the appearance of PHI on the dark web.

OCR’s investigation determined that in December 2020, an unauthorized actor infiltrated MMG’s systems and accessed PHI, including names, phone numbers, mailing addresses, email addresses, dates of birth and appointment information, affecting approximately 15 million individuals.

OCR concluded that MMG: (i) impermissibly disclosed PHI; (ii) failed to conduct an accurate and thorough risk analysis to assess risks and vulnerabilities to the confidentiality, integrity and availability of electronic PHI ; and (iii) failed to timely notify covered entities of the breach, as required under the HIPAA Breach Notification Rule.

Settlement Terms and Corrective Action Plan

Under HHS’s resolution agreement, MMG agreed to:

  • conduct and complete an accurate and thorough HIPAA risk analysis;
  • develop and implement a risk management plan to address identified risks and vulnerabilities;
  • develop, maintain and revise written policies and procedures to comply with the HIPAA Privacy and Security Rules;
  • provide workforce training on HIPAA Privacy and Security Rule requirements; and
  • conduct a breach risk assessment of the December 2020 incident and provide affected covered entities with appropriate breach notification information.

OCR will monitor MMG’s compliance with the corrective action plan for three years. MMG also agreed to pay $10,000 to OCR, with the agency noting that it considered MMG’s financial condition in determining the settlement amount.