惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
美团技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
aimingoo的专栏
aimingoo的专栏
腾讯CDC
WordPress大学
WordPress大学
Apple Machine Learning Research
Apple Machine Learning Research
F
Fortinet All Blogs
G
Google Developers Blog
MongoDB | Blog
MongoDB | Blog
Microsoft Azure Blog
Microsoft Azure Blog
小众软件
小众软件
Engineering at Meta
Engineering at Meta
博客园_首页
B
Blog RSS Feed
D
Docker
M
MIT News - Artificial intelligence
爱范儿
爱范儿
I
InfoQ

New Jersey Enacts New Restrictions on Health Care Facilities’ Use of Patient Data

New Jersey Enacts New Restrictions on Health Care Facilities’ Use of Patient Data HHS OCR Settles HIPAA Security Rule Investigation with Top of the World Ranch Treatment Center for $103,000 New York Attorney General Reaches $500,000 Settlement with Orthopedics Practice Over 2023 Data Breach
HHS’ Office for Civil Rights Settles HIPAA Investigation ...
2026-04-09 · via New Jersey Enacts New Restrictions on Health Care Facilities’ Use of Patient Data

HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company

The U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) recently announced a settlement with MMG Fusion, LLC (“MMG”), a Maryland-based health care software company, to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

According to OCR’s announcement, MMG operates as a business associate that receives protected health information (“PHI”) from covered entities and provides software used to communicate directly with patients. The investigation was initiated in March 2023 following a complaint regarding an unreported security incident and the appearance of PHI on the dark web.

OCR’s investigation determined that in December 2020, an unauthorized actor infiltrated MMG’s systems and accessed PHI, including names, phone numbers, mailing addresses, email addresses, dates of birth and appointment information, affecting approximately 15 million individuals.

OCR concluded that MMG: (i) impermissibly disclosed PHI; (ii) failed to conduct an accurate and thorough risk analysis to assess risks and vulnerabilities to the confidentiality, integrity and availability of electronic PHI ; and (iii) failed to timely notify covered entities of the breach, as required under the HIPAA Breach Notification Rule.

Settlement Terms and Corrective Action Plan

Under HHS’s resolution agreement, MMG agreed to:

  • conduct and complete an accurate and thorough HIPAA risk analysis;
  • develop and implement a risk management plan to address identified risks and vulnerabilities;
  • develop, maintain and revise written policies and procedures to comply with the HIPAA Privacy and Security Rules;
  • provide workforce training on HIPAA Privacy and Security Rule requirements; and
  • conduct a breach risk assessment of the December 2020 incident and provide affected covered entities with appropriate breach notification information.

OCR will monitor MMG’s compliance with the corrective action plan for three years. MMG also agreed to pay $10,000 to OCR, with the agency noting that it considered MMG’s financial condition in determining the settlement amount.