HHS OCR HIPAA Settlements Today: MMG Fusion and Ransomware Fines

Recent HHS OCR HIPAA settlements show a consistent pattern: healthcare providers, health plans, and their vendors are paying financial penalties and accepting multi-year corrective action plans after ransomware attacks, phishing intrusions, and delayed breach notifications, with nearly every case citing the same underlying failure to conduct a proper security risk analysis. The most recent action came on April 23, 2026, when the HHS Office for Civil Rights announced four ransomware settlements totaling $1,165,000, following a March 2026 settlement with software vendor MMG Fusion over a breach that exposed 15 million records.

The April 2026 Ransomware Settlements

OCR resolved four ransomware investigations in a single announcement on April 23, 2026. Together the incidents exposed records for more than 427,000 people, and all four entities agreed to two-year corrective action plans on top of their payments.1HHS.gov. OCR Settles Four Ransomware Investigations

  • Assured Imaging, a mobile mammography provider, paid $375,000 after a May 2020 server infection affecting 244,813 individuals. OCR cited impermissible disclosures, an inadequate risk analysis, and late breach notification.1HHS.gov. OCR Settles Four Ransomware Investigations
  • Regional Women’s Health Group, doing business as Axia Women’s Health, paid $320,000 after a December 2020 intrusion into its electronic medical records system affecting 37,989 patients. The sole finding was failure to conduct a thorough risk analysis.1HHS.gov. OCR Settles Four Ransomware Investigations
  • Star Group Health Benefits Plan, a self-funded employer plan, paid $245,000 after an October 2021 attack that exfiltrated data on 9,316 people. OCR found impermissible disclosures and no risk analysis.1HHS.gov. OCR Settles Four Ransomware Investigations
  • Consociate Health, a third-party benefits administrator, paid $225,000. OCR traced the breach to a July 2020 phishing attack that eventually exposed the records of roughly 136,539 individuals, including Social Security and bank account numbers.2Paubox. OCR Settles Four HIPAA Ransomware Cases Affecting 427K

MMG Fusion: 15 Million Records, $10,000 Settlement

The March 5, 2026 settlement with MMG Fusion, LLC, a Maryland-based dental practice software vendor, stands apart on both scale and penalty. On December 21, 2020, an unauthorized actor exfiltrated data on approximately 15 million individuals from the company’s internal network. MMG Fusion never reported the breach. OCR only learned of it in January 2023 through a third-party complaint after the data surfaced on the dark web.3HIPAA Journal. MMG Fusion HIPAA Settlement

OCR found no complete risk analysis, an impermissible disclosure, and a breach notification more than five years overdue. The settlement was $10,000. OCR stated it weighed MMG Fusion’s financial condition; reporting indicated the company was effectively insolvent, and the agreement was signed by a successor entity, HIQOR Dental. Under the HITECH Act, OCR must consider ability to pay, and here it chose a collectible amount paired with a three-year corrective action plan over an uncollectible fine.4HHS.gov. OCR MMG Fusion HIPAA Agreement5The HIPAA E-Tool. Millions of Records, $10,000 Fine: MMG Fusion Lesson

The Risk Analysis Thread

Look across the recent docket and the same violation keeps appearing. OCR formalized this focus in fall 2024 with its Risk Analysis Initiative, a targeted enforcement program responding to a 264% increase in large ransomware breaches between 2018 and 2024. In its first six months, the initiative produced seven enforcement actions, every one citing an inadequate assessment of risks to the confidentiality, integrity, and availability of electronic protected health information.6Feldesman Tucker Leifer Fidell LLP. OCR’s New Security Risk Analysis Initiative Results in Seven Enforcement Actions

The Security Rule requires covered entities and business associates to conduct an accurate and thorough analysis of threats and vulnerabilities to the ePHI they hold. In practice, that means knowing where patient data lives, how it moves, who touches it, and what could go wrong. OCR treats a missing or superficial analysis as its own violation, independent of whatever attack followed.

Notable 2025 Settlements

OCR closed 21 enforcement actions in 2025, collecting $8,330,066, its second-most active year on record.7HIPAA Journal. 2025 Healthcare Data Breach Report Several cases show the range of conduct and penalty size.

Solara Medical Supplies — $3 million. Between April and June 2019, phishing attacks compromised eight employee email accounts, exposing 114,007 individuals’ Social Security numbers, payment card data, and medical information. Solara then mailed 1,531 breach notification letters to wrong addresses in January 2020, creating a second reportable breach. OCR cited an inadequate risk analysis, weak security measures, and missed the 60-day notification deadline.8HHS.gov. Solara Medical Supplies Resolution Agreement and Corrective Action Plan

Warby Parker — $1.5 million civil money penalty. Between September and November 2018, attackers used credentials stolen from unrelated breaches to log into 197,986 customer accounts, exposing payment card information and eyewear prescriptions. Similar attacks recurred in 2020 and 2022. Warby Parker waived its right to a hearing, and the CMP was finalized in December 2024. A civil money penalty rather than a negotiated settlement generally signals that OCR could not reach an informal resolution.9HHS.gov. Penalty Against Warby Parker

Other 2025 outcomes included BayCare Health System at $800,000 for allowing a former employee’s credentials to access patient records, PIH Health at $600,000 for a phishing-related breach, and Northeast Radiology at $350,000 for a breach affecting 298,532 patients whose radiology images sat on a picture archiving system. At the small end, Vision Upright MRI paid $5,000 after failing to conduct a risk analysis and failing to notify 21,778 individuals whose imaging data was exposed. OCR calibrates penalties in part to entity size and resources.7HIPAA Journal. 2025 Healthcare Data Breach Report

How OCR Sets Penalties

OCR resolves cases two ways. A resolution agreement is a negotiated settlement: the entity pays and agrees to a corrective action plan, typically running two to three years, during which OCR requires implementation reports and annual compliance updates. A civil money penalty is imposed when informal resolution fails; it carries no corrective action plan, so OCR loses the ability to mandate operational changes.10HHS.gov. HIPAA Enforcement Resolution Agreements

Penalty amounts are tiered by culpability. Under the inflation-adjusted 2026 schedule, a violation an entity did not know about can draw a minimum of $145, while an uncorrected willful-neglect violation can reach up to $2,190,294 per violation per year.11HIPAA Journal. What Are the Penalties for HIPAA Violations OCR also considers an entity’s financial condition, which is how a 15-million-record breach can end in a $10,000 settlement.

What Corrective Action Plans Require

The plans that accompany settlements are structured similarly. Entities generally must conduct a new enterprise-wide risk analysis, develop a written risk management plan, revise HIPAA policies and distribute them to staff, provide job-specific training, and submit implementation and annual compliance reports to OCR. Recent plans also require mapping where patient data flows internally, implementing audit controls, and encrypting data at rest and in transit where appropriate. If an entity misses its corrective action obligations, OCR can treat the failure as a breach of the agreement and move to impose civil money penalties.12HHS.gov. OCR HIPAA Resolution Agreement and Corrective Action Plan (PIH)

What’s Changing at OCR

On May 18, 2026, HHS restructured the Office for Civil Rights into program-based divisions, including a Health Information Privacy, Data, and Cybersecurity Division and a separate Enforcement Division handling complaint intake and breach review. HHS stated the reorganization would not reduce OCR’s workforce.13HHS.gov. HHS Announces Restructuring of Its Office for Civil Rights The agency currently operates with 116 full-time employees and faces a $39.7 million budget deficit; the fiscal 2027 request seeks funding for 144 staff.14HIPAA Journal. HHS Restructuring Office for Civil Rights

A proposed overhaul of the HIPAA Security Rule, published in the Federal Register on January 6, 2025, remains unresolved. Its comment period closed in March 2025 after drawing nearly 4,750 comments, and a coalition of more than 100 healthcare organizations requested withdrawal, citing projected first-year compliance costs of $9 billion.15Federal Register. HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information Until that rulemaking is finalized or withdrawn, the Risk Analysis Initiative remains OCR’s primary lever for holding entities accountable after a cyber incident.