Auditen
sector watch

Millions of Records Lost. A Ten Thousand Dollar Fine.

The paperwork for a HIPAA breach is always tedious. It requires precise notifications, specific timelines and a level of transparency that usually makes corporate communications teams break out in hives. But if you are MMG Fusion, the paperwork is the hardest part.

They presided over a data breach involving some 15 million records. For this systemic failure, the fine was $10,000.

When you do the maths, that works out to roughly 67 cents per record. It isn't a penalty; it is a transaction fee. If a firm can lose the private health information of millions and walk away with a fine that wouldn't cover a junior consultant's monthly expenses, the regulation has ceased to be a deterrent. It has become a line item in the budget.

This brings us to the broader pressure on healthcare administration this week. We saw another practice management firm notify just under 4 million individuals about a 2025 breach. The pattern is clear: the risk has migrated away from the clinics and hospitals and settled firmly in the hands of the third-party vendors who manage the back office.

The regulatory response, however, remains inconsistent. Contrast the HIPAA apathy with the Irish Data Protection Commission's approach to GDPR. They are currently eyeing a fine for Tinder in the region of €8 million to €11 million. The scale of the punishment varies wildly depending on which regulator is holding the pen and which rulebook they are using. One treats privacy as a fundamental right; the other treats it as a clerical error.

Some might argue that HIPAA fines are intentionally scaled based on the "culpability" of the firm or their level of cooperation. They'll say that a $10,000 fine reflects a lack of wilful neglect.

That argument ignores the reality of the vendor market. Most healthcare providers don't conduct deep-dive audits of their software vendors; they check a box that says "HIPAA Compliant" and move on. If the regulator doesn't price the risk of a breach into the fine, there is no economic incentive for these vendors to actually secure the data. They only need to be compliant enough to pass a procurement checklist.

This creates a second-order effect for the insurers.

When regulators fail to punish negligence, the burden shifts to the cyber insurance market. Insurers aren't interested in whether a firm was "cooperative" with the HHS OCR; they are interested in the cost of notifying 15 million people and the subsequent litigation. We should expect to see premiums for practice management firms spike, regardless of whether the government gave them a slap on the wrist. The insurers will be the ones actually enforcing the standards that the regulators are ignoring.

The auditors are caught in the middle. They are tasked with verifying controls that they know are often toothless.

Look at EY Canada. The Canadian Public Accountability Board recently censured the firm for sharing answers on professional development courses. It is a dry story about cheating on tests, but it speaks to a deeper culture of "getting the answer" rather than doing the work. When the industry's leading auditors treat their own professional standards as optional, it's little wonder that third-party risk assessments in healthcare feel like a performance art piece.

Who is actually filing what this week? The practice management firms are filing breach notifications to millions of people. The insurance brokers are revising their risk models. The vendors are likely sighing with relief that $10,000 is the ceiling for a catastrophic leak.

The real question is whether the HHS OCR has any appetite to move away from these nominal fines. If they don't, "HIPAA compliance" will continue to be a badge of honour that signifies very little in terms of actual security.

I suspect we won't see a shift until a breach causes an actual systemic collapse rather than just a leak of records. Until then, the vendors can keep their fees high and their security budgets low.

The paperwork remains tedious, but at least it is cheap.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Data watchdog plans to fine dating firm Tinder between €8m and €11m - Irish Independent Compliance Week (Google News)
  2. Canadian Public Accountability Board censures EY Canada over answer sharing on professional development courses - Canadian Accountant Compliance Week (Google News)
  3. Practice Management Firm Notifies 3.8M of 2025 Breach - GovInfoSecurity InfoSec Compliance (Google News)
  4. The $10,000 Fine Behind a 15-Million-Record Breach: MMG Fusion and HIPAA's Weakest Link - HackerNoon InfoSec Compliance (Google News)
  5. AI Red Teaming, Explained: What Adversarial Testing Can Prove and What It Cannot - SQ Magazine InfoSec Compliance (Google News)
  6. CRA data breach: Some Canadians could be eligible for up to $5,000, compensation applications now open - BNN Bloomberg Data Privacy (Google News)
  7. Thai AirAsia Achieves IOSA Certification, Cementing World-Class Aviation Safety Standard - markets.businessinsider.com Compliance Week (Google News)
  8. Olenox Industries appoints Urish Popeck as new auditor, dismisses RBSM LLP - Investing.com Compliance Week (Google News)

How stories are selected and assessed