CRITICAL SEVERITYMedical

MMG Fusion Data Breach

MMG Fusion Dental Practice Management Platform Breach: 15 Million Patient Appointment & Contact Records Exposed

Dental practice management and marketing platform.

Verified by ObscureIQ Intelligence

8.5Severity
15.5MRecords
10Fields
2020Year

ObscureIQ Breach Intelligence Scores
10.0
Breach Risk Index
25
Data Value
25
Market Recency
406
days
Since Breach

Risk Interpretation

High risk of identity theft, insurance fraud, and treatment-themed phishing. Dental platform data is especially sensitive because it may expose patient, provider, and financial workflows together.

🎯 Impact & Downstream Threats

The institutional impact on MMG Fusion was substantial in regulatory and reputational terms but limited in financial penalty. The HHS settlement of $10,000 plus a three-year corrective action plan resolved the formal federal investigation, but the company appears to no longer operate as an active business. Affected dental-practice covered entities were never notified by MMG of the breach, leaving downstream patient-notification obligations effectively unfulfilled by the original responsible part

Primary downstream threats:
  • Credential stuffing against reused passwords across other platforms
  • Identity verification bypass using name + date of birth combination
  • SIM swap attacks where phone numbers are present
  • Targeted phishing campaigns using exposed email addresses
  • Doxxing risk from physical address exposure

🔓 Threat Vectors

Vacancy confirmation & medical fraud
Identity verification bypass
Phishing, credential stuffing & account takeover
Name-based social engineering
Profile enrichment
Credential stuffing & account takeover
SIM swapping, vishing & SMS phishing
Physical stalking, mail fraud & identity verification
Home targeting, stalking & physical threat
Social engineering context
Romance & family emergency fraud

📋 Breach Intelligence

EntityMMG Fusion
Organization • Global
Breach Date2020-12-20
DBC Added2025-03-17
Added Date2025-03-17
Records~15.5M (15,544,392 records)
Attack VectorMisconfiguration
Threat ActorUnknown
Data SubjectsPatient
Breach PathwayDirect
SourceHave I Been Pwned / DataBreach.com / ObscureIQ
SensitivityElevated
Breach ID897;898
StatusConfirmed

📝 Executive Summary

MMG Fusion, a Maryland-based dental practice management and marketing software company, suffered a data breach beginning on December 20 to 21, 2020 when an unauthorized actor infiltrated MMG's internal network and accessed and exfiltrated patient data from MMG's databases serving its dental-practice clients. The breach was not reported by MMG to HHS, to its covered-entity dental-practice clients, or to affected patients. The U.S. Department of Health and Human Services Office for Civil Rights only became aware of the incident in January 2023 when it received a complaint about an unreported security incident and the appearance of MMG-attributed protected health information on the dark web. OCR initiated a formal investigation in March 2023, and after nearly three years of investigation, announced a settlement with MMG on March 5, 2026 that included a $10,000 financial penalty and a three-year corrective action plan.

The breach affected approximately 15 million individuals across MMG's dental-practice client base, with Have I Been Pwned indexing approximately 2.6 million unique email addresses among the records. Compromised fields included names, phone numbers, mailing addresses, email addresses, dates of birth, genders, marital status, physical addresses, dates and times of dental appointments, and a smaller number of bcrypt-hashed passwords for users with MMG portal accounts. The combination of contact details, demographic information, and dental-appointment dates provides unusual support for highly targeted phishing because attackers can reference real upcoming or past appointments by date and time.

For affected patients, the practical risk profile is unusual because of the appointment-record exposure. The combination of name, date of birth, address, phone number, and confirmed dental-appointment dates supports targeted phishing referencing real visits, including fraudulent appointment-confirmation messages, billing-themed scams referencing real services, and identity-verification bypass at financial institutions where dental-practice context is volunteered as background. Affected patients with bcrypt-hashed password exposure should change passwords on any accounts where they reused the same password as their MMG-affiliated dental-practice portal. Because MMG never notified affected patients directly, many individuals remain unaware they were included in the dataset, and the risk of legacy phishing referencing genuine appointment information remains active years after the original breach.

🏢 About MMG Fusion

MMG Fusion, LLC was a Maryland-based cloud-based software solutions provider founded in 2015 that supplied dental practice management and patient engagement tools to dental and orthodontic practices across the United States. The platform provided automated marketing, patient engagement, appointment reminders, online review management, and front-office workflow tools to its dental-practice clients. As a HIPAA business associate to numerous covered-entity dental practices, MMG Fusion held aggregated patient identity, contact, scheduling, appointment, and limited treatment records across millions of dental patients. The company operated the platform as a SaaS product accessed through web browsers, with both all-in-one and modular subscription offerings. By 2026 reporting, MMG Fusion was characterized in HHS settlement coverage as a company that effectively no longer exists as an active operating business.

Healthcare Technology Company | Dental practice management and patient workflow services | Dental practice management platform | Global
Globalmmgfusion.com

🗂 Why They Hold Your Data

Dental practice-management platforms collect patient identity, contact details, insurance, billing, scheduling, treatment, and office workflow records across dental operations.

📰 Recent Developments

The MMG Fusion breach went unreported by the company for more than two years. On March 5, 2026, the U.S. Department of Health and Human Services Office for Civil Rights announced a settlement with MMG Fusion to resolve HIPAA violations stemming from the 2020 breach. The settlement included a $10,000 financial penalty and a three-year corrective action plan to be monitored by HHS. The settlement amount drew widespread industry commentary as remarkably small relative to the 15-million-individual breach scope, with healthcare-compliance commentators citing the case as illustrative of HHS's limited enforcement capacity for covered entities and business associates that have effectively wound down. OCR found that MMG had impermissibly disclosed PHI of approximately 15 million individuals, failed to conduct an accurate and thorough risk analysis of electronic PHI, and failed to notify affected covered entities about the breach as required under the HIPAA Breach Notification Rule.

🔍 Data Points Exposed

10 verified field types:
Email
Phone Number
Name
Home Address;Appointments
Dates of birth
Email
Genders
Marital statuses
Names
Passwords
Phone numbers
Physical addresses

Exposure Categories

LocationPHYS ADDR

Canonical Fields

appointments, date_of_birth, email_address, full_name, gender, password, phone_number, physical_address, physical_address:home, relationship_status:marital

🌐 Dark Web Verification

Confirmed

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of MMG Fusion
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

MisconfigurationEmailPhoneAddressPasswordsDOB

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom