MMG Fusion 2020 Data Breach

MMG Fusion Dental Practice Management Platform Breach: 15 Million Patient Appointment & Contact Records Exposed

Healthcare Technology Company · Dental practice management and patient workflow services · Dental practice management platform · Global

MMG Fusion Dental Practice Management Platform Breach: 15 Million Patient Appointment & Contact Records Exposed

Dental practice management and marketing platform.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
54/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
15.5MRecords
2020Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
PHI / MedicalAppointments
AddressPhysical address
Classification Tags
Cloud MisconfigurationHealthcareMedicalPatients2020

Breach Summary

MMG Fusion, a Maryland-based dental practice management and marketing software company, suffered a data breach beginning on December 20 to 21, 2020 when an unauthorized actor infiltrated MMG's internal network and accessed and exfiltrated patient data from MMG's databases serving its dental-practice clients. The breach was not reported by MMG to HHS, to its covered-entity dental-practice clients, or to affected patients. The U.S. Department of Health and Human Services Office for Civil Rights only became aware of the incident in January 2023 when it received a complaint about an unreported security incident and the appearance of MMG-attributed protected health information on the dark web. OCR initiated a formal investigation in March 2023, and after nearly three years of investigation, announced a settlement with MMG on March 5, 2026 that included a $10,000 financial penalty and a three-year corrective action plan. The breach affected approximately 15 million individuals across MMG's dental-practice client base, with Have I Been Pwned indexing approximately 2.6 million unique email addresses among the records. Compromised fields included names, phone numbers, mailing addresses, email addresses, dates of birth, genders, marital status, physical addresses, dates and times of dental appointments, and a smaller number of bcrypt-hashed passwords for users with MMG portal accounts. The combination of contact details, demographic information, and dental-appointment dates provides unusual support for highly targeted phishing because attackers can reference real upcoming or past appointments by date and time. For affected patients, the practical risk profile is unusual because of the appointment-record exposure. The combination of name, date of birth, address, phone number, and confirmed dental-appointment dates supports targeted phishing referencing real visits, including fraudulent appointment-confirmation messages, billing-themed scams referencing real services, and identity-verification bypass at financial institutions where dental-practice context is volunteered as background. Affected patients with bcrypt-hashed password exposure should change passwords on any accounts where they reused the same password as their MMG-affiliated dental-practice portal. Because MMG never notified affected patients directly, many individuals remain unaware they were included in the dataset, and the risk of legacy phishing referencing genuine appointment information remains active years after the original breach.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

15.5M records analyzed

About MMG Fusion

MMG Fusion, LLC was a Maryland-based cloud-based software solutions provider founded in 2015 that supplied dental practice management and patient engagement tools to dental and orthodontic practices across the United States. The platform provided automated marketing, patient engagement, appointment reminders, online review management, and front-office workflow tools to its dental-practice clients. As a HIPAA business associate to numerous covered-entity dental practices, MMG Fusion held aggregated patient identity, contact, scheduling, appointment, and limited treatment records across millions of dental patients. The company operated the platform as a SaaS product accessed through web browsers, with both all-in-one and modular subscription offerings. By 2026 reporting, MMG Fusion was characterized in HHS settlement coverage as a company that effectively no longer exists as an active operating business.

Why They Hold Your Data

Dental practice-management platforms collect patient identity, contact details, insurance, billing, scheduling, treatment, and office workflow records across dental operations.

Recent Developments

The MMG Fusion breach went unreported by the company for more than two years. On March 5, 2026, the U.S. Department of Health and Human Services Office for Civil Rights announced a settlement with MMG Fusion to resolve HIPAA violations stemming from the 2020 breach. The settlement included a $10,000 financial penalty and a three-year corrective action plan to be monitored by HHS. The settlement amount drew widespread industry commentary as remarkably small relative to the 15-million-individual breach scope, with healthcare-compliance commentators citing the case as illustrative of HHS's limited enforcement capacity for covered entities and business associates that have effectively wound down. OCR found that MMG had impermissibly disclosed PHI of approximately 15 million individuals, failed to conduct an accurate and thorough risk analysis of electronic PHI, and failed to notify affected covered entities about the breach as required under the HIPAA Breach Notification Rule.

Data Points Exposed

9 verified field types
Appointments
Date of Birth High
Email Address
Full Name
Gender
Password High
Phone Number
Physical address High
Relationship Status

Breach Impact

The institutional impact on MMG Fusion was substantial in regulatory and reputational terms but limited in financial penalty. The HHS settlement of $10,000 plus a three-year corrective action plan resolved the formal federal investigation, but the company appears to no longer operate as an active business. Affected dental-practice covered entities were never notified by MMG of the breach, leaving downstream patient-notification obligations effectively unfulfilled by the original responsible party. Civil litigation has been limited because the underlying breach occurred in 2020 and the disclosure delay placed many class-action timelines at risk under state breach-notification statutes. The case has been widely cited in HIPAA compliance training as a leading example of business-associate notification failure and the consequences of inadequate risk analysis. Dental-practice covered entities that contracted with MMG have faced their own derivative reputational and litigation exposure.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Identity verification bypass using name + date of birth combination | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Reset any reused passwords and enable MFA on email first, then financial accounts.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation