MMG Fusion Data Breach
MMG Fusion Dental Practice Management Platform Breach: 15 Million Patient Appointment & Contact Records Exposed
Dental practice management and marketing platform.
Risk Interpretation
High risk of identity theft, insurance fraud, and treatment-themed phishing. Dental platform data is especially sensitive because it may expose patient, provider, and financial workflows together.
Impact & Downstream Threats
The institutional impact on MMG Fusion was substantial in regulatory and reputational terms but limited in financial penalty. The HHS settlement of $10,000 plus a three-year corrective action plan resolved the formal federal investigation, but the company appears to no longer operate as an active business. Affected dental-practice covered entities were never notified by MMG of the breach, leaving downstream patient-notification obligations effectively unfulfilled by the original responsible part
- Credential stuffing against reused passwords across other platforms
- Identity verification bypass using name + date of birth combination
- SIM swap attacks where phone numbers are present
- Targeted phishing campaigns using exposed email addresses
- Doxxing risk from physical address exposure
Threat Vectors
Breach Intelligence
Executive Summary
MMG Fusion, a Maryland-based dental practice management and marketing software company, suffered a data breach beginning on December 20 to 21, 2020 when an unauthorized actor infiltrated MMG's internal network and accessed and exfiltrated patient data from MMG's databases serving its dental-practice clients. The breach was not reported by MMG to HHS, to its covered-entity dental-practice clients, or to affected patients. The U.S. Department of Health and Human Services Office for Civil Rights only became aware of the incident in January 2023 when it received a complaint about an unreported security incident and the appearance of MMG-attributed protected health information on the dark web. OCR initiated a formal investigation in March 2023, and after nearly three years of investigation, announced a settlement with MMG on March 5, 2026 that included a $10,000 financial penalty and a three-year corrective action plan.
The breach affected approximately 15 million individuals across MMG's dental-practice client base, with Have I Been Pwned indexing approximately 2.6 million unique email addresses among the records. Compromised fields included names, phone numbers, mailing addresses, email addresses, dates of birth, genders, marital status, physical addresses, dates and times of dental appointments, and a smaller number of bcrypt-hashed passwords for users with MMG portal accounts. The combination of contact details, demographic information, and dental-appointment dates provides unusual support for highly targeted phishing because attackers can reference real upcoming or past appointments by date and time.
For affected patients, the practical risk profile is unusual because of the appointment-record exposure. The combination of name, date of birth, address, phone number, and confirmed dental-appointment dates supports targeted phishing referencing real visits, including fraudulent appointment-confirmation messages, billing-themed scams referencing real services, and identity-verification bypass at financial institutions where dental-practice context is volunteered as background. Affected patients with bcrypt-hashed password exposure should change passwords on any accounts where they reused the same password as their MMG-affiliated dental-practice portal. Because MMG never notified affected patients directly, many individuals remain unaware they were included in the dataset, and the risk of legacy phishing referencing genuine appointment information remains active years after the original breach.
About MMG Fusion
MMG Fusion, LLC was a Maryland-based cloud-based software solutions provider founded in 2015 that supplied dental practice management and patient engagement tools to dental and orthodontic practices across the United States. The platform provided automated marketing, patient engagement, appointment reminders, online review management, and front-office workflow tools to its dental-practice clients. As a HIPAA business associate to numerous covered-entity dental practices, MMG Fusion held aggregated patient identity, contact, scheduling, appointment, and limited treatment records across millions of dental patients. The company operated the platform as a SaaS product accessed through web browsers, with both all-in-one and modular subscription offerings. By 2026 reporting, MMG Fusion was characterized in HHS settlement coverage as a company that effectively no longer exists as an active operating business.
Why They Hold Your Data
Dental practice-management platforms collect patient identity, contact details, insurance, billing, scheduling, treatment, and office workflow records across dental operations.
Recent Developments
The MMG Fusion breach went unreported by the company for more than two years. On March 5, 2026, the U.S. Department of Health and Human Services Office for Civil Rights announced a settlement with MMG Fusion to resolve HIPAA violations stemming from the 2020 breach. The settlement included a $10,000 financial penalty and a three-year corrective action plan to be monitored by HHS. The settlement amount drew widespread industry commentary as remarkably small relative to the 15-million-individual breach scope, with healthcare-compliance commentators citing the case as illustrative of HHS's limited enforcement capacity for covered entities and business associates that have effectively wound down. OCR found that MMG had impermissibly disclosed PHI of approximately 15 million individuals, failed to conduct an accurate and thorough risk analysis of electronic PHI, and failed to notify affected covered entities about the breach as required under the HIPAA Breach Notification Rule.
Data Points Exposed
Exposure Categories
Canonical Fields
appointments, date_of_birth, email_address, full_name, gender, password, phone_number, physical_address, physical_address:home, relationship_status:marital
Dark Web Verification
- Dataset containing ~15.5M records identified in breach intelligence sources
- Data indexed and searchable across breach notification platforms
- Source: mmg-fusion-2020;MMG Fusion Data Breach
Recommended Actions
⚠️ Do not assume this is low sensitivity.
Protect Yourself
Check If You’re Affected
Enter your email to check if your data appears in this breach.
Get Free Breach Alerts
Be the first to know when new breaches are disclosed.
High-Risk? Get an Exposure Audit
Full-spectrum exposure audits for executives and public figures.
ObscureIQ Advisory
We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.
- A public-facing individual
- A high-profile executive
- A customer of MMG Fusion
- Or concerned about credential reuse
Powered by the ObscureIQ Breach Intelligence Database
© 2026 ObscureIQ · All Rights Reserved · Data Licensing
Latest from ObscureIQ
What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.
Sextortion Spam
