DisclosureLens
MICHIGANHackingHealthcareHealthcareBusiness Associate (HIPAA)Customer Data InvolvedDelayed DiscoveryHealth (basic)Identity (basic)Government IDHighResolved

Lansing Community College Dental Care Plan

bd_fa0386a4cbc25c24 · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Jul 11, 2011

To disclose

Affected

5,000

Confidence

95%
Full breach record for Lansing Community College Dental Care Plan

Lansing Community College (as Business Associate) reported to HHS on 2011-07-11 a Hacking/IT Incident affecting approximately 5,000 individuals. An unknown external actor from a foreign IP address attempted to bypass security mechanisms on a network server belonging to former BA AssureCare Risk Management, which administered the Lansing Community College Dental Care Plan. The server contained PHI including names, addresses, SSNs, and clinical information. Forensic investigation by Kroll Background America found it unlikely that member data was exfiltrated. The BA shut down the server, notified HHS, affected individuals, and media, and overhauled its security policies.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline — partial

? — ?

Breach window unknown

Jul 11, 2011

Filed

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Part of Assurecare Risk Management, Inc. supply-chain incident (2011) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed5,000 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.