Lansing Community College Dental Care Plan
bd_fa0386a4cbc25c24 · schema v1 · pii pii-v1
Full breach record for Lansing Community College Dental Care Plan →Lansing Community College (as Business Associate) reported to HHS on 2011-07-11 a Hacking/IT Incident affecting approximately 5,000 individuals. An unknown external actor from a foreign IP address attempted to bypass security mechanisms on a network server belonging to former BA AssureCare Risk Management, which administered the Lansing Community College Dental Care Plan. The server contained PHI including names, addresses, SSNs, and clinical information. Forensic investigation by Kroll Background America found it unlikely that member data was exfiltrated. The BA shut down the server, notified HHS, affected individuals, and media, and overhauled its security policies.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 11, 2011
- Raw hash
- ff1042cc5a50a6b368979f69dfe57a565ce3672c1ef0b0df2ce10eaf367e6fed
Source filing
Reporting entity
- Name
- Lansing Community Collegenorm: lansing community college
- Domain
- lcc.edu
Victim entity
- Name
- Lansing Community College Dental Care Plannorm: lansing community college dental care plan
- Industry
- Insurance — Health
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 5,000
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- OCR obtained written documentation that the BA implemented corrective actions
- Third party
- via AssureCare Risk Managementbusiness associate
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.