Lansing Community College (as Business Associate) reported to HHS on 2011-07-11 a Hacking/IT Incident affecting approximately 5,000 individuals. An unknown external actor from a foreign IP address attempted to bypass security mechanisms on a network server belonging to former BA AssureCare Risk Management, which administered the Lansing Community College Dental Care Plan. The server contained PHI including names, addresses, SSNs, and clinical information. Forensic investigation by Kroll Background America found it unlikely that member data was exfiltrated. The BA shut down the server, notified HHS, affected individuals, and media, and overhauled its security policies.
Affected (this filing): 5,000