Lansing Urgent Care, an eight-clinic provider in Michigan, said it shut down its system after detecting an outsider’s attempt to access its network.
The disclosure followed an INC Ransom leak-site claim Monday that included document images presented as samples from Lansing Urgent Care. Ransomware.live recorded the listing about 24 hours before WILX published the provider’s account Tuesday. Lansing Urgent Care has not attributed the incident to INC or confirmed ransomware or data theft.
“Our security controls and protocols immediately detected the threat and shut down our system, preventing that access,” Lansing Urgent Care said in a written statement sent Friday to DysruptionHub through Sabo PR. Initial findings from its internal team and external technology provider indicated the incident was likely unsuccessful, the statement said.

The provider said it hired a third-party forensic specialist to determine whether protected data was accessed or taken. WILX reported Wednesday that Lansing Urgent Care was also working with law enforcement to determine the nature and scope of the attempt.
The Friday statement did not say when the attempted access was detected, how long the shutdown lasted, whether or when the system was restored or which systems and locations were affected. It also did not address whether the shutdown disrupted patient care or administrative work.
Three images attributed to the INC listing show a 2015 safety data sheet for a third-party skin care product, one page from a Lansing Urgent Care business associate agreement and one page from an apparently incomplete employee nondisclosure agreement. The latter two are administrative documents, not patient or clinical records.
The images show that INC published material it associated with the provider, but they do not authenticate the documents, establish that they were private or show how they were obtained. They also do not prove that INC accessed Lansing Urgent Care’s current network or stole protected information.
The episode follows another technology disruption at a Michigan clinic network. Cherry Health said in April that organizationwide technology problems disrupted phones while clinics remained open, although it had not publicly confirmed a cyber cause at the time.
Lansing Urgent Care’s response did not address whether INC’s listing was connected to the access attempt, whether it had authenticated the images or whether it received a ransom demand. It also did not provide final forensic findings.