Skip to content

Lansing Urgent Care in Michigan shuts down system after network access attempt

The provider said the incident was likely unsuccessful but did not address INC Ransom’s claim or describe the shutdown’s operational impact.

Lansing Urgent Care’s blue-and-red logo and name mounted on the exterior wall of its Frandor clinic.
Exterior signage at Lansing Urgent Care’s Frandor clinic in Lansing, Michigan. (Lansing Urgent Care)

Lansing Urgent Care, an eight-clinic provider in Michigan, said it shut down its system after detecting an outsider’s attempt to access its network.

The disclosure followed an INC Ransom leak-site claim Monday that included document images presented as samples from Lansing Urgent Care. Ransomware.live recorded the listing about 24 hours before WILX published the provider’s account Tuesday. Lansing Urgent Care has not attributed the incident to INC or confirmed ransomware or data theft.

“Our security controls and protocols immediately detected the threat and shut down our system, preventing that access,” Lansing Urgent Care said in a written statement sent Friday to DysruptionHub through Sabo PR. Initial findings from its internal team and external technology provider indicated the incident was likely unsuccessful, the statement said.

INC Ransom leak-site page naming Lansing Urgent Care and showing three small document images presented as samples.
An INC Ransom leak-site listing names Lansing Urgent Care and displays three images presented as document samples. (Screenshot by DysruptionHub)

The provider said it hired a third-party forensic specialist to determine whether protected data was accessed or taken. WILX reported Wednesday that Lansing Urgent Care was also working with law enforcement to determine the nature and scope of the attempt.

The Friday statement did not say when the attempted access was detected, how long the shutdown lasted, whether or when the system was restored or which systems and locations were affected. It also did not address whether the shutdown disrupted patient care or administrative work.

Three images attributed to the INC listing show a 2015 safety data sheet for a third-party skin care product, one page from a Lansing Urgent Care business associate agreement and one page from an apparently incomplete employee nondisclosure agreement. The latter two are administrative documents, not patient or clinical records.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

The images show that INC published material it associated with the provider, but they do not authenticate the documents, establish that they were private or show how they were obtained. They also do not prove that INC accessed Lansing Urgent Care’s current network or stole protected information.

The episode follows another technology disruption at a Michigan clinic network. Cherry Health said in April that organizationwide technology problems disrupted phones while clinics remained open, although it had not publicly confirmed a cyber cause at the time.

Lansing Urgent Care’s response did not address whether INC’s listing was connected to the access attempt, whether it had authenticated the images or whether it received a ransom demand. It also did not provide final forensic findings.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
Joseph Topping

Joseph Topping

A writer, intelligence analyst, and technology enthusiast passionate about the connection between the digital and physical worlds. His views expressed here do not necessarily reflect those of his employer, and he writes here as an individual.

All articles

More in Healthcare

See all

More from Joseph Topping

See all