Ingham County Medical Care Facility, d/b/a Dobie Road Data Breach
Ingham County Medical Facility Hit by Electronic Records Hack
What happened in the Ingham County Medical Care Facility, d/b/a Dobie Road data breach?
The Ingham County Medical Care Facility, d/b/a Dobie Road data breach was reported on January 5, 2025 and affected 3,078 individuals. The breach type was Hacking/IT Incident involving Electronic Medical Record. This breach occurred in Michigan. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Ingham County Medical Care Facility, d/b/a Dobie Road Breach Details
Ingham County Medical Care Facility Data Breach Report
Incident Overview
Inham County Medical Care Facility, operating under the name Dobie Road, experienced a significant data breach involving unauthorized access to its electronic medical record (EMR) system. The breach was reported to the Michigan Department of Attorney General on January 5, 2025, affecting 3,078 individuals. This hacking incident represents a serious compromise of patient privacy and protected health information (PHI) stored within the facility's digital infrastructure. The breach occurred through unauthorized access to the facility's EMR system, which typically contains comprehensive patient medical histories, treatment records, and associated personal identifiers.
Discovery and Response Timeline
The specific discovery date and initial response timeline have not been publicly detailed in the breach notification submission. However, standard HIPAA breach response protocols require that covered entities and their business associates conduct a thorough investigation upon discovering unauthorized access to PHI. Ingham County Medical Care Facility would have been obligated to determine the scope of the breach, identify affected individuals, and initiate notification procedures within 60 days of discovery. The involvement of a business associate in this incident suggests that the breach may have occurred through a third-party vendor or contractor with access to the facility's EMR systems, which is increasingly common in healthcare IT environments where multiple vendors manage different aspects of electronic health records.
Technical Details of the Breach
The breach is classified as a hacking/IT incident, which typically indicates unauthorized access through digital means rather than physical theft or loss of devices. Hacking incidents targeting healthcare EMR systems often involve techniques such as credential compromise, exploitation of unpatched vulnerabilities, phishing attacks targeting staff members, or unauthorized access through compromised business associate systems. The fact that a business associate was involved suggests the breach vector may have originated through a third-party connection, supply chain vulnerability, or inadequate access controls between the facility and external vendors. EMR systems are high-value targets for threat actors because they contain comprehensive patient data that can be used for identity theft, medical fraud, or sold on dark web marketplaces. The breach likely exposed data stored across multiple patient records within the facility's centralized electronic system, potentially affecting years of accumulated medical information.
Organizational Context
Inham County Medical Care Facility, d/b/a Dobie Road, is a healthcare provider operating in Ingham County, Michigan. Based on the facility name and operational structure, this appears to be a medical care facility serving the Lansing metropolitan area and surrounding communities. The facility's use of electronic medical records systems indicates it maintains modern healthcare IT infrastructure, though the breach demonstrates that such systems require continuous security monitoring and vendor management. The involvement of a business associate in the breach highlights the complex ecosystem of healthcare IT, where facilities often rely on external vendors for EMR hosting, maintenance, data backup, and security services. This distributed responsibility model, while necessary for operational efficiency, creates additional security challenges and potential vulnerabilities if business associates do not maintain equivalent security standards.
Patient Impact and Affected Individuals
Approximately 3,078 individuals had their protected health information potentially compromised in this breach. These patients likely include current and former patients of Ingham County Medical Care Facility whose records were stored in the compromised EMR system. The breach notification process, required under HIPAA's Breach Notification Rule, obligates the facility to provide written notice to each affected individual without unreasonable delay and no later than 60 calendar days after discovery of the breach. Notifications must include a description of the breach, types of information involved, steps individuals should take to protect themselves, what the facility is doing to investigate and prevent future breaches, and contact information for questions. Given the January 5, 2025 submission date, affected patients should have received or be receiving formal breach notification letters containing these required elements.
Data Exposure and Privacy Implications
Electronic medical record systems typically contain comprehensive patient information including names, dates of birth, medical record numbers, Social Security numbers, insurance information, diagnoses, treatment histories, medication records, laboratory results, imaging reports, and clinical notes. Depending on the scope of the EMR compromise, any or all of these data elements may have been exposed. The exposure of medical information combined with personal identifiers creates significant risk for identity theft, medical fraud, and unauthorized use of insurance benefits. Additionally, the sensitive nature of medical records—including information about diagnoses, treatments, and mental health conditions—creates privacy concerns beyond financial fraud. Patients may face discrimination or embarrassment if their medical information is disclosed to unauthorized parties. The breach also raises concerns about the confidentiality of the doctor-patient relationship and the trust patients place in healthcare providers to protect their most sensitive personal information.
HIPAA Compliance and Industry Context
This breach represents a violation of HIPAA's Security Rule, which requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect electronic PHI. The breach also triggers obligations under HIPAA's Breach Notification Rule, requiring notification to affected individuals, the media (if more than 500 residents of a state are affected), and the Secretary of Health and Human Services. Healthcare data breaches involving hacking and IT incidents have increased significantly in recent years, with the U.S. Department of Health and Human Services Office for Civil Rights reporting hundreds of breaches annually affecting millions of patients. Hacking incidents now represent one of the leading causes of healthcare data breaches, surpassing theft and loss of devices. The involvement of business associates in breaches underscores the importance of vendor risk management, contractual security requirements, and regular security assessments of third-party systems that access patient data. Healthcare organizations are increasingly implementing zero-trust security models, multi-factor authentication, encryption, and continuous monitoring to defend against sophisticated cyber threats.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Ingham County Medical Care Facility, d/b/a Dobie Road Breach
Monitor credit reports and financial accounts closely for signs of identity theft or fraudulent activity; consider placing a credit freeze or fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion)
Review explanation of benefits (EOB) statements from your insurance provider and medical bills for unauthorized charges or claims you did not authorize; contact your insurance company immediately if you identify suspicious activity
Consider enrolling in credit monitoring and identity theft protection services if offered by the facility; many breached entities provide complimentary monitoring for affected individuals
Change passwords for any online healthcare portals, insurance accounts, and related services; use strong, unique passwords and enable multi-factor authentication where available
Contact Ingham County Medical Care Facility directly using the contact information provided in the breach notification letter to ask specific questions about what information was exposed and what protective measures are being implemented
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you believe your information has been misused; maintain documentation of any fraudulent activity
Consider consulting with a healthcare privacy attorney if you experience significant harm or financial loss as a result of the breach
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Michigan Breaches
Search all breaches reported in Michigan