- State
- MI
- Covered entity type
- Healthcare Provider
- Individuals affected
- 3,947
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An unauthorized person evaded the network security of Ferris State University Michigan College of Optometry on December 1, 2011, and placed a malware program on the computer Ferris uses to operate its website, which had the technical ability to access its electronic files on certain network servers. The breach of electronic protected health information (ePHI) affected approximately 3,947 individuals and included patients' names, dates of birth, Social Security numbers, addresses, diagnoses/conditions, financial claims information, clinical information, and other treatment information. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media and posted substitute notification of the breach incident on its website. The CE created a dedicated call center regarding the breach and also offered one year of free credit monitoring to individuals whose social security number was involved in the breach. Following the breach, the CE engaged an outside forensic security firm to conduct an internal investigation, installed the latest operating systems and patches to its network asset and web server, and applyed the latest version of antivirus and malware on its servers. The CE verified the removal of ePHI from the application and archive files, worked with its customers to remove sensitive data, and blocked specific internet addresses from its networks. The CE also revised its policies and procedures addressing how it administratively, technically, and physically safeguards patients’ PHI. Additionally, the CE trained employees on its policies and procedures and documented its most recent risk analysis and corresponding risk management plan. OCR obtained documentation evidencing that the CE implemented the corrective actions listed.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.