ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Welcome to the American Heart Association’s movement to change the future of health and be the progress that ensures longer, healthier lives for all. By driving breakthroughs in science, policy, and care – together -- we can overcome today’s biggest health challenges and transform lives every day. The American Heart Association is the nation’s oldest and largest voluntary organization dedicated to fighting heart disease and stroke. We are advocates of good health and promoters of positive behaviors, nutritious eating habits and healthy lifestyles. We also fund cutting-edge research and professional education programs. We promise to have an extraordinary impact on your life by empowering you and your loved ones to save lives, live healthier and enjoy more peace of mind about cardiovascular health. Join our communities: Facebook: http://facebook.com/AmericanHeart X: http://x.com/American_Heart YouTube: http://www.youtube.com/American_Heart Pinterest: http://pinterest.com/americanheart Instagram: http://instagram.com/american_heart TikTok: https://tiktok.com/@americanheartassociation Heart News: http://twitter.com/heartnews ASA Facebook: http://facebook.com/AmericanStroke ASA X: https://X.com/American_Stroke Science News: https://x.com/AHAScience CPR Facebook: https://www.facebook.com/AHACPR CPR X: https://x.com/heartCPR Go Red for Women Facebook: https://www.facebook.com/goredforwomen Go Red for Women X: http://twitter.com/goredforwomen Advocacy Facebook: https://www.facebook.com/yourethecure Advocacy X: https://x.com/AmHeartAdvocacy

American Heart Association A.I CyberSecurity Scoring

AHA

Company Details

Linkedin ID:

american-heart-association

Employees number:

10,715

Number of followers:

1,260,928

NAICS:

71394

Industry Type:

Wellness and Fitness Services

Homepage:

heart.org

IP Addresses:

0

Company ID:

AME_1104788

Scan Status:

In-progress

AI scoreAHA Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/american-heart-association.jpeg
AHA Wellness and Fitness Services
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreAHA Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/american-heart-association.jpeg
AHA Wellness and Fitness Services
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

AHA Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
American Heart AssociationRansomware10042/2020
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: On September 15, 2020, the Washington State Office of the Attorney General reported a data breach involving the American Heart Association (AHA). The breach, discovered on August 18, 2020, was a ransomware attack that occurred between February 7, 2020, and May 20, 2020, affecting 7,658 Washington residents. The compromised information included individuals' names and full dates of birth.

American Heart Association
Ransomware
Severity: 100
Impact: 4
Seen: 2/2020
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: On September 15, 2020, the Washington State Office of the Attorney General reported a data breach involving the American Heart Association (AHA). The breach, discovered on August 18, 2020, was a ransomware attack that occurred between February 7, 2020, and May 20, 2020, affecting 7,658 Washington residents. The compromised information included individuals' names and full dates of birth.

Ailogo

AHA Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for AHA

Incidents vs Wellness and Fitness Services Industry Average (This Year)

No incidents recorded for American Heart Association in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for American Heart Association in 2025.

Incident Types AHA vs Wellness and Fitness Services Industry Avg (This Year)

No incidents recorded for American Heart Association in 2025.

Incident History — AHA (X = Date, Y = Severity)

AHA cyber incidents detection timeline including parent company and subsidiaries

AHA Company Subsidiaries

SubsidiaryImage

Welcome to the American Heart Association’s movement to change the future of health and be the progress that ensures longer, healthier lives for all. By driving breakthroughs in science, policy, and care – together -- we can overcome today’s biggest health challenges and transform lives every day. The American Heart Association is the nation’s oldest and largest voluntary organization dedicated to fighting heart disease and stroke. We are advocates of good health and promoters of positive behaviors, nutritious eating habits and healthy lifestyles. We also fund cutting-edge research and professional education programs. We promise to have an extraordinary impact on your life by empowering you and your loved ones to save lives, live healthier and enjoy more peace of mind about cardiovascular health. Join our communities: Facebook: http://facebook.com/AmericanHeart X: http://x.com/American_Heart YouTube: http://www.youtube.com/American_Heart Pinterest: http://pinterest.com/americanheart Instagram: http://instagram.com/american_heart TikTok: https://tiktok.com/@americanheartassociation Heart News: http://twitter.com/heartnews ASA Facebook: http://facebook.com/AmericanStroke ASA X: https://X.com/American_Stroke Science News: https://x.com/AHAScience CPR Facebook: https://www.facebook.com/AHACPR CPR X: https://x.com/heartCPR Go Red for Women Facebook: https://www.facebook.com/goredforwomen Go Red for Women X: http://twitter.com/goredforwomen Advocacy Facebook: https://www.facebook.com/yourethecure Advocacy X: https://x.com/AmHeartAdvocacy

Loading...
similarCompanies

AHA Similar Companies

Forever Living Products (Home Office)

Forever Living Products and its affiliates are the largest growers, manufacturers and distributors of aloe vera products in the world. The key to Forever's success is commitment to quality and purity. With offices in over 160 countries and Forever Business Owners worldwide, our goal is to provide a

Massage Envy

Massage Envy is the nation’s #1 provider of massage collectively across its franchise network and a national leader in skin care. All Massage Envy locations are independently owned and operated franchises, where the franchisee is the sole employer of all positions. Massage Envy combines big-brand r

Young Living Essential Oils

Through the painstaking steps of our proprietary Seed to Seal® production process, we produce the best, most authentic essential oils in the world. We are committed to providing pure, powerful products for every family and lifestyle, all infused with the life-changing benefits of our essential oils.

Purpose Brands, LLC

Purpose Brands, LLC provides fitness, nutrition and wellness support and services to more than 7,000 communities and millions of people around the world. We own and operate the world’s largest and most trusted portfolio of fitness, health and wellness franchise brands and services: Anytime Fit

Grupo Fleury

O Grupo Fleury é reconhecido como uma referência de qualidade em medicina diagnóstica no país, com soluções completas, coordenação de cuidado centrada no indivíduo, capacidade de inovação e tecnologia. Temos um portfólio de saúde integrado, preventivo e híbrido, nascemos como um laboratório e evolu

LA Fitness

LA Fitness is a privately owned fitness club chain. LA Fitness has hundreds of health clubs gyms and millions of members across US and Canada. In an industry often equated with fad and fashion, LA Fitness has steadily increased its presence by focusing on the one lifelong benefit valued by everyone:

Gold's Gym

Gold’s Gym has been the world’s trusted fitness authority since 1965. From its beginning as a small gym in Venice, California, Gold’s Gym has grown into a global icon with more than 700 locations serving 3 million people across six continents each day. Whether you are an industry professional or i

Herbalife

Herbalife is a global health and wellness community born to support you in living your best life. For over 40 years and in more than 90 countries, we’ve empowered millions of people to make real changes to their lives with our science-backed products, the support of a coach – what we call an Herbali

Planet Fitness

Planet Fitness is taking the fitness industry by storm! Enhancing people’s lives with an affordable, high-quality fitness experience requires a team of inspiring, motivated and fun-loving go-getters. As one of the largest and fastest-growing franchisors and operators of fitness centers in the Unit

newsone

AHA CyberSecurity News

November 27, 2025 07:50 AM
FCC eases cybersecurity rules for US telecom companies and why it may be ‘Big’ problem for Americans

The FCC has reportedly voted to eliminate rules requiring minimum cybersecurity standards for US phone and internet companies.

November 03, 2025 06:29 PM
Bharat Amin, NACD.DC

Former executive vice president and chief information officer, Huntington Ingalls Industries, Inc.; former vice president and chief information officer,...

October 13, 2025 07:00 AM
AHA blog: 2025 Cybersecurity Year in Review, Part One — Breaches and Defensive Measures

Related News Articles ... A critical vulnerability has been identified in 7-Zip, a free software program used for archiving data, according to the...

October 13, 2025 07:00 AM
Most serious FDA recall issued for Abiomed heart pump controllers | AHA News

The Food and Drug Administration has identified a Class I recall of Abiomed Automated Impella Controllers due to the potential for serious...

October 08, 2025 07:00 AM
HSCC launches toolkit to strengthen essential health care services and prevent cyberattacks

The Health Sector Coordinating Council Oct. 7 released its Sector Mapping and Risk Toolkit, created to help health care providers and other...

October 06, 2025 07:00 AM
AHA launches revamped Cybersecurity and Risk Advisory webpage

In part two of a recent blog, AHA National Advisor for Cybersecurity and Risk John Riggi and AHA Deputy National Advisor for Cybersecurity and...

September 03, 2025 07:00 AM
Advisory warns of activity by Chinese state-sponsored cyber actors

Chinese state-sponsored cyber actors are maliciously targeting networks globally, including telecommunications, government and others,...

August 21, 2025 07:00 AM
FBI warns Russian cybercriminals attacking devices using Cisco software with unpatched vulnerability

The FBI Aug. 20 released an advisory warning of malicious activity by Russian cyber actors targeting end-of-life devices running an...

May 23, 2025 07:00 AM
Russian state-sponsored cyber actors targeting tech companies, others

The FBI, along with the National Security Agency, and other international cybersecurity agencies, this week released a joint agency advisory...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

AHA CyberSecurity History Information

Official Website of American Heart Association

The official website of American Heart Association is http://www.heart.org.

American Heart Association’s AI-Generated Cybersecurity Score

According to Rankiteo, American Heart Association’s AI-generated cybersecurity score is 773, reflecting their Fair security posture.

How many security badges does American Heart Association’ have ?

According to Rankiteo, American Heart Association currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does American Heart Association have SOC 2 Type 1 certification ?

According to Rankiteo, American Heart Association is not certified under SOC 2 Type 1.

Does American Heart Association have SOC 2 Type 2 certification ?

According to Rankiteo, American Heart Association does not hold a SOC 2 Type 2 certification.

Does American Heart Association comply with GDPR ?

According to Rankiteo, American Heart Association is not listed as GDPR compliant.

Does American Heart Association have PCI DSS certification ?

According to Rankiteo, American Heart Association does not currently maintain PCI DSS compliance.

Does American Heart Association comply with HIPAA ?

According to Rankiteo, American Heart Association is not compliant with HIPAA regulations.

Does American Heart Association have ISO 27001 certification ?

According to Rankiteo,American Heart Association is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of American Heart Association

American Heart Association operates primarily in the Wellness and Fitness Services industry.

Number of Employees at American Heart Association

American Heart Association employs approximately 10,715 people worldwide.

Subsidiaries Owned by American Heart Association

American Heart Association presently has no subsidiaries across any sectors.

American Heart Association’s LinkedIn Followers

American Heart Association’s official LinkedIn profile has approximately 1,260,928 followers.

NAICS Classification of American Heart Association

American Heart Association is classified under the NAICS code 71394, which corresponds to Fitness and Recreational Sports Centers.

American Heart Association’s Presence on Crunchbase

No, American Heart Association does not have a profile on Crunchbase.

American Heart Association’s Presence on LinkedIn

Yes, American Heart Association maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/american-heart-association.

Cybersecurity Incidents Involving American Heart Association

As of December 10, 2025, Rankiteo reports that American Heart Association has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

American Heart Association has an estimated 12,079 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at American Heart Association ?

Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: American Heart Association Data Breach

Description: A ransomware attack on the American Heart Association (AHA) compromised personal information of 7,658 Washington residents.

Date Detected: 2020-08-18

Date Publicly Disclosed: 2020-09-15

Type: Data Breach

Attack Vector: Ransomware

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach AME210072825

Data Compromised: Names, Full dates of birth

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Full Dates Of Birth and .

Which entities were affected by each incident ?

Incident : Data Breach AME210072825

Entity Name: American Heart Association

Entity Type: Non-profit Organization

Industry: Health

Location: Washington

Customers Affected: 7658

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach AME210072825

Type of Data Compromised: Names, Full dates of birth

Number of Records Exposed: 7658

References

Where can I find more information about each incident ?

Incident : Data Breach AME210072825

Source: Washington State Office of the Attorney General

Date Accessed: 2020-09-15

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Washington State Office of the Attorney GeneralDate Accessed: 2020-09-15.

Additional Questions

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2020-08-18.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2020-09-15.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Names, Full Dates of Birth and .

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Full Dates of Birth and Names.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 773.0.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident is Washington State Office of the Attorney General.

cve

Latest Global CVEs (Not Company-Specific)

Description

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain a Stored Cross-Site Scripting (XSS) vulnerability in the /WeGIA/html/geral/configurar_senhas.php endpoint. The application does not sanitize user-controlled data before rendering it inside the employee selection dropdown. The application retrieves employee names from the database and injects them directly into HTML <option> elements without proper escaping. This issue is fixed in version 3.5.5.

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description

ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XSS through the Zitadel V2 logout endpoint. The /logout endpoint insecurely routes to a value that is supplied in the post_logout_redirect GET parameter. As a result, unauthenticated remote attacker can execute malicious JS code on Zitadel users’ browsers. To carry out an attack, multiple user sessions need to be active in the same browser, however, account takeover is mitigated when using Multi-Factor Authentication (MFA) or Passwordless authentication. This issue is fixed in version 4.7.1.

Risk Information
cvss3
Base: 8.0
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Description

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including self-hosted instances. This allows an unauthenticated attacker to force the server to make HTTP requests to arbitrary domains, such as internal addresses, and read the responses, enabling data exfiltration and bypassing network-segmentation controls. This issue is fixed in version 4.7.1.

Risk Information
cvss3
Base: 9.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Description

NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue is fixed in version 3.4.0.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.

Risk Information
cvss4
Base: 9.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=american-heart-association' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge