Company Details
american-heart-association
10,715
1,260,928
71394
heart.org
0
AME_1104788
In-progress

American Heart Association Company CyberSecurity Posture
heart.orgWelcome to the American Heart Association’s movement to change the future of health and be the progress that ensures longer, healthier lives for all. By driving breakthroughs in science, policy, and care – together -- we can overcome today’s biggest health challenges and transform lives every day. The American Heart Association is the nation’s oldest and largest voluntary organization dedicated to fighting heart disease and stroke. We are advocates of good health and promoters of positive behaviors, nutritious eating habits and healthy lifestyles. We also fund cutting-edge research and professional education programs. We promise to have an extraordinary impact on your life by empowering you and your loved ones to save lives, live healthier and enjoy more peace of mind about cardiovascular health. Join our communities: Facebook: http://facebook.com/AmericanHeart X: http://x.com/American_Heart YouTube: http://www.youtube.com/American_Heart Pinterest: http://pinterest.com/americanheart Instagram: http://instagram.com/american_heart TikTok: https://tiktok.com/@americanheartassociation Heart News: http://twitter.com/heartnews ASA Facebook: http://facebook.com/AmericanStroke ASA X: https://X.com/American_Stroke Science News: https://x.com/AHAScience CPR Facebook: https://www.facebook.com/AHACPR CPR X: https://x.com/heartCPR Go Red for Women Facebook: https://www.facebook.com/goredforwomen Go Red for Women X: http://twitter.com/goredforwomen Advocacy Facebook: https://www.facebook.com/yourethecure Advocacy X: https://x.com/AmHeartAdvocacy
Company Details
american-heart-association
10,715
1,260,928
71394
heart.org
0
AME_1104788
In-progress
Between 750 and 799

AHA Global Score (TPRM)XXXX

Description: On September 15, 2020, the Washington State Office of the Attorney General reported a data breach involving the American Heart Association (AHA). The breach, discovered on August 18, 2020, was a ransomware attack that occurred between February 7, 2020, and May 20, 2020, affecting 7,658 Washington residents. The compromised information included individuals' names and full dates of birth.


No incidents recorded for American Heart Association in 2025.
No incidents recorded for American Heart Association in 2025.
No incidents recorded for American Heart Association in 2025.
AHA cyber incidents detection timeline including parent company and subsidiaries

Welcome to the American Heart Association’s movement to change the future of health and be the progress that ensures longer, healthier lives for all. By driving breakthroughs in science, policy, and care – together -- we can overcome today’s biggest health challenges and transform lives every day. The American Heart Association is the nation’s oldest and largest voluntary organization dedicated to fighting heart disease and stroke. We are advocates of good health and promoters of positive behaviors, nutritious eating habits and healthy lifestyles. We also fund cutting-edge research and professional education programs. We promise to have an extraordinary impact on your life by empowering you and your loved ones to save lives, live healthier and enjoy more peace of mind about cardiovascular health. Join our communities: Facebook: http://facebook.com/AmericanHeart X: http://x.com/American_Heart YouTube: http://www.youtube.com/American_Heart Pinterest: http://pinterest.com/americanheart Instagram: http://instagram.com/american_heart TikTok: https://tiktok.com/@americanheartassociation Heart News: http://twitter.com/heartnews ASA Facebook: http://facebook.com/AmericanStroke ASA X: https://X.com/American_Stroke Science News: https://x.com/AHAScience CPR Facebook: https://www.facebook.com/AHACPR CPR X: https://x.com/heartCPR Go Red for Women Facebook: https://www.facebook.com/goredforwomen Go Red for Women X: http://twitter.com/goredforwomen Advocacy Facebook: https://www.facebook.com/yourethecure Advocacy X: https://x.com/AmHeartAdvocacy


Forever Living Products and its affiliates are the largest growers, manufacturers and distributors of aloe vera products in the world. The key to Forever's success is commitment to quality and purity. With offices in over 160 countries and Forever Business Owners worldwide, our goal is to provide a

Massage Envy is the nation’s #1 provider of massage collectively across its franchise network and a national leader in skin care. All Massage Envy locations are independently owned and operated franchises, where the franchisee is the sole employer of all positions. Massage Envy combines big-brand r

Through the painstaking steps of our proprietary Seed to Seal® production process, we produce the best, most authentic essential oils in the world. We are committed to providing pure, powerful products for every family and lifestyle, all infused with the life-changing benefits of our essential oils.

Purpose Brands, LLC provides fitness, nutrition and wellness support and services to more than 7,000 communities and millions of people around the world. We own and operate the world’s largest and most trusted portfolio of fitness, health and wellness franchise brands and services: Anytime Fit

O Grupo Fleury é reconhecido como uma referência de qualidade em medicina diagnóstica no país, com soluções completas, coordenação de cuidado centrada no indivíduo, capacidade de inovação e tecnologia. Temos um portfólio de saúde integrado, preventivo e híbrido, nascemos como um laboratório e evolu
LA Fitness is a privately owned fitness club chain. LA Fitness has hundreds of health clubs gyms and millions of members across US and Canada. In an industry often equated with fad and fashion, LA Fitness has steadily increased its presence by focusing on the one lifelong benefit valued by everyone:

Gold’s Gym has been the world’s trusted fitness authority since 1965. From its beginning as a small gym in Venice, California, Gold’s Gym has grown into a global icon with more than 700 locations serving 3 million people across six continents each day. Whether you are an industry professional or i

Herbalife is a global health and wellness community born to support you in living your best life. For over 40 years and in more than 90 countries, we’ve empowered millions of people to make real changes to their lives with our science-backed products, the support of a coach – what we call an Herbali
Planet Fitness is taking the fitness industry by storm! Enhancing people’s lives with an affordable, high-quality fitness experience requires a team of inspiring, motivated and fun-loving go-getters. As one of the largest and fastest-growing franchisors and operators of fitness centers in the Unit
.png)
The FCC has reportedly voted to eliminate rules requiring minimum cybersecurity standards for US phone and internet companies.
Former executive vice president and chief information officer, Huntington Ingalls Industries, Inc.; former vice president and chief information officer,...
Related News Articles ... A critical vulnerability has been identified in 7-Zip, a free software program used for archiving data, according to the...
The Food and Drug Administration has identified a Class I recall of Abiomed Automated Impella Controllers due to the potential for serious...
The Health Sector Coordinating Council Oct. 7 released its Sector Mapping and Risk Toolkit, created to help health care providers and other...
In part two of a recent blog, AHA National Advisor for Cybersecurity and Risk John Riggi and AHA Deputy National Advisor for Cybersecurity and...
Chinese state-sponsored cyber actors are maliciously targeting networks globally, including telecommunications, government and others,...
The FBI Aug. 20 released an advisory warning of malicious activity by Russian cyber actors targeting end-of-life devices running an...
The FBI, along with the National Security Agency, and other international cybersecurity agencies, this week released a joint agency advisory...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of American Heart Association is http://www.heart.org.
According to Rankiteo, American Heart Association’s AI-generated cybersecurity score is 773, reflecting their Fair security posture.
According to Rankiteo, American Heart Association currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, American Heart Association is not certified under SOC 2 Type 1.
According to Rankiteo, American Heart Association does not hold a SOC 2 Type 2 certification.
According to Rankiteo, American Heart Association is not listed as GDPR compliant.
According to Rankiteo, American Heart Association does not currently maintain PCI DSS compliance.
According to Rankiteo, American Heart Association is not compliant with HIPAA regulations.
According to Rankiteo,American Heart Association is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
American Heart Association operates primarily in the Wellness and Fitness Services industry.
American Heart Association employs approximately 10,715 people worldwide.
American Heart Association presently has no subsidiaries across any sectors.
American Heart Association’s official LinkedIn profile has approximately 1,260,928 followers.
American Heart Association is classified under the NAICS code 71394, which corresponds to Fitness and Recreational Sports Centers.
No, American Heart Association does not have a profile on Crunchbase.
Yes, American Heart Association maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/american-heart-association.
As of December 10, 2025, Rankiteo reports that American Heart Association has experienced 1 cybersecurity incidents.
American Heart Association has an estimated 12,079 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.
Title: American Heart Association Data Breach
Description: A ransomware attack on the American Heart Association (AHA) compromised personal information of 7,658 Washington residents.
Date Detected: 2020-08-18
Date Publicly Disclosed: 2020-09-15
Type: Data Breach
Attack Vector: Ransomware
Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Data Compromised: Names, Full dates of birth
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Full Dates Of Birth and .

Entity Name: American Heart Association
Entity Type: Non-profit Organization
Industry: Health
Location: Washington
Customers Affected: 7658

Type of Data Compromised: Names, Full dates of birth
Number of Records Exposed: 7658

Source: Washington State Office of the Attorney General
Date Accessed: 2020-09-15
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Washington State Office of the Attorney GeneralDate Accessed: 2020-09-15.
Most Recent Incident Detected: The most recent incident detected was on 2020-08-18.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2020-09-15.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Full Dates of Birth and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Full Dates of Birth and Names.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 773.0.
Most Recent Source: The most recent source of information about an incident is Washington State Office of the Attorney General.
.png)
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain a Stored Cross-Site Scripting (XSS) vulnerability in the /WeGIA/html/geral/configurar_senhas.php endpoint. The application does not sanitize user-controlled data before rendering it inside the employee selection dropdown. The application retrieves employee names from the database and injects them directly into HTML <option> elements without proper escaping. This issue is fixed in version 3.5.5.
ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XSS through the Zitadel V2 logout endpoint. The /logout endpoint insecurely routes to a value that is supplied in the post_logout_redirect GET parameter. As a result, unauthenticated remote attacker can execute malicious JS code on Zitadel users’ browsers. To carry out an attack, multiple user sessions need to be active in the same browser, however, account takeover is mitigated when using Multi-Factor Authentication (MFA) or Passwordless authentication. This issue is fixed in version 4.7.1.
ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including self-hosted instances. This allows an unauthenticated attacker to force the server to make HTTP requests to arbitrary domains, such as internal addresses, and read the responses, enabling data exfiltration and bypassing network-segmentation controls. This issue is fixed in version 4.7.1.
NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue is fixed in version 3.4.0.
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.