Company Details
anna-jaques-hospital
661
3,858
62
http://www.ajh.org
0
ANN_5124617
In-progress

Anna Jaques Hospital Company CyberSecurity Posture
http://www.ajh.orgAnna Jaques Hospital is a not-for-profit community hospital serving the Merrimack Valley, North Shore and Southern New Hampshire. Our mission is to provide measurably high quality medical care, in alliance with our medical staff. Anna Jaques is recognized for delivering high quality community health care at a lower cost, with an emphasis on patient satisfaction. The hospital is clinically affiliated with Beth Israel Deaconess Medical Center (BIDMC), a Boston academic medical center and major teaching hospital of Harvard Medical School.
Company Details
anna-jaques-hospital
661
3,858
62
http://www.ajh.org
0
ANN_5124617
In-progress
Between 700 and 749

AJH Global Score (TPRM)XXXX

Description: Anna Jaques Hospital, based in Vermont, experienced a cybersecurity incident on or around **December 25, 2023**, as reported by the Vermont Office of the Attorney General on **December 5, 2024**. The breach involved the potential compromise of **personal information**, specifically **names**, though the exact number of affected individuals remains undisclosed. While the full scope of the exposed data is unclear, the incident highlights vulnerabilities in the hospital’s digital infrastructure, raising concerns about patient privacy and the security of sensitive healthcare records.The attack underscores the growing threat to healthcare institutions, where cybercriminals often target patient data for financial gain or malicious exploitation. Given the nature of the compromised information—even if limited to names—there is a risk of further exploitation, such as phishing campaigns or identity fraud. The hospital has not yet confirmed whether additional details (e.g., medical records, financial data, or Social Security numbers) were exposed, but the incident warrants heightened scrutiny of cybersecurity protocols to prevent future breaches.As a healthcare provider, Anna Jaques Hospital’s breach could erode patient trust and trigger regulatory scrutiny, particularly under **HIPAA** (Health Insurance Portability and Accountability Act), which mandates strict protections for patient data. The financial and reputational repercussions may extend beyond immediate remediation costs, potentially affecting the hospital’s operations and community standing.
Description: The health record system at Anna Jaques Hospital was taken down by a cyberattack; hospital authorities are not providing many details regarding the reason for the severe breakdown or whether it has been fixed. During the height of the crisis, employees at Anna Jaques Hospital were sending ambulances to other hospitals in the vicinity instead of accepting patients who were being delivered to the hospital's emergency room. Sean Reardon, the mayor of Newburyport, stated that hospital employees were rerouting ambulances to other locations due to a malfunctioning electronic health record system on Christmas. The union also made the odd decision to voice its worries about the current cyberattack in a memo to the Department of Public Health.


No incidents recorded for Anna Jaques Hospital in 2025.
No incidents recorded for Anna Jaques Hospital in 2025.
No incidents recorded for Anna Jaques Hospital in 2025.
AJH cyber incidents detection timeline including parent company and subsidiaries

Anna Jaques Hospital is a not-for-profit community hospital serving the Merrimack Valley, North Shore and Southern New Hampshire. Our mission is to provide measurably high quality medical care, in alliance with our medical staff. Anna Jaques is recognized for delivering high quality community health care at a lower cost, with an emphasis on patient satisfaction. The hospital is clinically affiliated with Beth Israel Deaconess Medical Center (BIDMC), a Boston academic medical center and major teaching hospital of Harvard Medical School.


The Hospital Authority (HA) is a statutory body established under the Hospital Authority Ordinance in 1990. We have been responsible for managing Hong Kong's public hospitals services since December 1991. We are accountable to the Hong Kong Special Administrative Region Government through the Secret

Indiana University Health is Indiana’s largest and most comprehensive system. A unique partnership with the Indiana University School of Medicine—one of the nation’s largest medical schools—gives patients access to groundbreaking research and innovative treatments, and it offers team members acces

El Seguro Social de Salud, EsSalud, es un organismo público descentralizado, con personería jurídica de derecho público interno, adscrito al Sector Trabajo y Promoción Social. Tiene por finalidad dar cobertura a los asegurados y sus derechohabientes, a través del otorgamiento de prestaciones de pre
IQVIA (NYSE:IQV) is a leading global provider of clinical research services, commercial insights and healthcare intelligence to the life sciences and healthcare industries. IQVIA’s portfolio of solutions are powered by IQVIA Connected Intelligence™ to deliver actionable insights and services built o
NYC Health + Hospitals is the nation’s largest public health care delivery system. We are an integrated network of hospitals, trauma centers, neighborhood health centers, nursing homes, and post-acute care centers. We are a home care agency and a health plan, MetroPlus. The health system provides es
About Aveanna It all started with a simple idea: How can we help people live better lives by providing better homecare? That idea became a company called Aveanna, dedicated to bringing new possibilities and new hope to those we serve. At Aveanna, we believe that the ultimate place for caring is rig

One of the nation’s largest and most respected providers of hospital and healthcare services, Universal Health Services, Inc. (NYSE: UHS) has built an impressive record of achievement and performance, growing since its inception into a Fortune 300 corporation. Headquartered in King of Prussia, PA, U
A national blended health organization, Highmark Health and our leading businesses support millions of customers with products, services and solutions closely aligned to our mission of creating remarkable health experiences, freeing people to be their best. Headquartered in Pittsburgh, we're region

One of the largest Trusts in the UK, Guy’s and St Thomas’ NHS Foundation Trust comprises five of the UK’s best known hospitals – Guy’s, St Thomas’, Evelina London Children’s Hospital, Royal Brompton and Harefield – as well as community services in Lambeth and Southwark, all with a long history of hi
.png)
Two Massachusetts residents succeeded in their bid to return a proposed data breach class action against Anna Jaques Hospital to state court.
American Addiction Centers (AAC), a for-profit addiction treatment chain, has suffered a cybersecurity incident exposing the personal...
A Massachusetts hospital disclosed a ransomware attack that compromised the personal data of over 316000 patients on Christmas Day 2023.
Anna Jaques Hospital, a healthcare provider in Massachusetts, recently confirmed it suffered a ransomware attack on Christmas last year.
Anna Jaques Hospital in Newburyport, Massachusetts, has recently notified regulators and patients about a cyberattack and data breach that occurred on...
A security breach at a Massachusetts hospital may have exposed the data of hundreds of thousands of patients, officials warned.
Anna Jaques Hospital says the personal information of over 316000 individuals was compromised in a year-old data breach.
A data breach at Anna Jaques Hospital in Newburyport may have affected more than 300000 people, lawyers say.
Anna Jaques Hospital revealed that the ransomware attack it suffered last year has exposed sensitive health data for over 316000 patients.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Anna Jaques Hospital is http://www.ajh.org.
According to Rankiteo, Anna Jaques Hospital’s AI-generated cybersecurity score is 739, reflecting their Moderate security posture.
According to Rankiteo, Anna Jaques Hospital currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Anna Jaques Hospital is not certified under SOC 2 Type 1.
According to Rankiteo, Anna Jaques Hospital does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Anna Jaques Hospital is not listed as GDPR compliant.
According to Rankiteo, Anna Jaques Hospital does not currently maintain PCI DSS compliance.
According to Rankiteo, Anna Jaques Hospital is not compliant with HIPAA regulations.
According to Rankiteo,Anna Jaques Hospital is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Anna Jaques Hospital operates primarily in the Hospitals and Health Care industry.
Anna Jaques Hospital employs approximately 661 people worldwide.
Anna Jaques Hospital presently has no subsidiaries across any sectors.
Anna Jaques Hospital’s official LinkedIn profile has approximately 3,858 followers.
Anna Jaques Hospital is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
No, Anna Jaques Hospital does not have a profile on Crunchbase.
Yes, Anna Jaques Hospital maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/anna-jaques-hospital.
As of November 27, 2025, Rankiteo reports that Anna Jaques Hospital has experienced 2 cybersecurity incidents.
Anna Jaques Hospital has an estimated 30,007 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.
Title: Cyberattack on Anna Jaques Hospital
Description: The health record system at Anna Jaques Hospital was taken down by a cyberattack; hospital authorities are not providing many details regarding the reason for the severe breakdown or whether it has been fixed. During the height of the crisis, employees at Anna Jaques Hospital were sending ambulances to other hospitals in the vicinity instead of accepting patients who were being delivered to the hospital's emergency room. Sean Reardon, the mayor of Newburyport, stated that hospital employees were rerouting ambulances to other locations due to a malfunctioning electronic health record system on Christmas. The union also made the odd decision to voice its worries about the current cyberattack in a memo to the Department of Public Health.
Date Detected: 2023-12-25
Type: Cyberattack
Title: Anna Jaques Hospital Cybersecurity Incident
Description: The Vermont Office of the Attorney General reported that Anna Jaques Hospital experienced a cybersecurity incident on or about December 25, 2023. The incident potentially affected personal information including names, although specifics about the number of individuals affected remain unknown.
Date Detected: 2023-12-25
Date Publicly Disclosed: 2024-12-05
Type: Cyber Attack
Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Systems Affected: Electronic health record system
Operational Impact: Ambulances rerouted to other hospitalsPatients not accepted in the emergency room

Data Compromised: Names
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Information (Names) and .

Entity Name: Anna Jaques Hospital
Entity Type: Healthcare
Industry: Healthcare
Location: Newburyport

Entity Name: Anna Jaques Hospital
Entity Type: Hospital
Industry: Healthcare
Location: Vermont, USA

Type of Data Compromised: Personal information (names)
Personally Identifiable Information: names

Regulatory Notifications: Vermont Office of the Attorney General

Source: Vermont Office of the Attorney General
Date Accessed: 2024-12-05
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Vermont Office of the Attorney GeneralDate Accessed: 2024-12-05.
Most Recent Incident Detected: The most recent incident detected was on 2023-12-25.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-12-05.
Most Significant Data Compromised: The most significant data compromised in an incident were names and .
Most Significant System Affected: The most significant system affected in an incident was Electronic health record system.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach was names.
Most Recent Source: The most recent source of information about an incident is Vermont Office of the Attorney General.
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.