ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Anna Jaques Hospital is a not-for-profit community hospital serving the Merrimack Valley, North Shore and Southern New Hampshire. Our mission is to provide measurably high quality medical care, in alliance with our medical staff. Anna Jaques is recognized for delivering high quality community health care at a lower cost, with an emphasis on patient satisfaction. The hospital is clinically affiliated with Beth Israel Deaconess Medical Center (BIDMC), a Boston academic medical center and major teaching hospital of Harvard Medical School.

Anna Jaques Hospital A.I CyberSecurity Scoring

AJH

Company Details

Linkedin ID:

anna-jaques-hospital

Employees number:

661

Number of followers:

3,858

NAICS:

62

Industry Type:

Hospitals and Health Care

Homepage:

http://www.ajh.org

IP Addresses:

0

Company ID:

ANN_5124617

Scan Status:

In-progress

AI scoreAJH Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/anna-jaques-hospital.jpeg
AJH Hospitals and Health Care
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreAJH Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/anna-jaques-hospital.jpeg
AJH Hospitals and Health Care
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

AJH Company CyberSecurity News & History

Past Incidents
2
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Anna Jaques HospitalCyber Attack85412/2023
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: Anna Jaques Hospital, based in Vermont, experienced a cybersecurity incident on or around **December 25, 2023**, as reported by the Vermont Office of the Attorney General on **December 5, 2024**. The breach involved the potential compromise of **personal information**, specifically **names**, though the exact number of affected individuals remains undisclosed. While the full scope of the exposed data is unclear, the incident highlights vulnerabilities in the hospital’s digital infrastructure, raising concerns about patient privacy and the security of sensitive healthcare records.The attack underscores the growing threat to healthcare institutions, where cybercriminals often target patient data for financial gain or malicious exploitation. Given the nature of the compromised information—even if limited to names—there is a risk of further exploitation, such as phishing campaigns or identity fraud. The hospital has not yet confirmed whether additional details (e.g., medical records, financial data, or Social Security numbers) were exposed, but the incident warrants heightened scrutiny of cybersecurity protocols to prevent future breaches.As a healthcare provider, Anna Jaques Hospital’s breach could erode patient trust and trigger regulatory scrutiny, particularly under **HIPAA** (Health Insurance Portability and Accountability Act), which mandates strict protections for patient data. The financial and reputational repercussions may extend beyond immediate remediation costs, potentially affecting the hospital’s operations and community standing.

Anna Jaques HospitalCyber Attack60312/2023
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: The health record system at Anna Jaques Hospital was taken down by a cyberattack; hospital authorities are not providing many details regarding the reason for the severe breakdown or whether it has been fixed. During the height of the crisis, employees at Anna Jaques Hospital were sending ambulances to other hospitals in the vicinity instead of accepting patients who were being delivered to the hospital's emergency room. Sean Reardon, the mayor of Newburyport, stated that hospital employees were rerouting ambulances to other locations due to a malfunctioning electronic health record system on Christmas. The union also made the odd decision to voice its worries about the current cyberattack in a memo to the Department of Public Health.

Anna Jaques Hospital
Cyber Attack
Severity: 85
Impact: 4
Seen: 12/2023
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: Anna Jaques Hospital, based in Vermont, experienced a cybersecurity incident on or around **December 25, 2023**, as reported by the Vermont Office of the Attorney General on **December 5, 2024**. The breach involved the potential compromise of **personal information**, specifically **names**, though the exact number of affected individuals remains undisclosed. While the full scope of the exposed data is unclear, the incident highlights vulnerabilities in the hospital’s digital infrastructure, raising concerns about patient privacy and the security of sensitive healthcare records.The attack underscores the growing threat to healthcare institutions, where cybercriminals often target patient data for financial gain or malicious exploitation. Given the nature of the compromised information—even if limited to names—there is a risk of further exploitation, such as phishing campaigns or identity fraud. The hospital has not yet confirmed whether additional details (e.g., medical records, financial data, or Social Security numbers) were exposed, but the incident warrants heightened scrutiny of cybersecurity protocols to prevent future breaches.As a healthcare provider, Anna Jaques Hospital’s breach could erode patient trust and trigger regulatory scrutiny, particularly under **HIPAA** (Health Insurance Portability and Accountability Act), which mandates strict protections for patient data. The financial and reputational repercussions may extend beyond immediate remediation costs, potentially affecting the hospital’s operations and community standing.

Anna Jaques Hospital
Cyber Attack
Severity: 60
Impact: 3
Seen: 12/2023
Blog:
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: The health record system at Anna Jaques Hospital was taken down by a cyberattack; hospital authorities are not providing many details regarding the reason for the severe breakdown or whether it has been fixed. During the height of the crisis, employees at Anna Jaques Hospital were sending ambulances to other hospitals in the vicinity instead of accepting patients who were being delivered to the hospital's emergency room. Sean Reardon, the mayor of Newburyport, stated that hospital employees were rerouting ambulances to other locations due to a malfunctioning electronic health record system on Christmas. The union also made the odd decision to voice its worries about the current cyberattack in a memo to the Department of Public Health.

Ailogo

AJH Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for AJH

Incidents vs Hospitals and Health Care Industry Average (This Year)

No incidents recorded for Anna Jaques Hospital in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Anna Jaques Hospital in 2025.

Incident Types AJH vs Hospitals and Health Care Industry Avg (This Year)

No incidents recorded for Anna Jaques Hospital in 2025.

Incident History — AJH (X = Date, Y = Severity)

AJH cyber incidents detection timeline including parent company and subsidiaries

AJH Company Subsidiaries

SubsidiaryImage

Anna Jaques Hospital is a not-for-profit community hospital serving the Merrimack Valley, North Shore and Southern New Hampshire. Our mission is to provide measurably high quality medical care, in alliance with our medical staff. Anna Jaques is recognized for delivering high quality community health care at a lower cost, with an emphasis on patient satisfaction. The hospital is clinically affiliated with Beth Israel Deaconess Medical Center (BIDMC), a Boston academic medical center and major teaching hospital of Harvard Medical School.

Loading...
similarCompanies

AJH Similar Companies

Hospital Authority

The Hospital Authority (HA) is a statutory body established under the Hospital Authority Ordinance in 1990. We have been responsible for managing Hong Kong's public hospitals services since December 1991. We are accountable to the Hong Kong Special Administrative Region Government through the Secret

Indiana University Health

Indiana University Health is Indiana’s largest and most comprehensive system. A unique partnership with the Indiana University School of Medicine—one of the nation’s largest medical schools—gives patients access to groundbreaking research and innovative treatments, and it offers team members acces

EsSalud

El Seguro Social de Salud, EsSalud, es un organismo público descentralizado, con personería jurídica de derecho público interno, adscrito al Sector Trabajo y Promoción Social. Tiene por finalidad dar cobertura a los asegurados y sus derechohabientes, a través del otorgamiento de prestaciones de pre

IQVIA

IQVIA (NYSE:IQV) is a leading global provider of clinical research services, commercial insights and healthcare intelligence to the life sciences and healthcare industries. IQVIA’s portfolio of solutions are powered by IQVIA Connected Intelligence™ to deliver actionable insights and services built o

NYC Health + Hospitals

NYC Health + Hospitals is the nation’s largest public health care delivery system. We are an integrated network of hospitals, trauma centers, neighborhood health centers, nursing homes, and post-acute care centers. We are a home care agency and a health plan, MetroPlus. The health system provides es

Aveanna Healthcare

About Aveanna It all started with a simple idea: How can we help people live better lives by providing better homecare? That idea became a company called Aveanna, dedicated to bringing new possibilities and new hope to those we serve. At Aveanna, we believe that the ultimate place for caring is rig

One of the nation’s largest and most respected providers of hospital and healthcare services, Universal Health Services, Inc. (NYSE: UHS) has built an impressive record of achievement and performance, growing since its inception into a Fortune 300 corporation. Headquartered in King of Prussia, PA, U

Highmark Health

A national blended health organization, Highmark Health and our leading businesses support millions of customers with products, services and solutions closely aligned to our mission of creating remarkable health experiences, freeing people to be their best. Headquartered in Pittsburgh, we're region

Guy's and St Thomas'​ NHS Foundation Trust

One of the largest Trusts in the UK, Guy’s and St Thomas’ NHS Foundation Trust comprises five of the UK’s best known hospitals – Guy’s, St Thomas’, Evelina London Children’s Hospital, Royal Brompton and Harefield – as well as community services in Lambeth and Southwark, all with a long history of hi

newsone

AJH CyberSecurity News

July 09, 2025 07:00 AM
Anna Jaques Hospital Data Breach Suit Returned to State Court

Two Massachusetts residents succeeded in their bid to return a proposed data breach class action against Anna Jaques Hospital to state court.

December 24, 2024 08:00 AM
Over 400K patients exposed in addiction treatment hack

American Addiction Centers (AAC), a for-profit addiction treatment chain, has suffered a cybersecurity incident exposing the personal...

December 13, 2024 08:00 AM
Massive Data Breach Exposes Information of 316,000 Anna Jaques Patients

A Massachusetts hospital disclosed a ransomware attack that compromised the personal data of over 316000 patients on Christmas Day 2023.

December 09, 2024 02:20 PM
Data Breach at Anna Jaques Hospital Leaks Data of Over 300,000 Patients

Anna Jaques Hospital, a healthcare provider in Massachusetts, recently confirmed it suffered a ransomware attack on Christmas last year.

December 09, 2024 08:00 AM
Anna Jacques Hospital Notifies 316K Patients About December 2023 Ransomware Attack

Anna Jaques Hospital in Newburyport, Massachusetts, has recently notified regulators and patients about a cyberattack and data breach that occurred on...

December 09, 2024 08:00 AM
Security breach at Mass. hospital may have exposed data of hundreds of thousands of patients

A security breach at a Massachusetts hospital may have exposed the data of hundreds of thousands of patients, officials warned.

December 09, 2024 08:00 AM
Anna Jaques Hospital Data Breach Impacts 316,000 People

Anna Jaques Hospital says the personal information of over 316000 individuals was compromised in a year-old data breach.

December 09, 2024 08:00 AM
North Shore hospital data breach may affect hundreds of thousands

A data breach at Anna Jaques Hospital in Newburyport may have affected more than 300000 people, lawyers say.

December 09, 2024 08:00 AM
2023 Anna Jaques Hospital data breach impacted over 310,000 people

Anna Jaques Hospital revealed that the ransomware attack it suffered last year has exposed sensitive health data for over 316000 patients.

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

AJH CyberSecurity History Information

Official Website of Anna Jaques Hospital

The official website of Anna Jaques Hospital is http://www.ajh.org.

Anna Jaques Hospital’s AI-Generated Cybersecurity Score

According to Rankiteo, Anna Jaques Hospital’s AI-generated cybersecurity score is 739, reflecting their Moderate security posture.

How many security badges does Anna Jaques Hospital’ have ?

According to Rankiteo, Anna Jaques Hospital currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Anna Jaques Hospital have SOC 2 Type 1 certification ?

According to Rankiteo, Anna Jaques Hospital is not certified under SOC 2 Type 1.

Does Anna Jaques Hospital have SOC 2 Type 2 certification ?

According to Rankiteo, Anna Jaques Hospital does not hold a SOC 2 Type 2 certification.

Does Anna Jaques Hospital comply with GDPR ?

According to Rankiteo, Anna Jaques Hospital is not listed as GDPR compliant.

Does Anna Jaques Hospital have PCI DSS certification ?

According to Rankiteo, Anna Jaques Hospital does not currently maintain PCI DSS compliance.

Does Anna Jaques Hospital comply with HIPAA ?

According to Rankiteo, Anna Jaques Hospital is not compliant with HIPAA regulations.

Does Anna Jaques Hospital have ISO 27001 certification ?

According to Rankiteo,Anna Jaques Hospital is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Anna Jaques Hospital

Anna Jaques Hospital operates primarily in the Hospitals and Health Care industry.

Number of Employees at Anna Jaques Hospital

Anna Jaques Hospital employs approximately 661 people worldwide.

Subsidiaries Owned by Anna Jaques Hospital

Anna Jaques Hospital presently has no subsidiaries across any sectors.

Anna Jaques Hospital’s LinkedIn Followers

Anna Jaques Hospital’s official LinkedIn profile has approximately 3,858 followers.

NAICS Classification of Anna Jaques Hospital

Anna Jaques Hospital is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.

Anna Jaques Hospital’s Presence on Crunchbase

No, Anna Jaques Hospital does not have a profile on Crunchbase.

Anna Jaques Hospital’s Presence on LinkedIn

Yes, Anna Jaques Hospital maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/anna-jaques-hospital.

Cybersecurity Incidents Involving Anna Jaques Hospital

As of November 27, 2025, Rankiteo reports that Anna Jaques Hospital has experienced 2 cybersecurity incidents.

Number of Peer and Competitor Companies

Anna Jaques Hospital has an estimated 30,007 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Anna Jaques Hospital ?

Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.

Incident Details

Can you provide details on each incident ?

Incident : Cyberattack

Title: Cyberattack on Anna Jaques Hospital

Description: The health record system at Anna Jaques Hospital was taken down by a cyberattack; hospital authorities are not providing many details regarding the reason for the severe breakdown or whether it has been fixed. During the height of the crisis, employees at Anna Jaques Hospital were sending ambulances to other hospitals in the vicinity instead of accepting patients who were being delivered to the hospital's emergency room. Sean Reardon, the mayor of Newburyport, stated that hospital employees were rerouting ambulances to other locations due to a malfunctioning electronic health record system on Christmas. The union also made the odd decision to voice its worries about the current cyberattack in a memo to the Department of Public Health.

Date Detected: 2023-12-25

Type: Cyberattack

Incident : Cyber Attack

Title: Anna Jaques Hospital Cybersecurity Incident

Description: The Vermont Office of the Attorney General reported that Anna Jaques Hospital experienced a cybersecurity incident on or about December 25, 2023. The incident potentially affected personal information including names, although specifics about the number of individuals affected remain unknown.

Date Detected: 2023-12-25

Date Publicly Disclosed: 2024-12-05

Type: Cyber Attack

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Impact of the Incidents

What was the impact of each incident ?

Incident : Cyberattack ANN05022124

Systems Affected: Electronic health record system

Operational Impact: Ambulances rerouted to other hospitalsPatients not accepted in the emergency room

Incident : Cyber Attack ANN551091725

Data Compromised: Names

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Information (Names) and .

Which entities were affected by each incident ?

Incident : Cyberattack ANN05022124

Entity Name: Anna Jaques Hospital

Entity Type: Healthcare

Industry: Healthcare

Location: Newburyport

Incident : Cyber Attack ANN551091725

Entity Name: Anna Jaques Hospital

Entity Type: Hospital

Industry: Healthcare

Location: Vermont, USA

Data Breach Information

What type of data was compromised in each breach ?

Incident : Cyber Attack ANN551091725

Type of Data Compromised: Personal information (names)

Personally Identifiable Information: names

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : Cyber Attack ANN551091725

Regulatory Notifications: Vermont Office of the Attorney General

References

Where can I find more information about each incident ?

Incident : Cyber Attack ANN551091725

Source: Vermont Office of the Attorney General

Date Accessed: 2024-12-05

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Vermont Office of the Attorney GeneralDate Accessed: 2024-12-05.

Additional Questions

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2023-12-25.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-12-05.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were names and .

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was Electronic health record system.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach was names.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident is Vermont Office of the Attorney General.

cve

Latest Global CVEs (Not Company-Specific)

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.

Risk Information
cvss4
Base: 7.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=anna-jaques-hospital' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge