Comparison Overview

Arkansas Otolaryngology Center

VS

Hamad Medical Corporation

Arkansas Otolaryngology Center

10201 Kanis Rd, Little Rock, AR 72205, US
Last Update: 2025-05-04 (UTC)
Between 900 and 1000

Excellent

Welcome to Arkansas Otolaryngology Center (AOC), the largest comprehensive Ear, Nose, and Throat (ENT) and Allergy clinic in the state. Our board-certified physicians provide advanced treatments to patients across Arkansas with clinic locations in Little Rock, North Little Rock, Benton, Heber Springs, Cabot, Clinton, Monticello, Jacksonville and Stuttgart. Our free-standing ambulatory surgical facility provides patients a convenient option for outpatient procedures. As an independent physician group, our team provides care focused solely on what is best for our patients. We would appreciate the opportunity to care for you.

NAICS: 621
NAICS Definition: Ambulatory Health Care Services
Employees: 54
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Hamad Medical Corporation

PO Box 3488, undefined, undefined, undefined, QA
Last Update: 2025-03-05 (UTC)

Excellent

Between 900 and 1000

Hamad Medical Corporation (HMC) is the main provider of secondary and tertiary healthcare in Qatar and one of the leading hospital providers in the Middle East. For more than three decades, HMC has been dedicated to delivering the safest, most effective and compassionate care to all its patients. HMC manages twelve hospitals โ€“ nine specialist hospitals and three community hospitals โ€“ as well as the National Ambulance Service and home and residential care services. In January 2016, HMC achieved the significant distinction of becoming the first healthcare system across the globe to have all its hospitals accredited by Joint Commission International under the Academic Medical Center accreditation program. Additionally, the National Ambulance Service, Home Healthcare Service, Stroke Service and Palliative Care, have all received this prestigious accreditation since 2011. To meet the needs of a rapidly growing population, HMC has announced ambitious plans to expand capacity across its network through to 2030. HMC is leading the development of the regionโ€™s first academic health system โ€“ combining innovative research, top-class education and excellent clinical care โ€“ and is committed to building a legacy of healthcare expertise in Qatar. HMC collaborates with key partners who are experts in Qatar and beyond, including Weill Cornell Medical College-Qatar, the Institute for Healthcare Improvement and Partners Healthcare, Boston. HMC is also the first hospital system in the Middle East to achieve institutional accreditation from the Accreditation Council of Graduate Medical Education โ€“ International (ACGME-I), which demonstrates excellence in the way medical graduates are trained through residency, internship and fellowship programs. For more information about working at HMC, please visit www.hmc.org.qa/en/employees_careers/employees_careers.aspx

NAICS: 621
NAICS Definition:
Employees: 18,209
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/arkansas-otolaryngology.jpeg
Arkansas Otolaryngology Center
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
https://images.rankiteo.com/companyimages/hamad-medical-corporation.jpeg
Hamad Medical Corporation
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
Compliance Summary
Arkansas Otolaryngology Center
100%
Compliance Rate
0/4 Standards Verified
Hamad Medical Corporation
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Medical Practices Industry Average (This Year)

No incidents recorded for Arkansas Otolaryngology Center in 2025.

Incidents vs Medical Practices Industry Average (This Year)

No incidents recorded for Hamad Medical Corporation in 2025.

Incident History โ€” Arkansas Otolaryngology Center (X = Date, Y = Severity)

Arkansas Otolaryngology Center cyber incidents detection timeline including parent company and subsidiaries

Incident History โ€” Hamad Medical Corporation (X = Date, Y = Severity)

Hamad Medical Corporation cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/arkansas-otolaryngology.jpeg
Arkansas Otolaryngology Center
Incidents

No Incident

https://images.rankiteo.com/companyimages/hamad-medical-corporation.jpeg
Hamad Medical Corporation
Incidents

No Incident

FAQ

Both Arkansas Otolaryngology Center company and Hamad Medical Corporation company demonstrate a comparable AI risk posture, with strong governance and monitoring frameworks in place.

Historically, Hamad Medical Corporation company has disclosed a higher number of cyber incidents compared to Arkansas Otolaryngology Center company.

In the current year, Hamad Medical Corporation company and Arkansas Otolaryngology Center company have not reported any cyber incidents.

Neither Hamad Medical Corporation company nor Arkansas Otolaryngology Center company has reported experiencing a ransomware attack publicly.

Neither Hamad Medical Corporation company nor Arkansas Otolaryngology Center company has reported experiencing a data breach publicly.

Neither Hamad Medical Corporation company nor Arkansas Otolaryngology Center company has reported experiencing targeted cyberattacks publicly.

Neither Arkansas Otolaryngology Center company nor Hamad Medical Corporation company has reported experiencing or disclosing vulnerabilities publicly.

Neither Arkansas Otolaryngology Center company nor Hamad Medical Corporation company has publicly disclosed detailed information about the number of their subsidiaries.

Hamad Medical Corporation company employs more people globally than Arkansas Otolaryngology Center company, reflecting its scale as a Medical Practices.

Latest Global CVEs (Not Company-Specific)

Description

Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api-key/create` route. `session?.user ?? (authRequired ? null : { id: ctx.body.userId })`. When no session exists but `userId` is present in the request body, `authRequired` becomes false and the user object is set to the attacker-controlled ID. Server-only field validation only executes when `authRequired` is true (lines 280-295), allowing attackers to set privileged fields. No additional authentication occurs before the database operation, so the malicious payload is accepted. The same pattern exists in the update endpoint. This is a critical authentication bypass enabling full an unauthenticated attacker can generate an API key for any user and immediately gain complete authenticated access. This allows the attacker to perform any action as the victim user using the api key, potentially compromise the user data and the application depending on the victim's privileges. Version 1.3.26 contains a patch for the issue.

Risk Information
cvss4
Base: 9.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstarโ€™s Reviewbot component caused inbound webhook requests to be validated against a hard-coded, shared secret. The value used for the secret token was compiled into the Allstar binary and could not be configured at runtime. In practice, this meant that every deployment using Reviewbot would validate requests with the same secret unless the operator modified source code and rebuilt the component - an expectation that is not documented and is easy to miss. All Allstar releases prior to v4.5 that include the Reviewbot code path are affected. Deployments on v4.5 and later are not affected. Those who have not enabled or exposed the Reviewbot endpoint are not exposed to this issue.

Risk Information
cvss4
Base: 4.6
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 update 35 through update 92, and 7.3 update 25 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a userโ€™s (1) First Name, (2) Middle Name or (3) Last Name text field.

Risk Information
cvss4
Base: 4.8
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate provided e-mail addresses or doesn't require unique e-mail addresses. Version 5.6.0 contains a patch. As a workaround, review the authentication service policy on e-mail addresses; many will not allow exploiting this vulnerability.

Risk Information
cvss4
Base: 6.3
Severity: HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint didn't check if the kbs-client submitting the request was actually authenticated (had the right key). This allowed any kbs-client to actually change the attestation policy. Version 0.15.0 fixes the issue.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X