Company Details
aveanna-healthcare
12,268
32,488
62
aveanna.com
0
AVE_1750747
In-progress

Aveanna Healthcare Company CyberSecurity Posture
aveanna.comAbout Aveanna It all started with a simple idea: How can we help people live better lives by providing better homecare? That idea became a company called Aveanna, dedicated to bringing new possibilities and new hope to those we serve. At Aveanna, we believe that the ultimate place for caring is right in the comfort of home. We are a new company that has quickly established itself as a pre-eminent, national leader in healthcare as well as homecare. We believe in clinical excellence, innovation, and compassionate care to every patient and family we are privileged to help. But what sets us apart most is our focus on the relationship between the caregiver and the patient. By surrounding our patients with superior resources, and by giving our caregivers better technology and training, we are able to provide superior care that makes a difference in what’s possible in outcomes and daily living. Aveanna’s leadership team has worked for more than 40 years building other great homecare companies on a national level. Now that experience is building the homecare company of the future. Today, Aveanna Healthcare cares for patients and families in 33 states through our rapidly growing network of more than 300 branch offices, offering a variety of care and services to more than 80,000 children and adults.
Company Details
aveanna-healthcare
12,268
32,488
62
aveanna.com
0
AVE_1750747
In-progress
Between 750 and 799

Aveanna Healthcare Global Score (TPRM)XXXX

Description: The California Office of the Attorney General reported that Aveanna Healthcare experienced a data breach where certain employee email accounts were accessed by an unknown actor between July 9, 2019, and August 24, 2019. Approximately 5,004 California residents were affected, with potentially compromised personal information including Social Security numbers, driver’s licenses, financial account information, medical information, and health insurance information. Written notices began mailing to affected individuals on or about February 14, 2020.


No incidents recorded for Aveanna Healthcare in 2025.
No incidents recorded for Aveanna Healthcare in 2025.
No incidents recorded for Aveanna Healthcare in 2025.
Aveanna Healthcare cyber incidents detection timeline including parent company and subsidiaries

About Aveanna It all started with a simple idea: How can we help people live better lives by providing better homecare? That idea became a company called Aveanna, dedicated to bringing new possibilities and new hope to those we serve. At Aveanna, we believe that the ultimate place for caring is right in the comfort of home. We are a new company that has quickly established itself as a pre-eminent, national leader in healthcare as well as homecare. We believe in clinical excellence, innovation, and compassionate care to every patient and family we are privileged to help. But what sets us apart most is our focus on the relationship between the caregiver and the patient. By surrounding our patients with superior resources, and by giving our caregivers better technology and training, we are able to provide superior care that makes a difference in what’s possible in outcomes and daily living. Aveanna’s leadership team has worked for more than 40 years building other great homecare companies on a national level. Now that experience is building the homecare company of the future. Today, Aveanna Healthcare cares for patients and families in 33 states through our rapidly growing network of more than 300 branch offices, offering a variety of care and services to more than 80,000 children and adults.


Com cerca de 80 anos de experiência, a Hapvida é hoje a maior empresa de saúde integrada da América Latina. A companhia, que possui mais de 69 mil colaboradores, atende quase 16 milhões de beneficiários de saúde e odontologia espalhados pelas cinco regiões do Brasil. Todo o aparato foi construído a

Anteriormente Organización Sanitas Internacional, Keralty es un grupo empresarial de valor en salud, con más de 40 años de experiencia conformado por empresas de aseguramiento y prestación de servicios de salud y una red propia hospitalaria y asistencial. También forman parte de Keralty institucion
IQVIA (NYSE:IQV) is a leading global provider of clinical research services, commercial insights and healthcare intelligence to the life sciences and healthcare industries. IQVIA’s portfolio of solutions are powered by IQVIA Connected Intelligence™ to deliver actionable insights and services built o

Welcome to the official LinkedIn page for McKesson Corporation. We're an impact-driven healthcare organization dedicated to “Advancing Health Outcomes For All.” As a global healthcare company, we touch virtually every aspect of health. Our leaders empower our people to lead with a growth mindset an

Express Scripts by Evernorth provides pharmacy benefits services with a clear mission: To simplify complexities and provide holistic, condition-focused care and clinically superior pharmacy benefit solutions for our clients and the people they serve. Guided by our core values of service, patient ca
Relationships are the heart of our culture. They help us create a sense of family among our residents, associates and patients. Integrity is our soul. It guides us to be open in our communication with each other, and it enables us to make the right decisions for the people who have entrusted us with

BayCare is a leading not-for-profit academic health care system that connects individuals and families to a wide range of services at 16 hospitals, including a children’s hospital, and hundreds of other convenient locations throughout the Tampa Bay and central Florida regions. The system is West Cen

Ramsay Health Care is a trusted provider of private hospital and healthcare services in Australia, Europe and the United Kingdom. Every year, millions of patients put their trust in Ramsay, confident in our ability to deliver safe, high-quality healthcare with outstanding clinical outcomes. We ope

Driven by the vision of its Chairman, Dr. Prathap C. Reddy, the Apollo Hospitals Group pioneered corporate healthcare in India. Apollo revolutionized healthcare when Dr Prathap Reddy opened the first hospital in Chennai in 1983. Today Apollo is the world’s largest integrated healthcare platform wit
.png)
Third Quarter Revenue was $621.9 million, a 22.2% increase over the prior year periodThird Quarter Net income was $14.1 million compared to...
ATLANTA, June 04, 2025 (GLOBE NEWSWIRE) -- Aveanna Healthcare Holdings Inc. (NASDAQ: AVAH), a leading, diversified home care platform...
Major pediatric healthcare expansion brings specialized care to 7 states. Acquisition strengthens Aveanna's market position in home care...
ATLANTA, April 03, 2025 (GLOBE NEWSWIRE) -- Aveanna Healthcare Holdings Inc. (NASDAQ: AVAH), a leading, diversified home care platform...
Aveanna Healthcare announced Thursday it has made an agreement to acquire Thrive Skilled Pediatric Care for $75 million.
Strategic acquisition of Thrive SPC strengthens Aveanna's pediatric care network, adding 23 locations and expanding into new markets.
March was a particularly bad month for healthcare data breaches with 93 breaches of 500 or more records reported to the Department of Health and Human Services...
Aveanna Healthcare agreed to pay $425000 and adopt new security measures after several phishing-related healthcare data breaches impacted...
Patients impacted by the 2019 ransomware attack on Ferguson Medical Group, now owned by Saint Francis Healthcare, reached a $350000 with the...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Aveanna Healthcare is http://aveanna.com.
According to Rankiteo, Aveanna Healthcare’s AI-generated cybersecurity score is 753, reflecting their Fair security posture.
According to Rankiteo, Aveanna Healthcare currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Aveanna Healthcare is not certified under SOC 2 Type 1.
According to Rankiteo, Aveanna Healthcare does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Aveanna Healthcare is not listed as GDPR compliant.
According to Rankiteo, Aveanna Healthcare does not currently maintain PCI DSS compliance.
According to Rankiteo, Aveanna Healthcare is not compliant with HIPAA regulations.
According to Rankiteo,Aveanna Healthcare is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Aveanna Healthcare operates primarily in the Hospitals and Health Care industry.
Aveanna Healthcare employs approximately 12,268 people worldwide.
Aveanna Healthcare presently has no subsidiaries across any sectors.
Aveanna Healthcare’s official LinkedIn profile has approximately 32,488 followers.
Aveanna Healthcare is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
Yes, Aveanna Healthcare has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/aveanna-healthcare.
Yes, Aveanna Healthcare maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/aveanna-healthcare.
As of December 12, 2025, Rankiteo reports that Aveanna Healthcare has experienced 1 cybersecurity incidents.
Aveanna Healthcare has an estimated 31,001 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with written notices mailed to affected individuals..
Title: Aveanna Healthcare Data Breach
Description: The California Office of the Attorney General reported that Aveanna Healthcare experienced a data breach where certain employee email accounts were accessed by an unknown actor between July 9, 2019, and August 24, 2019. Approximately 5,004 California residents were affected, with potentially compromised personal information including Social Security numbers, driver’s licenses, financial account information, medical information, and health insurance information. Written notices began mailing to affected individuals on or about February 14, 2020.
Date Publicly Disclosed: 2020-02-14
Type: Data Breach
Attack Vector: Email Account Compromise
Threat Actor: Unknown
Common Attack Types: The most common types of attacks the company has faced is Breach.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Email Accounts.

Data Compromised: Social security numbers, Driver’s licenses, Financial account information, Medical information, Health insurance information
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Social Security Numbers, Driver’S Licenses, Financial Account Information, Medical Information, Health Insurance Information and .

Entity Name: Aveanna Healthcare
Entity Type: Healthcare Provider
Industry: Healthcare
Location: California
Customers Affected: 5004

Communication Strategy: Written notices mailed to affected individuals

Type of Data Compromised: Social security numbers, Driver’s licenses, Financial account information, Medical information, Health insurance information
Number of Records Exposed: 5004
Sensitivity of Data: High

Source: California Office of the Attorney General
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney General.
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Written notices mailed to affected individuals.

Entry Point: Email Accounts
Last Attacking Group: The attacking group in the last incident was an Unknown.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2020-02-14.
Most Significant Data Compromised: The most significant data compromised in an incident were Social Security numbers, Driver’s licenses, Financial account information, Medical information, Health insurance information and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Financial account information, Social Security numbers, Driver’s licenses, Health insurance information and Medical information.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 504.0.
Most Recent Source: The most recent source of information about an incident is California Office of the Attorney General.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an Email Accounts.
.png)
LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing errors; SyntaxError from express.json() includes user input in the error message, which gets reflected in responses. User input (including HTML/JavaScript) can be exposed in error responses, creating an XSS risk if Content-Type isn't strictly enforced. This issue does not have a fix at the time of publication.
LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests are sent to define and modify the prompts via PATCH endpoint for prompt groups (/api/prompts/groups/:groupId). However, the request bodies are not sufficiently validated for proper input, enabling users to modify prompts in a way that was not intended as part of the front end system. The patchPromptGroup function passes req.body directly to updatePromptGroup() without filtering sensitive fields. This issue is fixed in version 0.8.1.
LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the iconURL parameter of the POST request can be modified by an attacker. The malicious code is then stored in the chat which can then be shared to other users. When sharing chats with a potentially malicious “tracker”, resources loaded can lead to loss of privacy for users who view the chat link that is sent to them. This issue is fixed in version 0.8.1.
MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and other critical files, potentially resulting in privilege escalation. This issue is fixed in version 2.4.0.
MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.