Company Details
beverly-hills-cancer-center
66
4,534
621
bhcancercenter.com
0
BEV_3353445
In-progress


Beverly Hills Cancer Center Company CyberSecurity Posture
bhcancercenter.comAbout the Practice and Mission At the Beverly Hills Cancer Center, our primary goal is to cure every patient's cancer. Since we know that in many cases advanced-stage cancers cannot be cured, our next goal is to make cancer a chronic disease, with which our patients can live and lead relatively normal lives. We accomplish our goals daily in our Los Angeles facility, which provides state-of-the-art, cutting-edge medical treatment, and caring attention to the mind, body and soul of each and every patient. With this fusion of science and caring, we aim to provide our patients with the best possible healing, and pride ourselves for being one of the best cancer treatment centers internationally. As a private, comprehensive facility, Beverly Hills Cancer Center provides state-of-the-art cancer treatment under one roof. Our facilities include an innovative radiation oncology center, a soothing and spacious infusion center, a full-service diagnostic imaging center (with MRI, CT, PET/CT, and Bone Scan technology), and a complete, award-winning diagnostic laboratory. We also conduct some of the world’s leading clinical trials for cancer treatment right here in our facility — making ours one of the top cancer centers in Los Angeles and worldwide. Driven by our unique model and goal to provide exceptional and personalized care, we have become the only private comprehensive cancer treatment facility in Southern California. By combining advanced treatment modalities and technologies, in a soothing environment with caring physicians and staff, we are able to provide maximum peace of mind for patients. While such things may seem like a luxury to some, here at the Beverly Hills Cancer Center we understand that a tranquil, stress-free environment is integral to the healing process.
Company Details
beverly-hills-cancer-center
66
4,534
621
bhcancercenter.com
0
BEV_3353445
In-progress
Between 600 and 649

BHCC Global Score (TPRM)XXXX

Description: Beverly Hills Oncology Medical Group, a California-based cancer treatment provider, experienced a data breach exposing sensitive patient information, including personal and medical records. The incident involved unauthorized access to systems containing highly confidential data, such as patient identities, treatment histories, and potentially financial details. As a specialized oncology practice, the exposure of such information poses severe risks, including identity theft, medical fraud, and reputational harm to both patients and the organization. The breach underscores vulnerabilities in healthcare cybersecurity, particularly in sectors handling life-critical data. While the exact method of compromise (e.g., phishing, system exploitation) was not detailed, the nature of the exposed data medical records elevates the severity due to its sensitivity and regulatory implications under laws like HIPAA. Patients may face long-term consequences, including targeted scams or discrimination based on their health status. The incident also risks eroding trust in the provider, potentially leading to patient attrition and legal repercussions.
Description: Beverly Hills Oncology Medical Group, a specialized cancer treatment provider, suffered a data breach between February 7–11, 2025, when cybercriminals gained unauthorized access to its internal network. An investigation concluded on October 13, 2025, confirming that sensitive patient data including full names, Social Security numbers, driver’s license/government IDs, financial account details, credit/debit card information, health insurance data, treatment records, diagnoses, prescriptions, and clinical information was accessed and exfiltrated.The breach exposed highly confidential medical and financial records, posing severe risks of identity theft, financial fraud, and misuse of health data. The incident was disclosed to the California Attorney General’s office on October 31, 2025, with affected individuals notified via mail. The breach’s scope suggests a targeted attack aimed at exploiting vulnerable patient data for malicious purposes, potentially leading to long-term reputational damage, legal liabilities, and regulatory penalties for the medical group.


No incidents recorded for Beverly Hills Cancer Center in 2026.
No incidents recorded for Beverly Hills Cancer Center in 2026.
No incidents recorded for Beverly Hills Cancer Center in 2026.
BHCC cyber incidents detection timeline including parent company and subsidiaries

About the Practice and Mission At the Beverly Hills Cancer Center, our primary goal is to cure every patient's cancer. Since we know that in many cases advanced-stage cancers cannot be cured, our next goal is to make cancer a chronic disease, with which our patients can live and lead relatively normal lives. We accomplish our goals daily in our Los Angeles facility, which provides state-of-the-art, cutting-edge medical treatment, and caring attention to the mind, body and soul of each and every patient. With this fusion of science and caring, we aim to provide our patients with the best possible healing, and pride ourselves for being one of the best cancer treatment centers internationally. As a private, comprehensive facility, Beverly Hills Cancer Center provides state-of-the-art cancer treatment under one roof. Our facilities include an innovative radiation oncology center, a soothing and spacious infusion center, a full-service diagnostic imaging center (with MRI, CT, PET/CT, and Bone Scan technology), and a complete, award-winning diagnostic laboratory. We also conduct some of the world’s leading clinical trials for cancer treatment right here in our facility — making ours one of the top cancer centers in Los Angeles and worldwide. Driven by our unique model and goal to provide exceptional and personalized care, we have become the only private comprehensive cancer treatment facility in Southern California. By combining advanced treatment modalities and technologies, in a soothing environment with caring physicians and staff, we are able to provide maximum peace of mind for patients. While such things may seem like a luxury to some, here at the Beverly Hills Cancer Center we understand that a tranquil, stress-free environment is integral to the healing process.


Hamad Medical Corporation (HMC) is the main provider of secondary and tertiary healthcare in Qatar and one of the leading hospital providers in the Middle East. For more than three decades, HMC has been dedicated to delivering the safest, most effective and compassionate care to all its patients.
.png)
One of the nation's top class action law firms is investigating a data breach at Beverly Hills Oncology Medical Group.
Got a letter about the Beverly Hills Oncology Medical Group data breach? Learn more about the incident and what legal options you could...
Strauss Borrelli PLLC, a leading data breach law firm, is investigating Beverly Hills Oncology Medical Group, which does business as Beverly...
Data breach at Beverly Hills Oncology exposed sensitive patient and staff info including SSNs and medical details.
If you were affected by the Beverly Hills Oncology Medical Group data breach, you may be entitled to compensation.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Beverly Hills Cancer Center is http://www.bhcancercenter.com.
According to Rankiteo, Beverly Hills Cancer Center’s AI-generated cybersecurity score is 640, reflecting their Poor security posture.
According to Rankiteo, Beverly Hills Cancer Center currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Beverly Hills Cancer Center has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Beverly Hills Cancer Center is not certified under SOC 2 Type 1.
According to Rankiteo, Beverly Hills Cancer Center does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Beverly Hills Cancer Center is not listed as GDPR compliant.
According to Rankiteo, Beverly Hills Cancer Center does not currently maintain PCI DSS compliance.
According to Rankiteo, Beverly Hills Cancer Center is not compliant with HIPAA regulations.
According to Rankiteo,Beverly Hills Cancer Center is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Beverly Hills Cancer Center operates primarily in the Medical Practices industry.
Beverly Hills Cancer Center employs approximately 66 people worldwide.
Beverly Hills Cancer Center presently has no subsidiaries across any sectors.
Beverly Hills Cancer Center’s official LinkedIn profile has approximately 4,534 followers.
Beverly Hills Cancer Center is classified under the NAICS code 621, which corresponds to Ambulatory Health Care Services.
No, Beverly Hills Cancer Center does not have a profile on Crunchbase.
Yes, Beverly Hills Cancer Center maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/beverly-hills-cancer-center.
As of January 24, 2026, Rankiteo reports that Beverly Hills Cancer Center has experienced 2 cybersecurity incidents.
Beverly Hills Cancer Center has an estimated 9,107 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an incident response plan activated with yes (investigation conducted), and third party assistance with epiq - privacy solutions (credit monitoring), third party assistance with shamis & gentile p.a. (legal investigation), and remediation measures with free credit/identity monitoring for affected individuals, and recovery measures with mail notifications to affected individuals, and communication strategy with direct mail to affected patients, communication strategy with public disclosure to california attorney general..
Title: Beverly Hills Oncology Medical Group Data Breach
Description: Beverly Hills Oncology Medical Group experienced a data breach between February 7, 2025, and February 11, 2025, when a cybercriminal gained unauthorized access to its internal network. An investigation concluded on October 13, 2025, that sensitive personal information of patients may have been accessed and exfiltrated. The breach was disclosed to the California Attorney General’s office on October 31, 2025. Affected individuals are being notified by mail and offered free credit monitoring services (Epiq - Privacy Solutions ID).
Date Detected: 2025-02-07
Date Publicly Disclosed: 2025-10-31
Type: data breach
Attack Vector: network intrusion
Threat Actor: cybercriminal (unknown specific group)
Motivation: financial gaindata theft
Title: Beverly Hills Oncology Medical Group Data Breach Exposing Patient Information
Description: Beverly Hills Oncology Medical Group, a cancer treatment provider based in California, has disclosed a cybersecurity incident that may have compromised sensitive personal and medical information belonging to patients.
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Full name, Social security number, Driver’s license/government id number, Financial account information, Credit/debit card information, Health insurance policy information, Treatment information, Diagnosis information, Prescription information, Clinical information
Systems Affected: internal network
Brand Reputation Impact: potential reputational damage (ongoing investigation)
Legal Liabilities: potential lawsuits for compensation (class action investigation by Shamis & Gentile P.A.)
Identity Theft Risk: high (PII and financial data exposed)
Payment Information Risk: high (credit/debit card and financial account information exposed)

Data Compromised: Sensitive personal information, Medical information
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personally Identifiable Information (Pii), Protected Health Information (Phi), Financial Information, , Personal Information, Medical Information and .

Entity Name: Beverly Hills Oncology Medical Group
Entity Type: medical practice
Industry: healthcare (oncology)
Location: Beverly Hills, California, USA

Entity Name: Beverly Hills Oncology Medical Group
Entity Type: Healthcare Provider
Industry: Healthcare (Cancer Treatment)
Location: Beverly Hills, California, USA

Incident Response Plan Activated: yes (investigation conducted)
Third Party Assistance: Epiq - Privacy Solutions (Credit Monitoring), Shamis & Gentile P.A. (Legal Investigation).
Remediation Measures: free credit/identity monitoring for affected individuals
Recovery Measures: mail notifications to affected individuals
Communication Strategy: direct mail to affected patientspublic disclosure to California Attorney General
Third-Party Assistance: The company involves third-party assistance in incident response through Epiq - Privacy Solutions (credit monitoring), Shamis & Gentile P.A. (legal investigation), .

Type of Data Compromised: Personally identifiable information (pii), Protected health information (phi), Financial information
Sensitivity of Data: high (includes SSN, medical records, financial data)
Data Exfiltration: yes (data accessed and removed from network)
Personally Identifiable Information: full nameSocial Security numberdriver’s license/government ID numberfinancial account informationcredit/debit card information

Type of Data Compromised: Personal information, Medical information
Sensitivity of Data: High (Personal and medical records)
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: free credit/identity monitoring for affected individuals, .
Data Recovery from Ransomware: The company recovers data encrypted by ransomware through mail notifications to affected individuals, .

Regulations Violated: potential HIPAA violations (health data breach), California data breach notification laws,
Legal Actions: class action investigation by Shamis & Gentile P.A.,
Regulatory Notifications: California Attorney General’s office (notified on 2025-10-31)

Regulations Violated: Potentially HIPAA (Health Insurance Portability and Accountability Act),
Ensuring Regulatory Compliance: The company ensures compliance with regulatory requirements through class action investigation by Shamis & Gentile P.A., .

Recommendations: Enroll in free credit/identity monitoring (Epiq - Privacy Solutions ID)., Monitor financial accounts for suspicious activity., Place a fraud alert on credit reports., Request free annual credit reports from major bureaus., Seek legal counsel for potential compensation claims.Enroll in free credit/identity monitoring (Epiq - Privacy Solutions ID)., Monitor financial accounts for suspicious activity., Place a fraud alert on credit reports., Request free annual credit reports from major bureaus., Seek legal counsel for potential compensation claims.Enroll in free credit/identity monitoring (Epiq - Privacy Solutions ID)., Monitor financial accounts for suspicious activity., Place a fraud alert on credit reports., Request free annual credit reports from major bureaus., Seek legal counsel for potential compensation claims.Enroll in free credit/identity monitoring (Epiq - Privacy Solutions ID)., Monitor financial accounts for suspicious activity., Place a fraud alert on credit reports., Request free annual credit reports from major bureaus., Seek legal counsel for potential compensation claims.Enroll in free credit/identity monitoring (Epiq - Privacy Solutions ID)., Monitor financial accounts for suspicious activity., Place a fraud alert on credit reports., Request free annual credit reports from major bureaus., Seek legal counsel for potential compensation claims.

Source: Shamis & Gentile P.A. (class action investigation page)
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Shamis & Gentile P.A. (class action investigation page).

Investigation Status: completed (as of 2025-10-13)
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Direct Mail To Affected Patients and Public Disclosure To California Attorney General.

Stakeholder Advisories: Mail Notifications To Affected Patients.
Customer Advisories: Offer of free Epiq - Privacy Solutions ID membership.Guidance on credit monitoring, fraud alerts, and legal rights.
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Mail Notifications To Affected Patients, Offer Of Free Epiq - Privacy Solutions Id Membership., Guidance On Credit Monitoring, Fraud Alerts, And Legal Rights. and .

High Value Targets: Patient Pii/Phi, Financial Data,
Data Sold on Dark Web: Patient Pii/Phi, Financial Data,
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Epiq - Privacy Solutions (Credit Monitoring), Shamis & Gentile P.A. (Legal Investigation), .
Last Attacking Group: The attacking group in the last incident was an cybercriminal (unknown specific group).
Most Recent Incident Detected: The most recent incident detected was on 2025-02-07.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-10-31.
Most Significant Data Compromised: The most significant data compromised in an incident were full name, Social Security number, driver’s license/government ID number, financial account information, credit/debit card information, health insurance policy information, treatment information, diagnosis information, prescription information, clinical information, , Sensitive personal information, Medical information and .
Most Significant System Affected: The most significant system affected in an incident was internal network.
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was epiq - privacy solutions (credit monitoring), shamis & gentile p.a. (legal investigation), .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were credit/debit card information, Medical information, full name, prescription information, financial account information, treatment information, Sensitive personal information, Social Security number, driver’s license/government ID number, diagnosis information, health insurance policy information and clinical information.
Most Significant Legal Action: The most significant legal action taken for a regulatory violation was class action investigation by Shamis & Gentile P.A., .
Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Seek legal counsel for potential compensation claims., Place a fraud alert on credit reports., Enroll in free credit/identity monitoring (Epiq - Privacy Solutions ID)., Request free annual credit reports from major bureaus. and Monitor financial accounts for suspicious activity..
Most Recent Source: The most recent source of information about an incident is Shamis & Gentile P.A. (class action investigation page).
Current Status of Most Recent Investigation: The current status of the most recent investigation is completed (as of 2025-10-13).
Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was mail notifications to affected patients, .
Most Recent Customer Advisory: The most recent customer advisory issued were an Offer of free Epiq - Privacy Solutions ID membership.Guidance on credit monitoring, fraud alerts and and legal rights.
.png)
Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.
An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.