Company Details
brownuniversityhealth
29,413
66,088
62
lifespan.org
0
LIF_1388785
In-progress

Lifespan Company CyberSecurity Posture
lifespan.orgLifespan, Rhode Island's first health system, was founded in 1994 by Rhode Island Hospital and The Miriam Hospital. A comprehensive, integrated, academic health system, Lifespan’s present partners also include RI Hospital’s Hasbro Children's Hospital , Bradley Hospital, and Newport Hospital. A not-for-profit organization, Lifespan is overseen by a board of volunteer community leaders who are guided by its mission to improve the health status of the people it serves in Rhode Island and New England through the provision of customer friendly, geographically accessible and high value services. At Lifespan, Rhode Island’s largest health system and private employer, our employees represent a broad spectrum of experience, occupations and cultural backgrounds. Throughout Lifespan’s network of nationally recognized hospitals, you’ll find a commitment to community wellbeing and world-class nursing and health care opportunities. If you share our commitment to community caring, we invite you to choose the hospital and the area that suits you best, whether it’s Providence, named one of the best places to live in the U.S., or beautiful Newport, the “city by the sea.” The American Heart Association has certified the Lifespan health system as a Gold Level Start! Fit-Friendly Company, an award that recognizes employers that go “above and beyond” in promoting their employees’ health. Lifespan is the only Rhode Island company with this certification.
Company Details
brownuniversityhealth
29,413
66,088
62
lifespan.org
0
LIF_1388785
In-progress
Between 750 and 799

Lifespan Global Score (TPRM)XXXX

Description: The Maryland Office of the Attorney General reported a data breach involving LIFESPAN, Incorporated on May 3, 2022. The breach occurred on April 12, 2022, due to a cybersecurity incident that encrypted data on their servers, potentially exposing personal information such as Social Security numbers and bank routing numbers. Approximately one individual from Rhode Island was affected.


No incidents recorded for Lifespan in 2025.
No incidents recorded for Lifespan in 2025.
No incidents recorded for Lifespan in 2025.
Lifespan cyber incidents detection timeline including parent company and subsidiaries

Lifespan, Rhode Island's first health system, was founded in 1994 by Rhode Island Hospital and The Miriam Hospital. A comprehensive, integrated, academic health system, Lifespan’s present partners also include RI Hospital’s Hasbro Children's Hospital , Bradley Hospital, and Newport Hospital. A not-for-profit organization, Lifespan is overseen by a board of volunteer community leaders who are guided by its mission to improve the health status of the people it serves in Rhode Island and New England through the provision of customer friendly, geographically accessible and high value services. At Lifespan, Rhode Island’s largest health system and private employer, our employees represent a broad spectrum of experience, occupations and cultural backgrounds. Throughout Lifespan’s network of nationally recognized hospitals, you’ll find a commitment to community wellbeing and world-class nursing and health care opportunities. If you share our commitment to community caring, we invite you to choose the hospital and the area that suits you best, whether it’s Providence, named one of the best places to live in the U.S., or beautiful Newport, the “city by the sea.” The American Heart Association has certified the Lifespan health system as a Gold Level Start! Fit-Friendly Company, an award that recognizes employers that go “above and beyond” in promoting their employees’ health. Lifespan is the only Rhode Island company with this certification.


UMass Memorial Health is the health and wellness partner of the people of Central Massachusetts. Through pain and pandemics, our commitment to our communities never wanes. We use knowledge and innovation to create breakthrough medicine, to create jobs, and to make life better for those we serve. We
Sutter Health is a not-for-profit, people-centered healthcare system providing comprehensive care throughout California. Sutter Health is committed to innovative, high-quality patient care and community partnerships, and innovative, high-quality patient care. Today, Sutter Health is pursuing a bold

A world-leading integrated healthcare provider, IHH believes that making a difference starts with our aspiration to Care. For Good. Our team of 65,000 people commit to deliver greater good to our patients, people, the public and our planet, as we live our purpose each day to touch lives and trans

One of the nation’s largest and most respected providers of hospital and healthcare services, Universal Health Services, Inc. (NYSE: UHS) has built an impressive record of achievement and performance, growing since its inception into a Fortune 300 corporation. Headquartered in King of Prussia, PA, U

Anteriormente Organización Sanitas Internacional, Keralty es un grupo empresarial de valor en salud, con más de 40 años de experiencia conformado por empresas de aseguramiento y prestación de servicios de salud y una red propia hospitalaria y asistencial. También forman parte de Keralty institucion

At Mercy Health, we understand that every family is a universe. A network of people who love, and support, and count on one other to be there. Everybody means the world to someone and we are committed to care for others so they can be there for the ones they love. With nearly 35,000 employees across

From a single medical centre to a performance-driven healthcare enterprise spread across more than 400+ medical establishments, including 15 hospitals, 120 clinics and 307 pharmacies in GCC and growing, Aster DM Healthcare has transitioned into being the leading healthcare authority across the Middl

Atrium Health, part of Advocate Health, is redefining how, when and where care is delivered. We are rethinking methods of care delivery to reach more people and bringing human kindness to every step of their health journey. Our dedication to elevating health care for every individual, every teammate
Geisinger is among the nation’s leading providers of value-based care, serving 1.2 million people in urban and rural communities across Pennsylvania. Founded in 1915 by philanthropist Abigail Geisinger, the nonprofit system generates $10 billion in annual revenues across 126 care sites — including 1
.png)
iWave's telematics portfolio of TCUs, Telematic Gateways and loggers feature cybersecurity by design. As connected automotive and telematics...
When Microsoft announced it was ending support for Windows 10 last week, about 40 percent of all Windows users faced limited options.
A sophisticated malvertising campaign is using fake Microsoft Teams installers to compromise corporate systems, leveraging poisoned search...
This research demonstrates that Vehicle-to-Grid technology, bolstered by artificial intelligence and enhanced cybersecurity measures,...
Sep 16, 2025. The 15th of March is etched in history as the day when Julius Caesar met his end at the hands of the senators of Rome, and it's about to...
Apple has issued a warning regarding highly sophisticated "mercenary spyware" attacks targeting a select group of its users.
Learn how to protect your devices from Crypto Mining Applications by isolating them effectively and preventing unauthorized resource usage.
Identity and Access Management (IAM) is becoming an increasingly vital component of cyber defense in operational technology (OT) and...
Analyst(s): Olivier Blanchard Publication Date: June 24, 2025. AMD has released the Ryzen 5 5500X3D, a budget-friendly, 6-core desktop CPU built on Zen 3...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Lifespan is http://www.lifespan.org.
According to Rankiteo, Lifespan’s AI-generated cybersecurity score is 786, reflecting their Fair security posture.
According to Rankiteo, Lifespan currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Lifespan is not certified under SOC 2 Type 1.
According to Rankiteo, Lifespan does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Lifespan is not listed as GDPR compliant.
According to Rankiteo, Lifespan does not currently maintain PCI DSS compliance.
According to Rankiteo, Lifespan is not compliant with HIPAA regulations.
According to Rankiteo,Lifespan is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Lifespan operates primarily in the Hospitals and Health Care industry.
Lifespan employs approximately 29,413 people worldwide.
Lifespan presently has no subsidiaries across any sectors.
Lifespan’s official LinkedIn profile has approximately 66,088 followers.
Lifespan is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
No, Lifespan does not have a profile on Crunchbase.
Yes, Lifespan maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/brownuniversityhealth.
As of November 27, 2025, Rankiteo reports that Lifespan has experienced 1 cybersecurity incidents.
Lifespan has an estimated 29,962 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.
Title: Data Breach at LIFESPAN, Incorporated
Description: A data breach involving LIFESPAN, Incorporated was reported by the Maryland Office of the Attorney General on May 3, 2022. The breach occurred on April 12, 2022, due to a cybersecurity incident that encrypted data on their servers, potentially exposing personal information such as Social Security numbers and bank routing numbers. Approximately one individual from Rhode Island was affected.
Date Detected: 2022-04-12
Date Publicly Disclosed: 2022-05-03
Type: Data Breach
Attack Vector: Encryption of data on servers
Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Data Compromised: Social security numbers, Bank routing numbers
Systems Affected: Servers
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Social Security Numbers, Bank Routing Numbers and .

Entity Name: LIFESPAN, Incorporated
Entity Type: Company
Location: Rhode Island
Customers Affected: 1

Type of Data Compromised: Social security numbers, Bank routing numbers
Number of Records Exposed: 1
Sensitivity of Data: High

Data Encryption: True

Source: Maryland Office of the Attorney General
Date Accessed: 2022-05-03
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maryland Office of the Attorney GeneralDate Accessed: 2022-05-03.
Most Recent Incident Detected: The most recent incident detected was on 2022-04-12.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2022-05-03.
Most Significant Data Compromised: The most significant data compromised in an incident were Social Security numbers, bank routing numbers and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were bank routing numbers and Social Security numbers.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 1.0.
Most Recent Source: The most recent source of information about an incident is Maryland Office of the Attorney General.
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.