ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Casa de Salud (Casa) is a non-profit health clinic located in the City of St. Louis. Casa opened its doors in January 2010 with a mission to deliver high quality clinical and mental healthcare for uninsured and underinsured patients, focusing on new immigrants and refugees who encounter barriers to accessing other sources of care. Casa promotes better health outcomes through prevention and treatment, while also acting as a portal to other services through collaborations with many health and social service organizations in the metro St. Louis area.

Casa de Salud A.I CyberSecurity Scoring

CDS

Company Details

Linkedin ID:

casa-de-salud

Employees number:

65

Number of followers:

744

NAICS:

71394

Industry Type:

Wellness and Fitness Services

Homepage:

casadesaludstl.org

IP Addresses:

0

Company ID:

CAS_4284298

Scan Status:

In-progress

AI scoreCDS Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/casa-de-salud.jpeg
CDS Wellness and Fitness Services
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreCDS Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/casa-de-salud.jpeg
CDS Wellness and Fitness Services
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

CDS Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Casa de SaludBreach8046/2020
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: La Casa de Salud also fell victim to a data security breach at Acacia Network that impacted 9,969 individuals connected to La Casa de Salud. An unauthorized individual gained access to employee email accounts for six days in June 2020 and compromised the patient information including Social Security numbers, medical record numbers, birth dates, driver’s license numbers, addresses, financial account numbers, names, Medicare numbers, provider names, treatment information, and prescription information. Acacia Network investigated the incident and evaluated and modified its practices to enhance the security and privacy of clients’ information.

Casa de Salud
Breach
Severity: 80
Impact: 4
Seen: 6/2020
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: La Casa de Salud also fell victim to a data security breach at Acacia Network that impacted 9,969 individuals connected to La Casa de Salud. An unauthorized individual gained access to employee email accounts for six days in June 2020 and compromised the patient information including Social Security numbers, medical record numbers, birth dates, driver’s license numbers, addresses, financial account numbers, names, Medicare numbers, provider names, treatment information, and prescription information. Acacia Network investigated the incident and evaluated and modified its practices to enhance the security and privacy of clients’ information.

Ailogo

CDS Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for CDS

Incidents vs Wellness and Fitness Services Industry Average (This Year)

No incidents recorded for Casa de Salud in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Casa de Salud in 2025.

Incident Types CDS vs Wellness and Fitness Services Industry Avg (This Year)

No incidents recorded for Casa de Salud in 2025.

Incident History — CDS (X = Date, Y = Severity)

CDS cyber incidents detection timeline including parent company and subsidiaries

CDS Company Subsidiaries

SubsidiaryImage

Casa de Salud (Casa) is a non-profit health clinic located in the City of St. Louis. Casa opened its doors in January 2010 with a mission to deliver high quality clinical and mental healthcare for uninsured and underinsured patients, focusing on new immigrants and refugees who encounter barriers to accessing other sources of care. Casa promotes better health outcomes through prevention and treatment, while also acting as a portal to other services through collaborations with many health and social service organizations in the metro St. Louis area.

Loading...
similarCompanies

CDS Similar Companies

Purpose Brands, LLC

Purpose Brands, LLC provides fitness, nutrition and wellness support and services to more than 7,000 communities and millions of people around the world. We own and operate the world’s largest and most trusted portfolio of fitness, health and wellness franchise brands and services: Anytime Fit

Massage Envy

Massage Envy is the nation’s #1 provider of massage collectively across its franchise network and a national leader in skin care. All Massage Envy locations are independently owned and operated franchises, where the franchisee is the sole employer of all positions. Massage Envy combines big-brand r

Planet Fitness

Planet Fitness is taking the fitness industry by storm! Enhancing people’s lives with an affordable, high-quality fitness experience requires a team of inspiring, motivated and fun-loving go-getters. As one of the largest and fastest-growing franchisors and operators of fitness centers in the Unit

Forever Living Products (UK) Ltd

Forever Living Products and its affiliates are the largest growers, manufacturer and distributors of Aloe Vera products. The key to Forever Living's success is commitment to quality and purity. In order to ensure the highest quality, Forever Living cultivates aloe vera on its privately owned plantat

LA Fitness

LA Fitness is a privately owned fitness club chain. LA Fitness has hundreds of health clubs gyms and millions of members across US and Canada. In an industry often equated with fad and fashion, LA Fitness has steadily increased its presence by focusing on the one lifelong benefit valued by everyone:

Aetna, a CVS Health Company

Here at Aetna, a CVS Health® company, we’re building a healthier world by making health care easy, affordable and all about you. Because Healthier Happens Together™! Follow our page for company news, industry commentary, jobs and more. Founded in 1853 in Hartford, CT, Aetna® is one of the nation's l

American Heart Association

Welcome to the American Heart Association’s movement to change the future of health and be the progress that ensures longer, healthier lives for all. By driving breakthroughs in science, policy, and care – together -- we can overcome today’s biggest health challenges and transform lives every day.

Herbalife

Herbalife is a global health and wellness community born to support you in living your best life. For over 40 years and in more than 90 countries, we’ve empowered millions of people to make real changes to their lives with our science-backed products, the support of a coach – what we call an Herbali

Life Time Inc.

Life Time provides an entertaining, educational, friendly and inviting, functional and innovative experience of uncompromising quality that meets the health and fitness needs of the entire family. Life Time is a wellness pioneer reshaping the way consumers approach their health by integrating where

newsone

CDS CyberSecurity News

September 08, 2022 08:43 AM
Online IT Boot Camps

Virginia Wesleyan University Global Campus IT boot camps will prepare you for in-demand, high-paying jobs in the tech sector. Gain the skills and practical...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

CDS CyberSecurity History Information

Official Website of Casa de Salud

The official website of Casa de Salud is http://www.casadesaludstl.org.

Casa de Salud’s AI-Generated Cybersecurity Score

According to Rankiteo, Casa de Salud’s AI-generated cybersecurity score is 743, reflecting their Moderate security posture.

How many security badges does Casa de Salud’ have ?

According to Rankiteo, Casa de Salud currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Casa de Salud have SOC 2 Type 1 certification ?

According to Rankiteo, Casa de Salud is not certified under SOC 2 Type 1.

Does Casa de Salud have SOC 2 Type 2 certification ?

According to Rankiteo, Casa de Salud does not hold a SOC 2 Type 2 certification.

Does Casa de Salud comply with GDPR ?

According to Rankiteo, Casa de Salud is not listed as GDPR compliant.

Does Casa de Salud have PCI DSS certification ?

According to Rankiteo, Casa de Salud does not currently maintain PCI DSS compliance.

Does Casa de Salud comply with HIPAA ?

According to Rankiteo, Casa de Salud is not compliant with HIPAA regulations.

Does Casa de Salud have ISO 27001 certification ?

According to Rankiteo,Casa de Salud is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Casa de Salud

Casa de Salud operates primarily in the Wellness and Fitness Services industry.

Number of Employees at Casa de Salud

Casa de Salud employs approximately 65 people worldwide.

Subsidiaries Owned by Casa de Salud

Casa de Salud presently has no subsidiaries across any sectors.

Casa de Salud’s LinkedIn Followers

Casa de Salud’s official LinkedIn profile has approximately 744 followers.

NAICS Classification of Casa de Salud

Casa de Salud is classified under the NAICS code 71394, which corresponds to Fitness and Recreational Sports Centers.

Casa de Salud’s Presence on Crunchbase

No, Casa de Salud does not have a profile on Crunchbase.

Casa de Salud’s Presence on LinkedIn

Yes, Casa de Salud maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/casa-de-salud.

Cybersecurity Incidents Involving Casa de Salud

As of December 22, 2025, Rankiteo reports that Casa de Salud has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Casa de Salud has an estimated 12,129 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Casa de Salud ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

How does Casa de Salud detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an remediation measures with evaluated and modified its practices to enhance the security and privacy of clients’ information...

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Data Security Breach at Acacia Network Impacting La Casa de Salud

Description: An unauthorized individual gained access to employee email accounts for six days in June 2020 and compromised the patient information including Social Security numbers, medical record numbers, birth dates, driver’s license numbers, addresses, financial account numbers, names, Medicare numbers, provider names, treatment information, and prescription information.

Date Detected: June 2020

Type: Data Breach

Attack Vector: Email Account Compromise

Vulnerability Exploited: Unauthorized Access

Threat Actor: Unauthorized Individual

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

How does the company identify the attack vectors used in incidents ?

Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Email Accounts.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach CAS42711622

Data Compromised: Social security numbers, Medical record numbers, Birth dates, Driver’s license numbers, Addresses, Financial account numbers, Names, Medicare numbers, Provider names, Treatment information, Prescription information

Systems Affected: Email Accounts

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Social Security Numbers, Medical Record Numbers, Birth Dates, Driver’S License Numbers, Addresses, Financial Account Numbers, Names, Medicare Numbers, Provider Names, Treatment Information, Prescription Information and .

Which entities were affected by each incident ?

Incident : Data Breach CAS42711622

Entity Name: Acacia Network

Entity Type: Healthcare Organization

Industry: Healthcare

Customers Affected: 9969

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Breach CAS42711622

Remediation Measures: Evaluated and modified its practices to enhance the security and privacy of clients’ information.

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach CAS42711622

Type of Data Compromised: Social security numbers, Medical record numbers, Birth dates, Driver’s license numbers, Addresses, Financial account numbers, Names, Medicare numbers, Provider names, Treatment information, Prescription information

Number of Records Exposed: 9969

Sensitivity of Data: High

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Evaluated and modified its practices to enhance the security and privacy of clients’ information..

Initial Access Broker

How did the initial access broker gain entry for each incident ?

Incident : Data Breach CAS42711622

Entry Point: Email Accounts

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Data Breach CAS42711622

Corrective Actions: Evaluated and modified its practices to enhance the security and privacy of clients’ information.

What corrective actions has the company taken based on post-incident analysis ?

Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Evaluated and modified its practices to enhance the security and privacy of clients’ information..

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident was an Unauthorized Individual.

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on June 2020.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Social Security numbers, Medical record numbers, Birth dates, Driver’s license numbers, Addresses, Financial account numbers, Names, Medicare numbers, Provider names, Treatment information, Prescription information and .

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Financial account numbers, Medicare numbers, Names, Birth dates, Provider names, Prescription information, Medical record numbers, Treatment information, Driver’s license numbers, Addresses and Social Security numbers.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 1.0K.

Initial Access Broker

What was the most recent entry point used by an initial access broker ?

Most Recent Entry Point: The most recent entry point used by an initial access broker was an Email Accounts.

cve

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyDevs TempTool allows Stored XSS.This issue affects TempTool: from n/a through 1.3.1.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tormorten WP Microdata allows Stored XSS.This issue affects WP Microdata: from n/a through 1.0.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Description

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool allows Retrieve Embedded Sensitive Data.This issue affects TempTool: from n/a through 1.3.1.

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description

A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Risk Information
cvss2
Base: 9.0
Severity: LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
cvss3
Base: 8.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 7.4
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=casa-de-salud' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge