Company Details
casa-de-salud
65
744
71394
casadesaludstl.org
0
CAS_4284298
In-progress

Casa de Salud Company CyberSecurity Posture
casadesaludstl.orgCasa de Salud (Casa) is a non-profit health clinic located in the City of St. Louis. Casa opened its doors in January 2010 with a mission to deliver high quality clinical and mental healthcare for uninsured and underinsured patients, focusing on new immigrants and refugees who encounter barriers to accessing other sources of care. Casa promotes better health outcomes through prevention and treatment, while also acting as a portal to other services through collaborations with many health and social service organizations in the metro St. Louis area.
Company Details
casa-de-salud
65
744
71394
casadesaludstl.org
0
CAS_4284298
In-progress
Between 700 and 749

CDS Global Score (TPRM)XXXX

Description: La Casa de Salud also fell victim to a data security breach at Acacia Network that impacted 9,969 individuals connected to La Casa de Salud. An unauthorized individual gained access to employee email accounts for six days in June 2020 and compromised the patient information including Social Security numbers, medical record numbers, birth dates, driver’s license numbers, addresses, financial account numbers, names, Medicare numbers, provider names, treatment information, and prescription information. Acacia Network investigated the incident and evaluated and modified its practices to enhance the security and privacy of clients’ information.


No incidents recorded for Casa de Salud in 2025.
No incidents recorded for Casa de Salud in 2025.
No incidents recorded for Casa de Salud in 2025.
CDS cyber incidents detection timeline including parent company and subsidiaries

Casa de Salud (Casa) is a non-profit health clinic located in the City of St. Louis. Casa opened its doors in January 2010 with a mission to deliver high quality clinical and mental healthcare for uninsured and underinsured patients, focusing on new immigrants and refugees who encounter barriers to accessing other sources of care. Casa promotes better health outcomes through prevention and treatment, while also acting as a portal to other services through collaborations with many health and social service organizations in the metro St. Louis area.


Purpose Brands, LLC provides fitness, nutrition and wellness support and services to more than 7,000 communities and millions of people around the world. We own and operate the world’s largest and most trusted portfolio of fitness, health and wellness franchise brands and services: Anytime Fit

Massage Envy is the nation’s #1 provider of massage collectively across its franchise network and a national leader in skin care. All Massage Envy locations are independently owned and operated franchises, where the franchisee is the sole employer of all positions. Massage Envy combines big-brand r
Planet Fitness is taking the fitness industry by storm! Enhancing people’s lives with an affordable, high-quality fitness experience requires a team of inspiring, motivated and fun-loving go-getters. As one of the largest and fastest-growing franchisors and operators of fitness centers in the Unit

Forever Living Products and its affiliates are the largest growers, manufacturer and distributors of Aloe Vera products. The key to Forever Living's success is commitment to quality and purity. In order to ensure the highest quality, Forever Living cultivates aloe vera on its privately owned plantat
LA Fitness is a privately owned fitness club chain. LA Fitness has hundreds of health clubs gyms and millions of members across US and Canada. In an industry often equated with fad and fashion, LA Fitness has steadily increased its presence by focusing on the one lifelong benefit valued by everyone:

Here at Aetna, a CVS Health® company, we’re building a healthier world by making health care easy, affordable and all about you. Because Healthier Happens Together™! Follow our page for company news, industry commentary, jobs and more. Founded in 1853 in Hartford, CT, Aetna® is one of the nation's l

Welcome to the American Heart Association’s movement to change the future of health and be the progress that ensures longer, healthier lives for all. By driving breakthroughs in science, policy, and care – together -- we can overcome today’s biggest health challenges and transform lives every day.

Herbalife is a global health and wellness community born to support you in living your best life. For over 40 years and in more than 90 countries, we’ve empowered millions of people to make real changes to their lives with our science-backed products, the support of a coach – what we call an Herbali
Life Time provides an entertaining, educational, friendly and inviting, functional and innovative experience of uncompromising quality that meets the health and fitness needs of the entire family. Life Time is a wellness pioneer reshaping the way consumers approach their health by integrating where
.png)
Virginia Wesleyan University Global Campus IT boot camps will prepare you for in-demand, high-paying jobs in the tech sector. Gain the skills and practical...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Casa de Salud is http://www.casadesaludstl.org.
According to Rankiteo, Casa de Salud’s AI-generated cybersecurity score is 743, reflecting their Moderate security posture.
According to Rankiteo, Casa de Salud currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Casa de Salud is not certified under SOC 2 Type 1.
According to Rankiteo, Casa de Salud does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Casa de Salud is not listed as GDPR compliant.
According to Rankiteo, Casa de Salud does not currently maintain PCI DSS compliance.
According to Rankiteo, Casa de Salud is not compliant with HIPAA regulations.
According to Rankiteo,Casa de Salud is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Casa de Salud operates primarily in the Wellness and Fitness Services industry.
Casa de Salud employs approximately 65 people worldwide.
Casa de Salud presently has no subsidiaries across any sectors.
Casa de Salud’s official LinkedIn profile has approximately 744 followers.
Casa de Salud is classified under the NAICS code 71394, which corresponds to Fitness and Recreational Sports Centers.
No, Casa de Salud does not have a profile on Crunchbase.
Yes, Casa de Salud maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/casa-de-salud.
As of December 22, 2025, Rankiteo reports that Casa de Salud has experienced 1 cybersecurity incidents.
Casa de Salud has an estimated 12,129 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an remediation measures with evaluated and modified its practices to enhance the security and privacy of clients’ information...
Title: Data Security Breach at Acacia Network Impacting La Casa de Salud
Description: An unauthorized individual gained access to employee email accounts for six days in June 2020 and compromised the patient information including Social Security numbers, medical record numbers, birth dates, driver’s license numbers, addresses, financial account numbers, names, Medicare numbers, provider names, treatment information, and prescription information.
Date Detected: June 2020
Type: Data Breach
Attack Vector: Email Account Compromise
Vulnerability Exploited: Unauthorized Access
Threat Actor: Unauthorized Individual
Common Attack Types: The most common types of attacks the company has faced is Breach.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Email Accounts.

Data Compromised: Social security numbers, Medical record numbers, Birth dates, Driver’s license numbers, Addresses, Financial account numbers, Names, Medicare numbers, Provider names, Treatment information, Prescription information
Systems Affected: Email Accounts
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Social Security Numbers, Medical Record Numbers, Birth Dates, Driver’S License Numbers, Addresses, Financial Account Numbers, Names, Medicare Numbers, Provider Names, Treatment Information, Prescription Information and .

Entity Name: Acacia Network
Entity Type: Healthcare Organization
Industry: Healthcare
Customers Affected: 9969

Remediation Measures: Evaluated and modified its practices to enhance the security and privacy of clients’ information.

Type of Data Compromised: Social security numbers, Medical record numbers, Birth dates, Driver’s license numbers, Addresses, Financial account numbers, Names, Medicare numbers, Provider names, Treatment information, Prescription information
Number of Records Exposed: 9969
Sensitivity of Data: High
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Evaluated and modified its practices to enhance the security and privacy of clients’ information..

Entry Point: Email Accounts

Corrective Actions: Evaluated and modified its practices to enhance the security and privacy of clients’ information.
Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Evaluated and modified its practices to enhance the security and privacy of clients’ information..
Last Attacking Group: The attacking group in the last incident was an Unauthorized Individual.
Most Recent Incident Detected: The most recent incident detected was on June 2020.
Most Significant Data Compromised: The most significant data compromised in an incident were Social Security numbers, Medical record numbers, Birth dates, Driver’s license numbers, Addresses, Financial account numbers, Names, Medicare numbers, Provider names, Treatment information, Prescription information and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Financial account numbers, Medicare numbers, Names, Birth dates, Provider names, Prescription information, Medical record numbers, Treatment information, Driver’s license numbers, Addresses and Social Security numbers.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 1.0K.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an Email Accounts.
.png)
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyDevs TempTool allows Stored XSS.This issue affects TempTool: from n/a through 1.3.1.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tormorten WP Microdata allows Stored XSS.This issue affects WP Microdata: from n/a through 1.0.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool allows Retrieve Embedded Sensitive Data.This issue affects TempTool: from n/a through 1.3.1.
A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.