Comparison Overview

Change Healthcare

VS

Ricoh USA, Inc.

Change Healthcare

Nashville, Tennessee, US, 37217
Last Update: 2025-11-29

Change Healthcare is now a part of Optum. To stay up-to-date with news please connect with us at Optum.com. At both Optum and Change Healthcare, our teams strive to help people live healthier lives and help the health system work better for everyone.

NAICS: 5415
NAICS Definition: Computer Systems Design and Related Services
Employees: 4,876
Subsidiaries: 0
12-month incidents
5
Known data breaches
4
Attack type number
3

Ricoh USA, Inc.

300 Eagleview Blvd, Exton, PA, US, 19341
Last Update: 2025-11-24
Between 750 and 799

At Ricoh, we bring people, processes, and technology together to make information work for you. We unlock the power of information so organizations can unlock the full potential of their people. We're a leader in information management and digital services, creating competitive advantage for over 1.4 million businesses across the globe. Our team members serve a vast array of industries, using an innovative mix of people, processes, and technology to free trapped and hidden insights. We believe having access to the right information translates to better business agility, more human experiences, and the ability to thrive in today's age of hybrid and borderless work.

NAICS: 5415
NAICS Definition: Computer Systems Design and Related Services
Employees: 18,122
Subsidiaries: 2
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/change-healthcare.jpeg
Change Healthcare
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/ricoh-company-ltd-.jpeg
Ricoh USA, Inc.
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Change Healthcare
100%
Compliance Rate
0/4 Standards Verified
Ricoh USA, Inc.
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs IT Services and IT Consulting Industry Average (This Year)

Change Healthcare has 825.93% more incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs IT Services and IT Consulting Industry Average (This Year)

No incidents recorded for Ricoh USA, Inc. in 2025.

Incident History — Change Healthcare (X = Date, Y = Severity)

Change Healthcare cyber incidents detection timeline including parent company and subsidiaries

Incident History — Ricoh USA, Inc. (X = Date, Y = Severity)

Ricoh USA, Inc. cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/change-healthcare.jpeg
Change Healthcare
Incidents

Date Detected: 6/2025
Type:Ransomware
Attack Vector: Compromised Legitimate Websites (e.g., WordPress via wp-admin exploits), Domain Shadowing (malicious subdomains on trusted sites), Malicious Software Updates (e.g., browser/Flash Player impersonation), Traffic Distribution Systems (TDS) like Keitaro and Parrot TDS, Malvertising (e.g., Google Ads impersonating Kaiser Permanente HR portal)
Motivation: Financial Gain (MaaS subscriptions, ransomware profits), Cybercrime Enablement (selling access to affiliates), State-Sponsored Activities (via GRU Unit 29155)
Blog: Blog

Date Detected: 6/2025
Type:Ransomware
Attack Vector: Phishing (AI-enhanced), Impersonation (voice synthesis, browser-based), Vendor Supply Chain Compromise, Double Extortion (ransomware + data theft)
Motivation: Financial gain (ransomware, extortion), Data theft for resale/exploitation, Disruption of operations (supply chain impact)
Blog: Blog

Date Detected: 3/2025
Type:Ransomware
Blog: Blog
https://images.rankiteo.com/companyimages/ricoh-company-ltd-.jpeg
Ricoh USA, Inc.
Incidents

No Incident

FAQ

Ricoh USA, Inc. company demonstrates a stronger AI Cybersecurity Score compared to Change Healthcare company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Change Healthcare company has historically faced a number of disclosed cyber incidents, whereas Ricoh USA, Inc. company has not reported any.

In the current year, Change Healthcare company has reported more cyber incidents than Ricoh USA, Inc. company.

Change Healthcare company has confirmed experiencing a ransomware attack, while Ricoh USA, Inc. company has not reported such incidents publicly.

Change Healthcare company has disclosed at least one data breach, while the other Ricoh USA, Inc. company has not reported such incidents publicly.

Change Healthcare company has reported targeted cyberattacks, while Ricoh USA, Inc. company has not reported such incidents publicly.

Neither Change Healthcare company nor Ricoh USA, Inc. company has reported experiencing or disclosing vulnerabilities publicly.

Neither Change Healthcare nor Ricoh USA, Inc. holds any compliance certifications.

Neither company holds any compliance certifications.

Ricoh USA, Inc. company has more subsidiaries worldwide compared to Change Healthcare company.

Ricoh USA, Inc. company employs more people globally than Change Healthcare company, reflecting its scale as a IT Services and IT Consulting.

Neither Change Healthcare nor Ricoh USA, Inc. holds SOC 2 Type 1 certification.

Neither Change Healthcare nor Ricoh USA, Inc. holds SOC 2 Type 2 certification.

Neither Change Healthcare nor Ricoh USA, Inc. holds ISO 27001 certification.

Neither Change Healthcare nor Ricoh USA, Inc. holds PCI DSS certification.

Neither Change Healthcare nor Ricoh USA, Inc. holds HIPAA certification.

Neither Change Healthcare nor Ricoh USA, Inc. holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

Risk Information
cvss4
Base: 8.8
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

Risk Information
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

Risk Information
cvss3
Base: 5.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Description

File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Risk Information
cvss3
Base: 6.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L