Comparison Overview
Covenant Health

Covenant Health
100 Fort Sanders West Blvd, Knoxville, TN, US, 37922
Last Update: 03/04/2026
Covenant Health is a not-for-profit, locally owned integrated healthcare enterprise with a mission to improve the quality of life in our communities through better health. Covenant Health serves a 25-county region of Tennessee and has more than 2 million patient encount...

Provincial Health Services Authority
200-1333 West Broadway, Vancouver, V6H 4C1, CA
Last Update: 30/03/2026
Canada's first provincial health services authority. Provincial Health Services Authority (PHSA) is one of six health authorities – the other five health authorities serve geographic regions of BC. PHSA's primary role is to ensure that BC residents have access to a coo...
Compliance Ranges Comparison

Covenant Health







Provincial Health Services Authority






Benchmark & Cyber Underwriting Signals
Incidents vs Hospitals and Health Care Industry Avg (This Year)
Covenant Health has 28.06% fewer incidents than the average of same-industry companies with at least one recorded incident.
Incidents vs Hospitals and Health Care Industry Avg (This Year)
No incidents recorded for Provincial Health Services Authority in 2026.
Incident History - Covenant Health (X = Date, Y = Severity)
Covenant Health cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Provincial Health Services Authority (X = Date, Y = Severity)
Provincial Health Services Authority cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Covenant Health

Provincial Health Services Authority
FAQ
Latest Global CVEs
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs ACL-file protection and block-list checks. This issue is fixed in version 2.1.5.
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler split part.FileName() on / but did not reject .., allowing an unauthenticated upload with filename .. to create a file outside the served tree. This issue is fixed in version 2.1.5.
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with Overwrite: T. This issue is fixed in version 2.1.4.
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access. This issue is fixed in version 2.1.4.
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\r\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.