Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
CVS Health

CVS Health Vendor Cyber Rating & Cyber Score

CVSHealth.com

CVS Health is the leading health solutions company, delivering care like no one else can. We reach more people and improve the health of communities across America through our local presence, digital channels and over 300,000 dedicated colleagues. Wherever and whenever people need us, we help them with their health – whether that’s managing chronic diseases, staying compliant with their medications or accessing affordable health and wellness services in the most convenient ways. We help people navigate the health care system – and their personal health care – by simplifying health care one person, one family and one community at a time. Follow @CVSHealth on social media.


CVS Health A.I CyberSecurity Scoring

CVS Health
Company Information
Website:http://CVSHealth.com
Employees number:137,169
Number of followers:1,206,072
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:CVSHealth.com
CVS Health Risk Score (AI oriented)
Between 650 and 699
logo
CVS HealthHospitals and Health Care
Updated:
19/05/2026
683/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CVS Health Global Score (TPRM)
xxxx
logo
CVS HealthHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CVS Health
CVS HealthWeak
Current Score
683B (WEAK)
01000
3 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
685Before Incident
MAY 2026
681Before Incident
APRIL 2026
680Before Incident
MARCH 2026
674Before Incident
FEBRUARY 2026
673Before Incident
JANUARY 2026
671Before Incident
DECEMBER 2025
668Before Incident
NOVEMBER 2025
665Before Incident
OCTOBER 2025
662Before Incident
SEPTEMBER 2025
659Before Incident
AUGUST 2025
656Before Incident
JULY 2025
653Before Incident
FEBRUARY 2024
770Before Incident
Ransomware
01 Feb 2024CVS Health
Change Healthcare (UnitedHealth Group)

Ransomware Attacks Overview (2011–2025)

585After Incident
CRITICAL-185
CHA455090325
In February 2024, Change Healthcare, a critical division of UnitedHealth Group, fell victim to a devastating BlackCat/ALPHV ransomware attack. The assault crippled its systems, disrupting prescription processing, medical claims, and payment operations across the U.S. healthcare sector. Over 100 million individuals were impacted due to service outages, with hospitals, pharmacies, and insurers facing delays in billing, reimbursements, and patient care. The company paid a $22 million ransom, but total financial losses ballooned to an estimated $2 billion, factoring in operational downtime, recovery costs, and reputational damage. The attack exposed vulnerabilities in third-party supply chains, as the breach originated from compromised credentials in a connected vendor system. Regulatory scrutiny intensified, with federal investigations probing compliance failures under HIPAA and cybersecurity negligence. The incident underscored the escalating threat of RaaS (Ransomware-as-a-Service) models, where affiliate hackers leverage sophisticated tools to target high-value sectors like healthcare, exploiting systemic interdependencies for maximum disruption.
INCIDENT DETAILS -
TYPE
ransomwaredata breachsupply chain attackphishingtriple extortion
MOTIVATION
financial gain (ransom payments, data extortion)disruption of critical infrastructure (e.g., healthcare, supply chains)data theft for dark web sales (e.g., PII, medical records)espionage (e.g., state-linked DanaBot attacks)reputation damage (e.g., leaking sensitive data)
IMPACT
$4B (WannaCry, 2017)$18M (Baltimore, 2019)$50M–$70M (Cognizant, 2020)$4.4M (Colonial Pipeline) + $11M (JBS, 2021)$1.1B (MOVEit breaches, 2023)$22M ransom + $2B losses (Change Healthcare, 2024)$25M (CDK Global, 2024)$160M (CommonSpirit Health, 2022)$300M (Marks & Spencer, 2024–2025)$4B (Sensata Technologies, 2025)Average ransom payment: $2.73M (2024, up from $1.5M in 2023)Average cost per attack: $5.13M (2025, +574% since 2019)93.3M individuals (MOVEit, 2023)9.7M medical records (Medibank, 2022)5.6M patient records (Healthcorps, 2024)726K customers (Patelco Credit Union, 2024)254K users (Kadokawa/Niconico, 2024)500GB (Spanish Tax Agency, 2024)1TB (Nvidia, 2022)190GB (Samsung, 2022)65GB (British Library, University of Hawaii, 2023)PII, payment info, medical records, corporate secrets (e.g., Apple blueprints via Quanta, 2021)300K+ computers (WannaCry, 150+ countries, 2017)650 servers + 150 apps (Sky Lakes Medical Center, 2021)800 servers (Costa Rica government, 2022)10TB data (Canon, 2020)740GB (Toshiba, 2021)1.4M patient records (Lubbock County, 2019)Port of Nagoya (10% of Japan’s trade disrupted, 2023)thousands of dealerships (CDK Global, 2024)US fuel supply (Colonial Pipeline, 2021)US meat supply (JBS, 2021)1 month (Baltimore, 2019)7 months (Sky Lakes Medical Center, 2021)prolonged disruptions (Change Healthcare, CDK Global, 2024)manual processes (University Hospital Center Zagreb, 2024)fuel shortages (Colonial Pipeline, 2021)meat supply disruption (JBS, 2021)healthcare service outages (CommonSpirit, Change Healthcare)auto sales halted (CDK Global, 2024)container operations destroyed (Port of Nagoya, 2023)online retail disruptions (Marks & Spencer, 2024–2025)government crises (Costa Rica, 2022)$2B (Change Healthcare, 2024)$300M (Marks & Spencer, 2024–2025)$160M (CommonSpirit Health, 2022)stock price drops (e.g., Carnival Corp, 2020)market cap drop of £1B (Marks & Spencer, 2025)leaked sensitive data (e.g., Washington DC Police, British Library)loss of trust in healthcare (e.g., Medibank, Healthcorps)publicized breaches (e.g., Christie’s, 2025)fines for regulatory violations (e.g., GDPR, HIPAA)lawsuits from affected customers (e.g., patients, credit union members)SEC disclosures (e.g., Sensata Technologies, 2025)9.7M medical records (Medibank, 2022)5.6M patient records (Healthcorps, 2024)726K customers (Patelco Credit Union, 2024)500K clients (Christie’s, 2025)credit card data (e.g., Patelco Credit Union, 2024)financial records (e.g., Spanish Tax Agency, 2024)cryptocurrency theft (e.g., CoinDash, 2017)
DATA BREACH
PII (e.g., Medibank, Patelco Credit Union)medical records (e.g., CommonSpirit, Healthcorps)payment information (e.g., Spanish Tax Agency)corporate secrets (e.g., Apple blueprints via Quanta)government data (e.g., Washington DC Police, Costa Rica)student/employee data (e.g., Munster Technological University)customer data (e.g., Christie’s, Marks & Spencer)93.3M (MOVEit, 2023)9.7M (Medibank, 2022)5.6M (Healthcorps, 2024)726K (Patelco Credit Union, 2024)254K (Kadokawa/Niconico, 2024)500K (Christie’s, 2025)1.4M (Lubbock County, 2019)70K (Nvidia, 2022)high (PII, medical, financial, corporate secrets)MOVEit (Clop gang, 2023)BlackCat/ALPHV (Change Healthcare, 2024)REvil (JBS, Kaseya, 2021)Lapsus$ (Nvidia, Samsung, 2022)Babuk (Washington DC Police, 2021)Rhysida (British Library, 2023)WannaCry (2017, 300K+ computers)Colonial Pipeline (2021)CDK Global (2024)Change Healthcare (2024)Port of Nagoya (2023)databases (e.g., patient records, customer data)documents (e.g., corporate secrets, legal files)emails (e.g., phishing lures, credentials)source code (e.g., Samsung, Nvidia)financial records (e.g., Spanish Tax Agency)names, addresses, SSNs (e.g., Patelco Credit Union)medical histories (e.g., Medibank, Healthcorps)payment card data (e.g., retail breaches)biometric data (e.g., healthcare breaches)
JANUARY 2023
793Before Incident
Breach
01 Jan 2023CVS Health
CVS

CVS Data Breach

756After Incident
LOW-37
CVS910072525
On April 8, 2024, the Maine Office of the Attorney General reported a data breach involving CVS that occurred on January 1, 2023. The breach was an internal system breach affecting a total of 10 individuals, with consumer notification conducted electronically on January 10, 2023. Identity theft protection services were offered.
INCIDENT DETAILS -
TYPE
Data Breach
MARCH 2021
823Before Incident
Breach
01 Mar 2021CVS Health
CVS Health

CVS Data Leak Incident

780After Incident
CRITICAL-43
CVS153930322
Over a billion customer records of Pharmacy giant CVS were leaked on internet in a cyber incident. The exposed data included customer email addresses, device IDs, and the order histories of CVS. Upon learning about the incident CVS Health immediately worked to secure the data and informed the impacted customers to remain alert.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
customer email addressesdevice IDsorder histories
DATA BREACH
customer email addressesdevice IDsorder historiesNumber Of Records Exposed: Over a billion

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CVS Health ?
?
What was CVS Health's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CVS Health's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CVS Health's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CVS Health's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CVS Health's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CVS Health's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CVS Health's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CVS Health's A.I Rankiteo Cyber Score in October 2025 ?
?
What was CVS Health's A.I Rankiteo Cyber Score in September 2025 ?
?
What was CVS Health's A.I Rankiteo Cyber Score in August 2025 ?
?
What was CVS Health's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on CVS Health's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CVS Health ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CVS Health's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?