Geisinger A.I CyberSecurity Scoring
Geisinger
Company Information
Website:https://www.geisinger.org/
Employees number:15,511
Number of followers:84,447
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:geisinger.org
Geisinger Risk Score (AI oriented)
Between 0 and 549
GeisingerHospitals and Health Care
Updated:
01/04/2026
01/04/2026
450/1000
Critical
C
Geisinger Global Score (TPRM)
xxxx
GeisingerHospitals and Health Care
Score locked

GeisingerCritical
Current Score
450C (CRITICAL)
01000
7 incidents
-61.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
465
MAY 2026
460
APRIL 2026
456
MARCH 2026
446
FEBRUARY 2026
544
Breach
03 Feb 2026 • Geisinger
Microsoft, Nuance Communications and Geisinger Health System: Man accused in 2023 Geisinger data breach case faces more charges
Former Nuance Engineer Charged in 2023 Geisinger Health Data Breach Affecting 1.3 Million Patients
438
CRITICAL-106
GEINUAMIC1770196655
Former Nuance Engineer Charged in 2023 Geisinger Health Data Breach Affecting 1.3 Million Patients
A California man, Max Vance (formerly Andre Burk), faces additional charges in connection with the 2023 data breach of Geisinger Health System, which exposed the personal and medical records of over 1.3 million patients. A superseding indictment filed in the U.S. Middle District Court on Tuesday accuses Vance of making false statements to FBI agents in January 2024, denying he had downloaded unauthorized data onto personal devices.
Vance, a former principal healthcare interface engineer at Nuance Communications a Microsoft subsidiary providing IT services to hospitals was initially indicted in January 2024 for unauthorized access to a protected computer. Authorities allege that after being fired by Microsoft on November 27, 2023, for unrelated misconduct, Vance used his Nuance credentials to query Geisinger’s servers two days later. He extracted sensitive patient data, including names, dates of birth, addresses, medical record numbers, and treatment details, downloading it into two files before uploading them to his Microsoft Azure cloud account. The files were later transferred to his personal laptop and a Samsung hard drive, with evidence recovered during a search of his El Cajon apartment.
Geisinger detected the breach on November 29, 2023, but delayed notifying affected patients until June 24, 2024, citing the need to avoid interfering with a federal investigation. The breach has since led to multiple civil lawsuits, including a class-action suit with preliminary approval of a $5 million settlement covering 1,308,363 individuals. Plaintiffs argue the delayed notification increased risks of identity theft.
Vance, who legally changed his name in 2021 and relocated to California in 2022, is currently detained at Lycoming County Prison in Pennsylvania. Representing himself, he has filed motions challenging his detention and evidence admissibility. The case remains under federal investigation.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
539
DECEMBER 2025
535
NOVEMBER 2025
610
OCTOBER 2025
529
SEPTEMBER 2025
524
AUGUST 2025
519
JULY 2025
514
JUNE 2025
524
Cyber Attack
19 Jun 2025 • Geisinger
Geisinger: Ryuk ransomware’s initial access expert extradited to the U.S. from Ukraine
Ryuk Ransomware Initial Access Broker Extradited to U.S.
507
CRITICAL-17
GEI1767779516
Ryuk Ransomware Affiliate Extradited to U.S. After Global Cyberattacks
In a coordinated international operation, a 33-year-old man linked to the Ryuk ransomware group was extradited to the U.S. from Ukraine on June 18, 2025. The suspect, arrested in Kyiv in April at the FBI’s request, specialized in gaining initial access to corporate networks and is accused of participating in attacks targeting companies across France, Norway, Germany, the Netherlands, Canada, and the U.S.
Ukrainian cyber police, alongside the National Police and global law enforcement partners, launched the investigation in 2023 following a wave of ransomware incidents tied to the group. The extradition marks a significant step in disrupting Ryuk’s operations, which have long been associated with high-profile cyber extortion campaigns.
The case underscores the persistent threat of ransomware gangs and the growing collaboration between nations to counter cybercrime. No further details on the suspect’s identity or the specific companies affected have been disclosed.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
JUNE 2024
567
Breach
28 Jun 2024 • Geisinger
Geisinger Health and Nuance Communications: Stolen data complaint against Geisinger Health, Nuance Communications settled for $5M
$5 Million Settlement Approved in Geisinger-Nuance Medical Data Breach Affecting 1.3 Million Patients
461
CRITICAL-106
NUAGEI1773772921
$5 Million Settlement Approved in Geisinger-Nuance Medical Data Breach Affecting 1.3 Million Patients
A Pennsylvania judge has approved a $5 million settlement resolving a class-action lawsuit against Geisinger Health and Nuance Communications following the theft of 1.3 million patient records by a former Nuance employee. The breach, which exposed sensitive data including names, birthdates, addresses, medical record numbers, treatment details, and insurance information stemmed from Geisinger’s partnership with Nuance, a Microsoft subsidiary specializing in AI-driven clinical documentation tools.
The lawsuit was filed on June 28, 2024, with the settlement finalized earlier this month. While the agreement does not require either company to admit wrongdoing, it includes $30,000 in additional payments to cover litigation costs and awards for the five plaintiffs who initiated the case. Victims have until March 18 to file claims, though the exact payout per individual will depend on how many of the 1.3 million affected patients participate.
As of March 5, only 97,000 victims had registered for direct cash compensation. Affected individuals may also opt for complimentary credit monitoring, though participation in the settlement class is required to access the benefit. Notably, there is no evidence that the stolen data has surfaced on the dark web or been misused.
Geisinger, a nonprofit health system serving 45 Pennsylvania counties, operates 10 hospitals and 126 care sites, treating over 3 million patients annually. The breach highlights ongoing risks in third-party data handling within the healthcare sector.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2023
644
Breach
29 Nov 2023 • Geisinger
Geisinger Health
Geisinger Health and Nuance Communications Patient Data Breach (2023)
537
CRITICAL-107
GEI5102451112125
A former employee of Nuance Communications (a Microsoft-owned IT services vendor) accessed Geisinger Health’s patient records without authorization two days after their employment termination on November 29, 2023. The breach exposed the personal and health information of over 1.3 million patients, including full names, dates of birth, addresses, medical record numbers, race, gender, phone numbers, facility abbreviations, Social Security numbers (SSNs), and health insurance details. Initially, Geisinger stated no financial or credit card data was compromised, but court documents later confirmed SSNs and sensitive medical information were exposed. The incident led to a $5 million class-action settlement, with affected patients eligible to file claims until March 2026. The former employee faces federal criminal charges for the unauthorized access, which occurred after law enforcement concluded its investigation. The breach severely undermined patient trust and triggered legal, financial, and reputational repercussions for Geisinger Health.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2023
735
Breach
16 Jun 2023 • Geisinger
Geisinger Health
Geisinger Health and Nuance Communications Data Breach (2023)
629
CRITICAL-106
GEI4702447112225
A Pennsylvania district court approved a $5 million settlement for a 2023 data breach at Geisinger Health, involving a former Nuance Communications employee (Nuance is now owned by Microsoft). The breach exposed over 1 million patients' sensitive data, including names, dates of birth, addresses, medical record numbers, race, gender, phone numbers, admit/discharge codes, and facility abbreviations. The employee, terminated just two days before the incident, accessed and potentially exfiltrated the data, leading to criminal charges and an ongoing federal investigation. Notification to affected patients was delayed per law enforcement’s request. The breach underscored insider threat risks in healthcare, with the consolidated class-action lawsuit highlighting reputational, financial, and legal repercussions. The final approval hearing is set for March 2026, with claims submissions due shortly after.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2020
751
Breach
01 Jun 2020 • Geisinger
Geisinger
Geisinger Data Breach by Former Employee
694
CRITICAL-57
GEI21525422
Geisinger was targeted in a data breach incident by a former employee in a non-permitted manner.
The breach compromised the medical records and other personal information including patient names, date of birth, and other details of over 700 patients.
The company immediately took strict actions and fired the employee and informed the affected patients to be alerted.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2016
783
Breach
01 Aug 2016 • Geisinger
Geisinger
Geisinger Data Breach
716
MEDIUM-67
GEI185214622
Geisinger was targeted in a data breach incident that exposed 2,800 members and 220 employers Protected Health Information (PHI) in an unauthorized manner.
Members of Geisinger Gold, GHP Family, or GHP Kids were unaffected by this incident.
The attack compromised member name, date of birth, health insurance premium information, member identification number and smoking status.
No medical treatment or financial information, such as social security number, was included.
The company immediately took strict actions and informed the affected patients and employee to be alerted.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Geisinger ??
What was Geisinger's A.I Rankiteo Cyber Score in May 2026 ??
What was Geisinger's A.I Rankiteo Cyber Score in April 2026 ??
What was Geisinger's A.I Rankiteo Cyber Score in March 2026 ??
What was Geisinger's A.I Rankiteo Cyber Score in February 2026 ??
What was Geisinger's A.I Rankiteo Cyber Score in January 2026 ??
What was Geisinger's A.I Rankiteo Cyber Score in December 2025 ??
What was Geisinger's A.I Rankiteo Cyber Score in November 2025 ??
What was Geisinger's A.I Rankiteo Cyber Score in October 2025 ??
What was Geisinger's A.I Rankiteo Cyber Score in September 2025 ??
What was Geisinger's A.I Rankiteo Cyber Score in August 2025 ??
What was Geisinger's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Geisinger's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Geisinger ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Geisinger's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?