Comparison Overview
HCA Healthcare Physician Services

HCA Healthcare Physician Services
2000 Health Park Dr, Brentwood, Tennessee, US, 37027
Last Update: 12/03/2026
HCA Healthcare Physician Services is the expert in physician employment, practice and urgent care operations, hospitalist integration and more. In addition to managing more than 1,500 physician practices and 330+ urgent care centers, Physician Services is HCA Healthcare...

The Cigna Group
900 Cottage Grove Rd, Bloomfield, 06002, US
Last Update: 02/04/2026
The Cigna Group is a global health company committed to creating a better future built on the vitality of every individual and every community. We relentlessly challenge ourselves to partner and innovate solutions for better health. The Cigna Group includes products a...
Compliance Ranges Comparison

HCA Healthcare Physician Services







The Cigna Group






Benchmark & Cyber Underwriting Signals
Incidents vs Hospitals and Health Care Industry Avg (This Year)
No incidents recorded for HCA Healthcare Physician Services in 2026.
Incidents vs Hospitals and Health Care Industry Avg (This Year)
No incidents recorded for The Cigna Group in 2026.
Incident History - HCA Healthcare Physician Services (X = Date, Y = Severity)
HCA Healthcare Physician Services cyber incidents detection timeline including parent company and subsidiaries.
Incident History - The Cigna Group (X = Date, Y = Severity)
The Cigna Group cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

HCA Healthcare Physician Services

The Cigna Group
FAQ
Latest Global CVEs
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).