Company Details
healthtechwb
22
2,373
8135
htwb.org
0
HEA_2112661
In-progress

Health Tech Without Borders Company CyberSecurity Posture
htwb.orgHealth Tech Without Borders is a global non-profit organization that supports local communities affected by sudden humanitarian emergencies. Health Tech Without Borders acts as an innovative hub that connects companies offering digital tools with experts in medical and psychological care. As a result, the global non-profit organization provides digital health interventions, such as online consultations, remote monitoring, and digital therapeutics. Organization connects qualified and vetted volunteer clinicians to those wounded by humanitarian disasters, war, or assault, and all human beings in need of medical attention. Additionally, Health Tech Without Borders offers online trainings for clinicians in crisis areas in medical and mental health challenges, as well as vetted digital health tools. Health Tech Without Borders was founded in 2022, and is working with corporations, universities, governing agencies, and other institutions around the globe to bring help, hope, and healthcare efficiently to local communities affected by crisis. Health Tech Without Borders focuses on supporting any person affected by humanitarian disasters while remaining non-sectarian and apolitical. Since our inception, we helped more than 65.000 patients in regions of crisis to seek medical and psychological support and facilitated targeted training for more than 2.000 clinicians.
Company Details
healthtechwb
22
2,373
8135
htwb.org
0
HEA_2112661
In-progress
Between 650 and 699

HTWB Global Score (TPRM)XXXX

Description: The Yap Department of Health Services in Micronesia suffered a significant ransomware attack on March 11, 2025, compromising the health system network and necessitating a complete shutdown of all computers. This disruption resulted in slower delivery of healthcare services as digital systems and internet connectivity were offline to prevent further damage. The impact of the attack led to a reduction in operational efficiency and could potentially have affected patient care, as the reliance on technology for health services is critical. The attack required intervention from both government bodies and private IT contractors to assess the damage and facilitate the recovery of services.


Health Tech Without Borders has 36.99% more incidents than the average of same-industry companies with at least one recorded incident.
Health Tech Without Borders has 53.85% more incidents than the average of all companies with at least one recorded incident.
Health Tech Without Borders reported 1 incidents this year: 0 cyber attacks, 1 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.
HTWB cyber incidents detection timeline including parent company and subsidiaries

Health Tech Without Borders is a global non-profit organization that supports local communities affected by sudden humanitarian emergencies. Health Tech Without Borders acts as an innovative hub that connects companies offering digital tools with experts in medical and psychological care. As a result, the global non-profit organization provides digital health interventions, such as online consultations, remote monitoring, and digital therapeutics. Organization connects qualified and vetted volunteer clinicians to those wounded by humanitarian disasters, war, or assault, and all human beings in need of medical attention. Additionally, Health Tech Without Borders offers online trainings for clinicians in crisis areas in medical and mental health challenges, as well as vetted digital health tools. Health Tech Without Borders was founded in 2022, and is working with corporations, universities, governing agencies, and other institutions around the globe to bring help, hope, and healthcare efficiently to local communities affected by crisis. Health Tech Without Borders focuses on supporting any person affected by humanitarian disasters while remaining non-sectarian and apolitical. Since our inception, we helped more than 65.000 patients in regions of crisis to seek medical and psychological support and facilitated targeted training for more than 2.000 clinicians.


Every day, we help millions of people to make journeys across London: By Tube, bus, tram, car, bike – and more. People don’t associate us with journeys by river, on foot or via the air, but we help with that, too. Getting people to where they need to go has been our business for over 100 years, and

UNICEF works in some of the world’s toughest places, to reach the world’s most disadvantaged children. To save their lives. To defend their rights. To help them fulfill their potential. Across 190 countries and territories, we work for every child, everywhere, every day, to build a better world fo
The Salvation Army is the nation's largest direct provider of social services. Annually, we help millions overcome poverty, addiction, and spiritual and economic hardships by preaching the gospel of Jesus Christ and meeting human needs in His name without discrimination in nearly every zip code.

TED’s mission is to discover and champion the ideas that will shape tomorrow. Powerful ideas, powerfully presented, can move us to feel something, to think differently, to take action and create a brighter future. TED finds these powerful ideas across disciplines and around the globe, from people w

World Vision is the largest child-focused private charity in the world. Our 33,000+ staff members working in nearly 100 countries have united with our incredible supporters to impact the lives of over 200 million vulnerable children by tackling the root causes of poverty. Through World Vision every

Médecins Sans Frontières (MSF) is an international, independent, medical humanitarian organisation working to provide medical assistance to people affected by conflict, epidemics, disasters, or exclusion from healthcare. Since our founding in 1971, we’ve grown to a global movement delivering human

Save the Children Save the Children is the world's leading independent organisation for children. We work in around 120 countries. Our vision is to live in a world in which every child attains the right to survival, protection, development and participation. Last year Save the Children's prog

YMCA of the USA is the national resource office for the nation's YMCAs. Located in Chicago, IL, YMCA of the USA exists to serve YMCAs. To address the specific needs of communities, each YMCA is an independent organization, autonomous and separate from YMCA of the USA. They are required by the nation

Colsubsidio es una organización privada sin ánimo de lucro, que pertenece al Sistema de Protección y Seguridad Social, su evolución ha estado marcada tanto por el reconocimiento de las personas como seres integrales con necesidades dinámicas, múltiples e interdependientes, como por las transformacio
.png)
As we enter 2026, global cybersecurity risk and laws are rapidly expanding. Geopolitical tensions, technological advancements, and evolving...
The HIPAA training requirements are that “a covered entity must train all members of its workforce on policies and procedures […]
A lawsuit filed by Nebraska Attorney General Mike Hilgers over the 2024 Change Healthcare data breach has been allowed to proceed after...
The White & Case Tech Newsflash provides updates on the latest issues and trends in technology and the law. We deliver fresh perspectives across all of our...
BOSTON, September 12, 2025--Health Tech Without Borders (HTWB), Inc., an international, 501c3, non‑profit devoted to expanding access to...
The aviation sector is the bedrock of worldwide connectivity. Aviation: Benefits Beyond Borders reports that the industry is responsible for...
As geopolitical tensions increasingly spill into cyberspace, a growing number of cybersecurity professionals are beginning to look beyond...
New HIPAA regulations may be implemented in 2025, such as the proposed update to the HIPAA Privacy Rule, a final rule for which is long overdue.
We discuss all the HIPAA updates since the inception of HIPAA in this article and this information can be used in conjunction with our HIPAA checklist.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Health Tech Without Borders is https://www.htwb.org/.
According to Rankiteo, Health Tech Without Borders’s AI-generated cybersecurity score is 670, reflecting their Weak security posture.
According to Rankiteo, Health Tech Without Borders currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Health Tech Without Borders is not certified under SOC 2 Type 1.
According to Rankiteo, Health Tech Without Borders does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Health Tech Without Borders is not listed as GDPR compliant.
According to Rankiteo, Health Tech Without Borders does not currently maintain PCI DSS compliance.
According to Rankiteo, Health Tech Without Borders is not compliant with HIPAA regulations.
According to Rankiteo,Health Tech Without Borders is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Health Tech Without Borders operates primarily in the Non-profit Organizations industry.
Health Tech Without Borders employs approximately 22 people worldwide.
Health Tech Without Borders presently has no subsidiaries across any sectors.
Health Tech Without Borders’s official LinkedIn profile has approximately 2,373 followers.
Health Tech Without Borders is classified under the NAICS code 8135, which corresponds to Others.
No, Health Tech Without Borders does not have a profile on Crunchbase.
Yes, Health Tech Without Borders maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/healthtechwb.
As of December 11, 2025, Rankiteo reports that Health Tech Without Borders has experienced 1 cybersecurity incidents.
Health Tech Without Borders has an estimated 20,886 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.
Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with private it contractors, and containment measures with shutdown of all computers, and recovery measures with intervention from government bodies and private it contractors..
Title: Ransomware Attack on Yap Department of Health Services
Description: The Yap Department of Health Services in Micronesia suffered a significant ransomware attack on March 11, 2025, compromising the health system network and necessitating a complete shutdown of all computers. This disruption resulted in slower delivery of healthcare services as digital systems and internet connectivity were offline to prevent further damage. The impact of the attack led to a reduction in operational efficiency and could potentially have affected patient care, as the reliance on technology for health services is critical. The attack required intervention from both government bodies and private IT contractors to assess the damage and facilitate the recovery of services.
Date Detected: 2025-03-11
Type: Ransomware
Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Systems Affected: health system networkall computers
Downtime: slower delivery of healthcare services
Operational Impact: reduction in operational efficiency

Entity Name: Yap Department of Health Services
Entity Type: Government
Industry: Healthcare
Location: Micronesia

Third Party Assistance: Private It Contractors.
Containment Measures: shutdown of all computers
Recovery Measures: intervention from government bodies and private IT contractors
Third-Party Assistance: The company involves third-party assistance in incident response through private IT contractors, .
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by shutdown of all computers.
Data Recovery from Ransomware: The company recovers data encrypted by ransomware through intervention from government bodies and private IT contractors.
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Private It Contractors, .
Most Recent Incident Detected: The most recent incident detected was on 2025-03-11.
Most Significant System Affected: The most significant system affected in an incident was health system networkall computers.
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was private it contractors, .
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was shutdown of all computers.
.png)
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain a Stored Cross-Site Scripting (XSS) vulnerability in the /WeGIA/html/geral/configurar_senhas.php endpoint. The application does not sanitize user-controlled data before rendering it inside the employee selection dropdown. The application retrieves employee names from the database and injects them directly into HTML <option> elements without proper escaping. This issue is fixed in version 3.5.5.
ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XSS through the Zitadel V2 logout endpoint. The /logout endpoint insecurely routes to a value that is supplied in the post_logout_redirect GET parameter. As a result, unauthenticated remote attacker can execute malicious JS code on Zitadel users’ browsers. To carry out an attack, multiple user sessions need to be active in the same browser, however, account takeover is mitigated when using Multi-Factor Authentication (MFA) or Passwordless authentication. This issue is fixed in version 4.7.1.
ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including self-hosted instances. This allows an unauthenticated attacker to force the server to make HTTP requests to arbitrary domains, such as internal addresses, and read the responses, enabling data exfiltration and bypassing network-segmentation controls. This issue is fixed in version 4.7.1.
NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue is fixed in version 3.4.0.
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.