Company Details
henry-ford-health
20,343
121,801
62
henryford.com
4
HEN_2535154
Completed

Henry Ford Health Company CyberSecurity Posture
henryford.com*Job seekers: please be aware of fraudulent job postings and phishing scams via LinkedIn. Henry Ford Health only contacts applicants through our human resources department and via a corporate email address. Here are some tips to be aware of: http://ow.ly/Kc0o50EKory Serving communities across Michigan and beyond, Henry Ford Health is committed to partnering with patients & members along their entire health journey. Henry Ford Health provides a full continuum of services – from primary and preventative care, to complex and specialty care, health insurance, a full suite of home health offerings, virtual care, pharmacy, eye care & other healthcare retail. It is one of the nation’s leading academic medical centers, recognized for clinical excellence in cancer care, cardiology and cardiovascular surgery, neurology and neurosurgery, orthopedics and sports medicine, and multi-organ transplants. Consistently ranked among the top five NIH-funded institutions in Michigan, Henry Ford Health engages in thousands of research projects annually. Equally committed to educating the next generation of health professionals, Henry Ford Health trains more than 4,000 medical students, residents and fellows every year across 50+ accredited programs. With more than 50,000 valued team members, Henry Ford Health is also among Michigan’s largest and most diverse employers. President and CEO Bob Riney leads the health system and serves a growing number of customers across more than 550 sites across Michigan. That includes: 13 acute care hospitals; 3 behavioral health facilities including two world-class addiction treatment centers; a state-of-the-art orthopedics and sports medicine facility; multiple cancer care destinations including the Brigitte Harris Cancer Pavilion, Henry Ford Health’s premier location in Detroit; & more options than ever for primary care for patients and families across the region.
Company Details
henry-ford-health
20,343
121,801
62
henryford.com
4
HEN_2535154
Completed
Between 750 and 799

HFH Global Score (TPRM)XXXX

Description: Henry Ford Health System has compromised patient information after an employee lost a flash drive with information on 2,777 patients. The drive stored information including names, medical record numbers, test information and results. Henry Ford officials said no Social Security numbers or health insurance identification numbers.
Description: Henry Ford Health System has compromised patient information after a system got hacked that exposed 18,500 patients' personal information. The compromised information included the patient's name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, and health insurer. Neither Social Security numbers nor credit card information was revealed. People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked.


No incidents recorded for Henry Ford Health in 2025.
No incidents recorded for Henry Ford Health in 2025.
No incidents recorded for Henry Ford Health in 2025.
HFH cyber incidents detection timeline including parent company and subsidiaries

*Job seekers: please be aware of fraudulent job postings and phishing scams via LinkedIn. Henry Ford Health only contacts applicants through our human resources department and via a corporate email address. Here are some tips to be aware of: http://ow.ly/Kc0o50EKory Serving communities across Michigan and beyond, Henry Ford Health is committed to partnering with patients & members along their entire health journey. Henry Ford Health provides a full continuum of services – from primary and preventative care, to complex and specialty care, health insurance, a full suite of home health offerings, virtual care, pharmacy, eye care & other healthcare retail. It is one of the nation’s leading academic medical centers, recognized for clinical excellence in cancer care, cardiology and cardiovascular surgery, neurology and neurosurgery, orthopedics and sports medicine, and multi-organ transplants. Consistently ranked among the top five NIH-funded institutions in Michigan, Henry Ford Health engages in thousands of research projects annually. Equally committed to educating the next generation of health professionals, Henry Ford Health trains more than 4,000 medical students, residents and fellows every year across 50+ accredited programs. With more than 50,000 valued team members, Henry Ford Health is also among Michigan’s largest and most diverse employers. President and CEO Bob Riney leads the health system and serves a growing number of customers across more than 550 sites across Michigan. That includes: 13 acute care hospitals; 3 behavioral health facilities including two world-class addiction treatment centers; a state-of-the-art orthopedics and sports medicine facility; multiple cancer care destinations including the Brigitte Harris Cancer Pavilion, Henry Ford Health’s premier location in Detroit; & more options than ever for primary care for patients and families across the region.


Sentara Health, an integrated, not-for-profit health care delivery system, celebrates more than 135 years in pursuit of its mission - "we improve health every day." Sentara is one of the largest health systems in the U.S. Mid-Atlantic and Southeast, and among the top 20 largest not-for-profit integr

Penn Medicine’s mission is to advance knowledge and improve health through research, patient care, and the education of trainees in an inclusive culture that embraces diversity, fosters innovation, stimulates critical thinking, supports lifelong learning, and sustains our legacy of excellence. Penn

A world-leading integrated healthcare provider, IHH believes that making a difference starts with our aspiration to Care. For Good. Our team of 65,000 people commit to deliver greater good to our patients, people, the public and our planet, as we live our purpose each day to touch lives and trans

Be at the heart of exceptional care. Team MHS Florida is an award-winning group of friends and colleagues at one of the largest not-for-profit health systems in the nation. We're 17,000 strong, advancing towards a brighter future together. We're passionate about the work we do, delivering deep, pe

BrightSpring is the parent company of a family of services and brands that provides clinical, nonclinical, pharmacy and ancillary care services for people of all ages, health and skill levels across home and community settings. The company is a leading provider of diversified home and community-ba

We provide quality, compassionate health care at more than 40 hospitals and care centers that are serving communities across California, Arizona and Nevada every minute of every day. And while not everyone may live near a major medical facility, Dignity Health is making health care more accessible b
Guided by the needs of our patients and their families, Massachusetts General Hospital aims to deliver the very best health care in a safe, compassionate environment; to advance that care through innovative research and education; and, to improve the health and well-being of the diverse communitie

Com cerca de 80 anos de experiência, a Hapvida é hoje a maior empresa de saúde integrada da América Latina. A companhia, que possui mais de 69 mil colaboradores, atende quase 16 milhões de beneficiários de saúde e odontologia espalhados pelas cinco regiões do Brasil. Todo o aparato foi construído a

Welcome to the official LinkedIn page for McKesson Corporation. We're an impact-driven healthcare organization dedicated to “Advancing Health Outcomes For All.” As a global healthcare company, we touch virtually every aspect of health. Our leaders empower our people to lead with a growth mindset an
.png)
In west Michigan, nurses are using an app to redirect nonmedical work to other workers. In Jackson, some nurses are working virtually.
BioCardia (NASDAQ: BCDA) announced that Henry Ford Health enrolled its first patient on Nov 10, 2025 in the ongoing Phase 3 CardiAMP HF II...
Healthcare employers of all sizes are grappling to determine how changes to the H-1B visa program will affect their ability to expand their...
FRANKLIN LAKES, N.J., Sept. 22, 2025 /PRNewswire/ -- BD (Becton, Dickinson and Company) (NYSE: BDX), a leading…...
A growing number of health systems are centralizing pharmacy services to capture millions of dollars in savings and build up those revenue...
Radio Station WHMI 93.5 FM — Livingston County Michigan News, Weather, Traffic, Sports, School Updates, and the Best Classic Hits for Howell...
Detroit police search for Mario Green, 65, who shot and killed his ex-wife at Henry Ford Hospital. White Dodge Charger, license DXC 7067.
Henry Ford Health, Michigan State University and the MSU Research Foundation have created a $10 million venture fund to invest in early-stage healthcare...
Gabriella Ngang, of Farmington Hills, is one of three in Michigan to take part in a clinical trial of a new sickle cell disease gene-editing...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Henry Ford Health is http://www.henryford.com.
According to Rankiteo, Henry Ford Health’s AI-generated cybersecurity score is 768, reflecting their Fair security posture.
According to Rankiteo, Henry Ford Health currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Henry Ford Health is not certified under SOC 2 Type 1.
According to Rankiteo, Henry Ford Health does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Henry Ford Health is not listed as GDPR compliant.
According to Rankiteo, Henry Ford Health does not currently maintain PCI DSS compliance.
According to Rankiteo, Henry Ford Health is not compliant with HIPAA regulations.
According to Rankiteo,Henry Ford Health is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Henry Ford Health operates primarily in the Hospitals and Health Care industry.
Henry Ford Health employs approximately 20,343 people worldwide.
Henry Ford Health presently has no subsidiaries across any sectors.
Henry Ford Health’s official LinkedIn profile has approximately 121,801 followers.
Henry Ford Health is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
No, Henry Ford Health does not have a profile on Crunchbase.
Yes, Henry Ford Health maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/henry-ford-health.
As of November 27, 2025, Rankiteo reports that Henry Ford Health has experienced 2 cybersecurity incidents.
Henry Ford Health has an estimated 29,990 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Data Leak.
Title: Data Breach at Henry Ford Health System
Description: Henry Ford Health System has compromised patient information after an employee lost a flash drive with information on 2,777 patients. The drive stored information including names, medical record numbers, test information and results. Henry Ford officials said no Social Security numbers or health insurance identification numbers were compromised.
Type: Data Breach
Attack Vector: Physical Loss
Vulnerability Exploited: Loss of Physical Media
Threat Actor: Employee
Motivation: Accidental
Title: Henry Ford Health System Data Breach
Description: Henry Ford Health System has compromised patient information after a system got hacked that exposed 18,500 patients' personal information. The compromised information included the patient's name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, and health insurer. Neither Social Security numbers nor credit card information was revealed.
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Data Leak.

Data Compromised: Names, Medical record numbers, Test information and results

Data Compromised: Name, Date of birth, Medical record number, Provider's name, Date of service, Department's name, Location, Medical condition, Health insurer
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Medical Record Numbers, Test Information And Results, , Personal Information, Health Information and .

Entity Name: Henry Ford Health System
Entity Type: Healthcare
Industry: Healthcare
Customers Affected: 2777

Entity Name: Henry Ford Health System
Entity Type: Healthcare Provider
Industry: Healthcare
Customers Affected: 18500

Type of Data Compromised: Names, Medical record numbers, Test information and results
Number of Records Exposed: 2777
Sensitivity of Data: High

Type of Data Compromised: Personal information, Health information
Number of Records Exposed: 18500
Sensitivity of Data: High
Personally Identifiable Information: namedate of birthmedical record number

Recommendations: People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked.
Implemented Recommendations: The company has implemented the following recommendations to improve cybersecurity: People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked..
Last Attacking Group: The attacking group in the last incident was an Employee.
Most Significant Data Compromised: The most significant data compromised in an incident were names, medical record numbers, test information and results, , name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, health insurer and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were location, date of birth, medical record number, name, department's name, medical condition, test information and results, medical record numbers, provider's name, date of service, health insurer and names.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 469.0.
Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked..
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.