Company Details
henry-ford-health
20,800
125,741
62
henryford.com
4
HEN_2535154
Completed


Henry Ford Health Company CyberSecurity Posture
henryford.com*Job seekers: please be aware of fraudulent job postings and phishing scams via LinkedIn. Henry Ford Health only contacts applicants through our human resources department and via a corporate email address. Here are some tips to be aware of: http://ow.ly/Kc0o50EKory Serving communities across Michigan and beyond, Henry Ford Health is committed to partnering with patients & members along their entire health journey. Henry Ford Health provides a full continuum of services – from primary and preventative care, to complex and specialty care, health insurance, a full suite of home health offerings, virtual care, pharmacy, eye care & other healthcare retail. It is one of the nation’s leading academic medical centers, recognized for clinical excellence in cancer care, cardiology and cardiovascular surgery, neurology and neurosurgery, orthopedics and sports medicine, and multi-organ transplants. Consistently ranked among the top five NIH-funded institutions in Michigan, Henry Ford Health engages in thousands of research projects annually. Equally committed to educating the next generation of health professionals, Henry Ford Health trains more than 4,000 medical students, residents and fellows every year across 50+ accredited programs. With more than 50,000 valued team members, Henry Ford Health is also among Michigan’s largest and most diverse employers. President and CEO Bob Riney leads the health system and serves a growing number of customers across more than 550 sites across Michigan. That includes: 13 acute care hospitals; 3 behavioral health facilities including two world-class addiction treatment centers; a state-of-the-art orthopedics and sports medicine facility; multiple cancer care destinations including the Brigitte Harris Cancer Pavilion, Henry Ford Health’s premier location in Detroit; & more options than ever for primary care for patients and families across the region.
Company Details
henry-ford-health
20,800
125,741
62
henryford.com
4
HEN_2535154
Completed
Between 750 and 799

HFH Global Score (TPRM)XXXX

Description: Henry Ford Health System has compromised patient information after a system got hacked that exposed 18,500 patients' personal information. The compromised information included the patient's name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, and health insurer. Neither Social Security numbers nor credit card information was revealed. People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked.
Description: Henry Ford Health System has compromised patient information after an employee lost a flash drive with information on 2,777 patients. The drive stored information including names, medical record numbers, test information and results. Henry Ford officials said no Social Security numbers or health insurance identification numbers.


No incidents recorded for Henry Ford Health in 2026.
No incidents recorded for Henry Ford Health in 2026.
No incidents recorded for Henry Ford Health in 2026.
HFH cyber incidents detection timeline including parent company and subsidiaries

*Job seekers: please be aware of fraudulent job postings and phishing scams via LinkedIn. Henry Ford Health only contacts applicants through our human resources department and via a corporate email address. Here are some tips to be aware of: http://ow.ly/Kc0o50EKory Serving communities across Michigan and beyond, Henry Ford Health is committed to partnering with patients & members along their entire health journey. Henry Ford Health provides a full continuum of services – from primary and preventative care, to complex and specialty care, health insurance, a full suite of home health offerings, virtual care, pharmacy, eye care & other healthcare retail. It is one of the nation’s leading academic medical centers, recognized for clinical excellence in cancer care, cardiology and cardiovascular surgery, neurology and neurosurgery, orthopedics and sports medicine, and multi-organ transplants. Consistently ranked among the top five NIH-funded institutions in Michigan, Henry Ford Health engages in thousands of research projects annually. Equally committed to educating the next generation of health professionals, Henry Ford Health trains more than 4,000 medical students, residents and fellows every year across 50+ accredited programs. With more than 50,000 valued team members, Henry Ford Health is also among Michigan’s largest and most diverse employers. President and CEO Bob Riney leads the health system and serves a growing number of customers across more than 550 sites across Michigan. That includes: 13 acute care hospitals; 3 behavioral health facilities including two world-class addiction treatment centers; a state-of-the-art orthopedics and sports medicine facility; multiple cancer care destinations including the Brigitte Harris Cancer Pavilion, Henry Ford Health’s premier location in Detroit; & more options than ever for primary care for patients and families across the region.


Allegheny Health Network is an integrated health care delivery system serving the greater Western Pennsylvania region. More than 2,600 physicians and 21,000 employees serve the system's 14 hospitals as well as its ambulatory medical and surgery centers, Health + Wellness Pavilions, and hundreds of p

NMC Healthcare is one of the largest private healthcare networks in the United Arab Emirates. Since 1975, we have provided high quality, personalised, and compassionate care to our patients and are proud to have earned the trust of millions of people in the UAE and around the world. ---------------

Be at the heart of exceptional care. Team MHS Florida is an award-winning group of friends and colleagues at one of the largest not-for-profit health systems in the nation. We're 17,000 strong, advancing towards a brighter future together. We're passionate about the work we do, delivering deep, pe
DaVita means “to give life,” reflecting our proud history as leaders in dialysis—an essential, life-sustaining treatment for those living with end stage kidney disease (ESKD). Today, our mission is to minimize the devastating impacts of kidney disease across the full spectrum of kidney health care.

Answering God's call to bring health, healing and hope to all. Ascension is one of the nation’s leading non-profit and Catholic health systems, with a Mission of delivering compassionate, personalized care to all, with special attention to those most vulnerable. In FY2025, Ascension provided $1.7

At The Ohio State University Wexner Medical Center you will find more than a job – you can establish a career that allows you to actually change the face of medicine. As central Ohio's only academic medical center, we emphasize learning, development and innovation in order to offer the very best in

On September 1, 2018 Bon Secours Health System and Mercy Health combined to become the United States’ fifth largest Catholic health care ministry and one of the nation’s 20 largest health care systems. With 48 hospitals, thousands of providers, over 1,000 points of care and over 60,000 employees Bon

NHG Health is a leading public healthcare provider in Singapore recognised for its quality clinical care and its commitment in enabling healthier lives through preventive health, innovative solutions and person-centred programmes tailored to every life stage. Our integrated health system, which span

Boston Children's Hospital is a 404-bed comprehensive center for pediatric health care. As one of the largest pediatric medical centers in the United States, Boston Children's offers a complete range of health care services for children from birth through 21 years of age. (Our services can begin int
.png)
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) data breach portal shows that patients' protected health...
Hospital CISOs cite visibility and internal process gaps as the biggest hurdles to securing connected medical equipment.
An insider data breach has been reported by Henry Ford Health in Michigan, and Wilmington Community Clinic has notified patients about an...
The AHA's cybersecurity and risk experts provide insight into 2025's health care cybersecurity challenges to help hospitals prepare for the...
The AHA's American Society for Healthcare Risk Management will host the ASHRM25 Virtual Conference Nov. 5-7. This event, designed for health...
The AHA's cybersecurity and risk experts provide insight into 2025's health care cybersecurity challenges to help hospitals prepare for the...
The personal data of nearly 139000 people in Michigan's Thumb has been compromised in a cybersecurity breach at Aspire Rural Health System.
Radio Station WHMI 93.5 FM — Livingston County Michigan News, Weather, Traffic, Sports, School Updates, and the Best Classic Hits for Howell...
Henry Ford Health, Michigan State University and the MSU Research Foundation have created a $10 million venture fund to invest in early-stage healthcare...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Henry Ford Health is http://www.henryford.com.
According to Rankiteo, Henry Ford Health’s AI-generated cybersecurity score is 769, reflecting their Fair security posture.
According to Rankiteo, Henry Ford Health currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Henry Ford Health has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Henry Ford Health is not certified under SOC 2 Type 1.
According to Rankiteo, Henry Ford Health does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Henry Ford Health is not listed as GDPR compliant.
According to Rankiteo, Henry Ford Health does not currently maintain PCI DSS compliance.
According to Rankiteo, Henry Ford Health is not compliant with HIPAA regulations.
According to Rankiteo,Henry Ford Health is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Henry Ford Health operates primarily in the Hospitals and Health Care industry.
Henry Ford Health employs approximately 20,800 people worldwide.
Henry Ford Health presently has no subsidiaries across any sectors.
Henry Ford Health’s official LinkedIn profile has approximately 125,741 followers.
Henry Ford Health is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
No, Henry Ford Health does not have a profile on Crunchbase.
Yes, Henry Ford Health maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/henry-ford-health.
As of January 21, 2026, Rankiteo reports that Henry Ford Health has experienced 2 cybersecurity incidents.
Henry Ford Health has an estimated 31,578 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Data Leak.
Title: Data Breach at Henry Ford Health System
Description: Henry Ford Health System has compromised patient information after an employee lost a flash drive with information on 2,777 patients. The drive stored information including names, medical record numbers, test information and results. Henry Ford officials said no Social Security numbers or health insurance identification numbers were compromised.
Type: Data Breach
Attack Vector: Physical Loss
Vulnerability Exploited: Loss of Physical Media
Threat Actor: Employee
Motivation: Accidental
Title: Henry Ford Health System Data Breach
Description: Henry Ford Health System has compromised patient information after a system got hacked that exposed 18,500 patients' personal information. The compromised information included the patient's name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, and health insurer. Neither Social Security numbers nor credit card information was revealed.
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Data Leak.

Data Compromised: Names, Medical record numbers, Test information and results

Data Compromised: Name, Date of birth, Medical record number, Provider's name, Date of service, Department's name, Location, Medical condition, Health insurer
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Medical Record Numbers, Test Information And Results, , Personal Information, Health Information and .

Entity Name: Henry Ford Health System
Entity Type: Healthcare
Industry: Healthcare
Customers Affected: 2777

Entity Name: Henry Ford Health System
Entity Type: Healthcare Provider
Industry: Healthcare
Customers Affected: 18500

Type of Data Compromised: Names, Medical record numbers, Test information and results
Number of Records Exposed: 2777
Sensitivity of Data: High

Type of Data Compromised: Personal information, Health information
Number of Records Exposed: 18500
Sensitivity of Data: High
Personally Identifiable Information: namedate of birthmedical record number

Recommendations: People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked.
Implemented Recommendations: The company has implemented the following recommendations to improve cybersecurity: People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked..
Last Attacking Group: The attacking group in the last incident was an Employee.
Most Significant Data Compromised: The most significant data compromised in an incident were names, medical record numbers, test information and results, , name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, health insurer and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were date of service, provider's name, medical condition, department's name, names, name, location, test information and results, health insurer, medical record numbers, medical record number and date of birth.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 469.0.
Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked..
.png)
SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute arbitrary commands on the system running Wrangler. Root causeThe commitHash variable, derived from user input via the --commit-hash CLI argument, is interpolated directly into a shell command using template literals (e.g., execSync(`git show -s --format=%B ${commitHash}`)). Shell metacharacters are interpreted by the shell, enabling command execution. ImpactThis vulnerability is generally hard to exploit, as it requires --commit-hash to be attacker controlled. The vulnerability primarily affects CI/CD environments where `wrangler pages deploy` is used in automated pipelines and the --commit-hash parameter is populated from external, potentially untrusted sources. An attacker could exploit this to: * Run any shell command. * Exfiltrate environment variables. * Compromise the CI runner to install backdoors or modify build artifacts. Credits Disclosed responsibly by kny4hacker. Mitigation * Wrangler v4 users are requested to upgrade to Wrangler v4.59.1 or higher. * Wrangler v3 users are requested to upgrade to Wrangler v3.114.17 or higher. * Users on Wrangler v2 (EOL) should upgrade to a supported major version.
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L).
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.