ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

*Job seekers: please be aware of fraudulent job postings and phishing scams via LinkedIn. Henry Ford Health only contacts applicants through our human resources department and via a corporate email address. Here are some tips to be aware of: http://ow.ly/Kc0o50EKory Serving communities across Michigan and beyond, Henry Ford Health is committed to partnering with patients & members along their entire health journey. Henry Ford Health provides a full continuum of services – from primary and preventative care, to complex and specialty care, health insurance, a full suite of home health offerings, virtual care, pharmacy, eye care & other healthcare retail. It is one of the nation’s leading academic medical centers, recognized for clinical excellence in cancer care, cardiology and cardiovascular surgery, neurology and neurosurgery, orthopedics and sports medicine, and multi-organ transplants. Consistently ranked among the top five NIH-funded institutions in Michigan, Henry Ford Health engages in thousands of research projects annually. Equally committed to educating the next generation of health professionals, Henry Ford Health trains more than 4,000 medical students, residents and fellows every year across 50+ accredited programs. With more than 50,000 valued team members, Henry Ford Health is also among Michigan’s largest and most diverse employers. President and CEO Bob Riney leads the health system and serves a growing number of customers across more than 550 sites across Michigan. That includes: 13 acute care hospitals; 3 behavioral health facilities including two world-class addiction treatment centers; a state-of-the-art orthopedics and sports medicine facility; multiple cancer care destinations including the Brigitte Harris Cancer Pavilion, Henry Ford Health’s premier location in Detroit; & more options than ever for primary care for patients and families across the region.

Henry Ford Health A.I CyberSecurity Scoring

HFH

Company Details

Linkedin ID:

henry-ford-health

Employees number:

20,343

Number of followers:

121,801

NAICS:

62

Industry Type:

Hospitals and Health Care

Homepage:

henryford.com

IP Addresses:

4

Company ID:

HEN_2535154

Scan Status:

Completed

AI scoreHFH Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/henry-ford-health.jpeg
HFH Hospitals and Health Care
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreHFH Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/henry-ford-health.jpeg
HFH Hospitals and Health Care
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

HFH Company CyberSecurity News & History

Past Incidents
2
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Henry Ford HealthData Leak60302/2011
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: Henry Ford Health System has compromised patient information after an employee lost a flash drive with information on 2,777 patients. The drive stored information including names, medical record numbers, test information and results. Henry Ford officials said no Social Security numbers or health insurance identification numbers.

Henry Ford HealthData Leak85312/2017
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: Henry Ford Health System has compromised patient information after a system got hacked that exposed 18,500 patients' personal information. The compromised information included the patient's name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, and health insurer. Neither Social Security numbers nor credit card information was revealed. People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked.

Henry Ford Health
Data Leak
Severity: 60
Impact: 3
Seen: 02/2011
Blog:
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: Henry Ford Health System has compromised patient information after an employee lost a flash drive with information on 2,777 patients. The drive stored information including names, medical record numbers, test information and results. Henry Ford officials said no Social Security numbers or health insurance identification numbers.

Henry Ford Health
Data Leak
Severity: 85
Impact: 3
Seen: 12/2017
Blog:
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: Henry Ford Health System has compromised patient information after a system got hacked that exposed 18,500 patients' personal information. The compromised information included the patient's name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, and health insurer. Neither Social Security numbers nor credit card information was revealed. People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked.

Ailogo

HFH Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for HFH

Incidents vs Hospitals and Health Care Industry Average (This Year)

No incidents recorded for Henry Ford Health in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Henry Ford Health in 2025.

Incident Types HFH vs Hospitals and Health Care Industry Avg (This Year)

No incidents recorded for Henry Ford Health in 2025.

Incident History — HFH (X = Date, Y = Severity)

HFH cyber incidents detection timeline including parent company and subsidiaries

HFH Company Subsidiaries

SubsidiaryImage

*Job seekers: please be aware of fraudulent job postings and phishing scams via LinkedIn. Henry Ford Health only contacts applicants through our human resources department and via a corporate email address. Here are some tips to be aware of: http://ow.ly/Kc0o50EKory Serving communities across Michigan and beyond, Henry Ford Health is committed to partnering with patients & members along their entire health journey. Henry Ford Health provides a full continuum of services – from primary and preventative care, to complex and specialty care, health insurance, a full suite of home health offerings, virtual care, pharmacy, eye care & other healthcare retail. It is one of the nation’s leading academic medical centers, recognized for clinical excellence in cancer care, cardiology and cardiovascular surgery, neurology and neurosurgery, orthopedics and sports medicine, and multi-organ transplants. Consistently ranked among the top five NIH-funded institutions in Michigan, Henry Ford Health engages in thousands of research projects annually. Equally committed to educating the next generation of health professionals, Henry Ford Health trains more than 4,000 medical students, residents and fellows every year across 50+ accredited programs. With more than 50,000 valued team members, Henry Ford Health is also among Michigan’s largest and most diverse employers. President and CEO Bob Riney leads the health system and serves a growing number of customers across more than 550 sites across Michigan. That includes: 13 acute care hospitals; 3 behavioral health facilities including two world-class addiction treatment centers; a state-of-the-art orthopedics and sports medicine facility; multiple cancer care destinations including the Brigitte Harris Cancer Pavilion, Henry Ford Health’s premier location in Detroit; & more options than ever for primary care for patients and families across the region.

Loading...
similarCompanies

HFH Similar Companies

Sentara Health

Sentara Health, an integrated, not-for-profit health care delivery system, celebrates more than 135 years in pursuit of its mission - "we improve health every day." Sentara is one of the largest health systems in the U.S. Mid-Atlantic and Southeast, and among the top 20 largest not-for-profit integr

Penn Medicine, University of Pennsylvania Health System

Penn Medicine’s mission is to advance knowledge and improve health through research, patient care, and the education of trainees in an inclusive culture that embraces diversity, fosters innovation, stimulates critical thinking, supports lifelong learning, and sustains our legacy of excellence. Penn

IHH Healthcare

A world-leading integrated healthcare provider, IHH believes that making a difference starts with our aspiration to Care. For Good. Our team of 65,000 people commit to deliver greater good to our patients, people, the public and our planet, as we live our purpose each day to touch lives and trans

Memorial Healthcare System

Be at the heart of exceptional care. Team MHS Florida is an award-winning group of friends and colleagues at one of the largest not-for-profit health systems in the nation. We're 17,000 strong, advancing towards a brighter future together. We're passionate about the work we do, delivering deep, pe

BrightSpring Health Services

BrightSpring is the parent company of a family of services and brands that provides clinical, nonclinical, pharmacy and ancillary care services for people of all ages, health and skill levels across home and community settings. The company is a leading provider of diversified home and community-ba

Dignity Health

We provide quality, compassionate health care at more than 40 hospitals and care centers that are serving communities across California, Arizona and Nevada every minute of every day. And while not everyone may live near a major medical facility, Dignity Health is making health care more accessible b

Massachusetts General Hospital

Guided by the needs of our patients and their families, Massachusetts General Hospital aims to deliver the very best health care in a safe, compassionate environment; to advance that care through innovative research and education; and, to improve the health and well-being of the diverse communitie

Hapvida NotreDame Intermédica

Com cerca de 80 anos de experiência, a Hapvida é hoje a maior empresa de saúde integrada da América Latina. A companhia, que possui mais de 69 mil colaboradores, atende quase 16 milhões de beneficiários de saúde e odontologia espalhados pelas cinco regiões do Brasil. Todo o aparato foi construído a

McKesson

Welcome to the official LinkedIn page for McKesson Corporation. We're an impact-driven healthcare organization dedicated to “Advancing Health Outcomes For All.” As a global healthcare company, we touch virtually every aspect of health. Our leaders empower our people to lead with a growth mindset an

newsone

HFH CyberSecurity News

November 12, 2025 04:03 AM
How Michigan hospitals are tackling burnout among nurses

In west Michigan, nurses are using an app to redirect nonmedical work to other workers. In Jackson, some nurses are working virtually.

November 10, 2025 01:30 PM
BioCardia (NASDAQ: BCDA) begins Phase 3 CardiAMP HF II; first patient enrolled at Henry Ford Health

BioCardia (NASDAQ: BCDA) announced that Henry Ford Health enrolled its first patient on Nov 10, 2025 in the ongoing Phase 3 CardiAMP HF II...

September 23, 2025 07:00 AM
What the changes to H-1B visas might mean for healthcare

Healthcare employers of all sizes are grappling to determine how changes to the H-1B visa program will affect their ability to expand their...

September 22, 2025 07:00 AM
BD and Henry Ford Health Sign Pharmacy Automation Partnership to Revolutionize Medication Storage and Prescription Delivery

FRANKLIN LAKES, N.J., Sept. 22, 2025 /PRNewswire/ -- BD (Becton, Dickinson and Company) (NYSE: BDX), a leading…...

August 27, 2025 07:00 AM
How health systems are saving money with centralized pharmacies

A growing number of health systems are centralizing pharmacy services to capture millions of dollars in savings and build up those revenue...

August 25, 2025 07:00 AM
Cleary University's New Program Offers 50% Tuition Grant to Businesses

Radio Station WHMI 93.5 FM — Livingston County Michigan News, Weather, Traffic, Sports, School Updates, and the Best Classic Hits for Howell...

August 22, 2025 07:00 AM
Detroit police manhunt for suspect who shot ex-wife

Detroit police search for Mario Green, 65, who shot and killed his ex-wife at Henry Ford Hospital. White Dodge Charger, license DXC 7067.

July 23, 2025 07:00 AM
Henry Ford Health, Michigan State University launch $10M VC fund

Henry Ford Health, Michigan State University and the MSU Research Foundation have created a $10 million venture fund to invest in early-stage healthcare...

July 06, 2025 07:00 AM
Oakland County teen to undergo gene-editing trial, hoping to cure her sickle cell disease

Gabriella Ngang, of Farmington Hills, is one of three in Michigan to take part in a clinical trial of a new sickle cell disease gene-editing...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

HFH CyberSecurity History Information

Official Website of Henry Ford Health

The official website of Henry Ford Health is http://www.henryford.com.

Henry Ford Health’s AI-Generated Cybersecurity Score

According to Rankiteo, Henry Ford Health’s AI-generated cybersecurity score is 768, reflecting their Fair security posture.

How many security badges does Henry Ford Health’ have ?

According to Rankiteo, Henry Ford Health currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Henry Ford Health have SOC 2 Type 1 certification ?

According to Rankiteo, Henry Ford Health is not certified under SOC 2 Type 1.

Does Henry Ford Health have SOC 2 Type 2 certification ?

According to Rankiteo, Henry Ford Health does not hold a SOC 2 Type 2 certification.

Does Henry Ford Health comply with GDPR ?

According to Rankiteo, Henry Ford Health is not listed as GDPR compliant.

Does Henry Ford Health have PCI DSS certification ?

According to Rankiteo, Henry Ford Health does not currently maintain PCI DSS compliance.

Does Henry Ford Health comply with HIPAA ?

According to Rankiteo, Henry Ford Health is not compliant with HIPAA regulations.

Does Henry Ford Health have ISO 27001 certification ?

According to Rankiteo,Henry Ford Health is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Henry Ford Health

Henry Ford Health operates primarily in the Hospitals and Health Care industry.

Number of Employees at Henry Ford Health

Henry Ford Health employs approximately 20,343 people worldwide.

Subsidiaries Owned by Henry Ford Health

Henry Ford Health presently has no subsidiaries across any sectors.

Henry Ford Health’s LinkedIn Followers

Henry Ford Health’s official LinkedIn profile has approximately 121,801 followers.

NAICS Classification of Henry Ford Health

Henry Ford Health is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.

Henry Ford Health’s Presence on Crunchbase

No, Henry Ford Health does not have a profile on Crunchbase.

Henry Ford Health’s Presence on LinkedIn

Yes, Henry Ford Health maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/henry-ford-health.

Cybersecurity Incidents Involving Henry Ford Health

As of November 27, 2025, Rankiteo reports that Henry Ford Health has experienced 2 cybersecurity incidents.

Number of Peer and Competitor Companies

Henry Ford Health has an estimated 29,990 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Henry Ford Health ?

Incident Types: The types of cybersecurity incidents that have occurred include Data Leak.

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Data Breach at Henry Ford Health System

Description: Henry Ford Health System has compromised patient information after an employee lost a flash drive with information on 2,777 patients. The drive stored information including names, medical record numbers, test information and results. Henry Ford officials said no Social Security numbers or health insurance identification numbers were compromised.

Type: Data Breach

Attack Vector: Physical Loss

Vulnerability Exploited: Loss of Physical Media

Threat Actor: Employee

Motivation: Accidental

Incident : Data Breach

Title: Henry Ford Health System Data Breach

Description: Henry Ford Health System has compromised patient information after a system got hacked that exposed 18,500 patients' personal information. The compromised information included the patient's name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, and health insurer. Neither Social Security numbers nor credit card information was revealed.

Type: Data Breach

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Data Leak.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach HEN19214123

Data Compromised: Names, Medical record numbers, Test information and results

Incident : Data Breach HEN2285323

Data Compromised: Name, Date of birth, Medical record number, Provider's name, Date of service, Department's name, Location, Medical condition, Health insurer

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Medical Record Numbers, Test Information And Results, , Personal Information, Health Information and .

Which entities were affected by each incident ?

Incident : Data Breach HEN19214123

Entity Name: Henry Ford Health System

Entity Type: Healthcare

Industry: Healthcare

Customers Affected: 2777

Incident : Data Breach HEN2285323

Entity Name: Henry Ford Health System

Entity Type: Healthcare Provider

Industry: Healthcare

Customers Affected: 18500

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach HEN19214123

Type of Data Compromised: Names, Medical record numbers, Test information and results

Number of Records Exposed: 2777

Sensitivity of Data: High

Incident : Data Breach HEN2285323

Type of Data Compromised: Personal information, Health information

Number of Records Exposed: 18500

Sensitivity of Data: High

Personally Identifiable Information: namedate of birthmedical record number

Lessons Learned and Recommendations

What recommendations were made to prevent future incidents ?

Incident : Data Breach HEN2285323

Recommendations: People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked.

What recommendations has the company implemented to improve cybersecurity ?

Implemented Recommendations: The company has implemented the following recommendations to improve cybersecurity: People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked..

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident was an Employee.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were names, medical record numbers, test information and results, , name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, health insurer and .

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were location, date of birth, medical record number, name, department's name, medical condition, test information and results, medical record numbers, provider's name, date of service, health insurer and names.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 469.0.

Lessons Learned and Recommendations

What was the most significant recommendation implemented to improve cybersecurity ?

Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked..

cve

Latest Global CVEs (Not Company-Specific)

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.

Risk Information
cvss4
Base: 7.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=henry-ford-health' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge