Comparison Overview
LHC Group

LHC Group
901 Hugh Wallis Rd. S., Lafayette, 70508, US
Last Update: 12/09/2026
LHC Group, Inc. is a national provider of in-home healthcare services and innovations for communities around the nation, offering quality, value-based healthcare to patients primarily within the comfort and privacy of their home or place of residence. The company’s 29,0...

Encompass Health
9001 Liberty Pkwy, Birmingham, 35242, US
Last Update: 13/09/2026
Encompass Health is the largest owner and operator of rehabilitation hospitals in the United States. With a national footprint that includes more than 170 hospitals in 39 states and Puerto Rico, the Company provides high-quality, compassionate rehabilitative care for pa...
Compliance Ranges Comparison

LHC Group







Encompass Health






Benchmark & Cyber Underwriting Signals
Incidents vs Hospitals and Health Care Industry Avg (This Year)
LHC Group has 41.84% more incidents than the average of same-industry companies with at least one recorded incident.
Incidents vs Hospitals and Health Care Industry Avg (This Year)
No incidents recorded for Encompass Health in 2026.
Incident History - LHC Group (X = Date, Y = Severity)
LHC Group cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Encompass Health (X = Date, Y = Severity)
Encompass Health cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

LHC Group

Encompass Health
FAQ
Latest Global CVEs
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.