Company Details
mass-general-brigham
11,655
140,095
62
massgeneralbrigham.org
69
MAS_6710814
Completed

Mass General Brigham Company CyberSecurity Posture
massgeneralbrigham.orgMass General Brigham is an integrated academic health care system, uniting great minds to solve the hardest problems in medicine for our communities and the world. Mass General Brigham connects a full continuum of care across a system of academic medical centers, community and specialty hospitals, a health insurance plan, physician networks, community health centers, home care, and long-term care services. Mass General Brigham is a nonprofit organization that is committed to patient care, research, teaching, and service to the community. In addition, Mass General Brigham is one of the nation’s leading biomedical research organizations and a principal teaching affiliate of Harvard Medical School.
Company Details
mass-general-brigham
11,655
140,095
62
massgeneralbrigham.org
69
MAS_6710814
Completed
Between 700 and 749

MGB Global Score (TPRM)XXXX

Description: The New Hampshire Attorney General's Office reported a data breach involving Mass General Brigham Incorporated on December 18, 2020. The breach was due to human error where a file containing personal information, including names and Social Security numbers, was posted on a public website for a 14-hour period between November 23-24, 2020, affecting approximately 179 New Hampshire residents.
Description: The Vermont Office of the Attorney General reported on June 28, 2024, a data breach incident involving Mass General Brigham Health Plan (MGBHP) that may have allowed unauthorized access to members' personal information between July 31, 2023, and April 2, 2024. The exposed information potentially included names, addresses, medical record numbers, dates of birth, email addresses, phone numbers, health insurance policy numbers, and Social Security numbers.


No incidents recorded for Mass General Brigham in 2025.
No incidents recorded for Mass General Brigham in 2025.
No incidents recorded for Mass General Brigham in 2025.
MGB cyber incidents detection timeline including parent company and subsidiaries

Mass General Brigham is an integrated academic health care system, uniting great minds to solve the hardest problems in medicine for our communities and the world. Mass General Brigham connects a full continuum of care across a system of academic medical centers, community and specialty hospitals, a health insurance plan, physician networks, community health centers, home care, and long-term care services. Mass General Brigham is a nonprofit organization that is committed to patient care, research, teaching, and service to the community. In addition, Mass General Brigham is one of the nation’s leading biomedical research organizations and a principal teaching affiliate of Harvard Medical School.


ABOUT THE UNIVERSITY OF TEXAS MEDICAL BRANCH: Texas' first academic health center opened its doors in 1891 and today has four campuses, five health sciences schools, six institutes for advanced study, a research enterprise that includes one of only two national laboratories dedicated to the safe stu

Rochester Regional Health, headquartered in Rochester, NY, is an integrated health services organization serving the people of Western New York, the Finger Lakes, St. Lawrence County, and beyond. We are dedicated to helping our community stay healthy and live fulfilling lives. Together, we find the

The University of Maryland Medical System (UMMS) was created in 1984 when the state-owned University Hospital became a private, nonprofit organization. It has evolved into a multi-hospital system with academic, community and specialty service missions reaching every part of the state and beyond. UM
The International SOS Group of Companies has been in the business of saving lives for over 40 years. Protecting global workforces from health and security threats, we deliver customised health, security risk management and wellbeing solutions to fuel our clients’ growth and productivity. In the even

One of the largest Trusts in the UK, Guy’s and St Thomas’ NHS Foundation Trust comprises five of the UK’s best known hospitals – Guy’s, St Thomas’, Evelina London Children’s Hospital, Royal Brompton and Harefield – as well as community services in Lambeth and Southwark, all with a long history of hi

NHG Health is a leading public healthcare provider in Singapore recognised for its quality clinical care and its commitment in enabling healthier lives through preventive health, innovative solutions and person-centred programmes tailored to every life stage. Our integrated health system, which span

SARquavitae, personas que cuidan a las personas SARquavitae es la mayor plataforma de España de servicios sanitarios y sociales de atención a las personas. La plantilla, formada por 12.200 profesionales, ofrece más de 10.900 plazas repartidas por todo el territorio español y atiende a unas 200.0

Zuellig Pharma is a leading integrated healthcare solutions company in Asia with experience spanning over a century in the region. Partnering with multinational pharmaceutical manufacturers, governments, healthcare providers, and professionals, we broaden access to pharmaceutical and healthcare prod

Every day, 119,000 compassionate caregivers serve patients and communities through Providence St. Joseph Health, a national, Catholic, not-for-profit health system, driven by a belief that health is a human right. Rooted in the founding missions of the Sisters of Providence and the Sisters of St.
.png)
The new startup Realm.Security was founded by veterans of Boston-area firms Rapid7 and Carbon Black.
Vulnerabilities in the software have allowed hackers to access file systems and execute code, the US Cybersecurity and Infrastructure...
Tech power players like Corey Thomas are leading the way in Greater Boston's cybersecurity industry. Learn more in our 2025 list of New...
Instead of ranking the leaders, the Globe chose a dozen tech sectors — and the top people in each sector — that are key to the region's...
News News: The Trump administration's $9 billion review of research funding tied to Harvard University could severely impact Boston...
Newly enhanced AI tools from the cyber company aim to provide warnings about unhealthy behavior while maintaining the kids' sense of...
Cybersecurity tech company CyberArk just reached an important milestone: $1 billion in annual revenue. And being one of the cyber industry's...
Israeli cybersecurity expert Lior Div came to the United States more than a decade ago when he relocated his company, Cybereason, to Boston.
The educational software giant said it doesn't anticipate any of the compromised information “being shared or made public,” as a review of...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Mass General Brigham is https://www.massgeneralbrigham.org/.
According to Rankiteo, Mass General Brigham’s AI-generated cybersecurity score is 730, reflecting their Moderate security posture.
According to Rankiteo, Mass General Brigham currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Mass General Brigham is not certified under SOC 2 Type 1.
According to Rankiteo, Mass General Brigham does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Mass General Brigham is not listed as GDPR compliant.
According to Rankiteo, Mass General Brigham does not currently maintain PCI DSS compliance.
According to Rankiteo, Mass General Brigham is not compliant with HIPAA regulations.
According to Rankiteo,Mass General Brigham is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Mass General Brigham operates primarily in the Hospitals and Health Care industry.
Mass General Brigham employs approximately 11,655 people worldwide.
Mass General Brigham presently has no subsidiaries across any sectors.
Mass General Brigham’s official LinkedIn profile has approximately 140,095 followers.
Mass General Brigham is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
No, Mass General Brigham does not have a profile on Crunchbase.
Yes, Mass General Brigham maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/mass-general-brigham.
As of December 09, 2025, Rankiteo reports that Mass General Brigham has experienced 2 cybersecurity incidents.
Mass General Brigham has an estimated 30,707 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Title: Data Breach at Mass General Brigham Incorporated
Description: A data breach occurred due to human error where a file containing personal information, including names and Social Security numbers, was posted on a public website for a 14-hour period between November 23-24, 2020.
Date Detected: 2020-11-24
Date Publicly Disclosed: 2020-12-18
Type: Data Breach
Attack Vector: Human Error
Vulnerability Exploited: Improper Data Handling
Title: Data Breach at Mass General Brigham Health Plan
Description: The Vermont Office of the Attorney General reported on June 28, 2024, a data breach incident involving Mass General Brigham Health Plan (MGBHP) that may have allowed unauthorized access to members' personal information between July 31, 2023, and April 2, 2024. The exposed information potentially included names, addresses, medical record numbers, dates of birth, email addresses, phone numbers, health insurance policy numbers, and Social Security numbers.
Date Detected: 2024-06-28
Date Publicly Disclosed: 2024-06-28
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Names, Social security numbers

Data Compromised: Names, Addresses, Medical record numbers, Dates of birth, Email addresses, Phone numbers, Health insurance policy numbers, Social security numbers
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Social Security Numbers, , Names, Addresses, Medical Record Numbers, Dates Of Birth, Email Addresses, Phone Numbers, Health Insurance Policy Numbers, Social Security Numbers and .

Entity Name: Mass General Brigham Incorporated
Entity Type: Healthcare
Industry: Healthcare
Location: New Hampshire
Customers Affected: 179

Entity Name: Mass General Brigham Health Plan
Entity Type: Healthcare
Industry: Healthcare

Type of Data Compromised: Names, Social security numbers
Number of Records Exposed: 179
Sensitivity of Data: High

Type of Data Compromised: Names, Addresses, Medical record numbers, Dates of birth, Email addresses, Phone numbers, Health insurance policy numbers, Social security numbers
Sensitivity of Data: High

Source: New Hampshire Attorney General's Office
Date Accessed: 2020-12-18

Source: Vermont Office of the Attorney General
Date Accessed: 2024-06-28
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: New Hampshire Attorney General's OfficeDate Accessed: 2020-12-18, and Source: Vermont Office of the Attorney GeneralDate Accessed: 2024-06-28.

Root Causes: Human Error
Most Recent Incident Detected: The most recent incident detected was on 2020-11-24.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-06-28.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Social Security numbers, , names, addresses, medical record numbers, dates of birth, email addresses, phone numbers, health insurance policy numbers, Social Security numbers and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were health insurance policy numbers, medical record numbers, names, Names, dates of birth, Social Security numbers, addresses, phone numbers and email addresses.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 179.0.
Most Recent Source: The most recent source of information about an incident are Vermont Office of the Attorney General and New Hampshire Attorney General's Office.
.png)
Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763126988 and Tuleap Enterprise Edition prior to 17.0-3 and 16.13-8 have missing CSRF protections which allow attackers to create or remove tracker triggers. This issue is fixed in Tuleap Community Edition version 17.0.99.1763126988 and Tuleap Enterprise Edition versions 17.0-3 and 16.13-8.
Tuleap is a free and open source suite for management of software development and collaboration. Tuleap Community Editon versions prior to 17.0.99.1762456922 and Tuleap Enterprise Edition versions prior to 17.0-2, 16.13-7 and 16.12-10 are vulnerable to CSRF attacks through planning management API. Attackers have access to create, edit or remove plans. This issue is fixed in Tuleap Community Edition version 17.0.99.1762456922 and Tuleap Enterprise Edtion versions 17.0-2, 16.13-7 and 16.12-10.
Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versions below 17.0.99.1762444754 and Tuleap Enterprise Edition versions prior to 17.0-2, 16.13-7 and 16.12-10 allow attackers trick victims into changing tracker general settings. This issue is fixed in version Tuleap Community Edition version 17.0.99.1762444754 and Tuleap Enterprise Edition versions 17.0-2, 16.13-7 and 16.12-10.
Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.1762431347 of Tuleap Community Edition and Tuleap Enterprise Edition below 17.0-2, 16.13-7 and 16.12-10 allow attackers to access file release system information in projects they do not have access to. This issue is fixed in version 17.0.99.1762431347 of the Tuleap Community Edition and versions 17.0-2, 16.13-7 and 16.12-10 of Tuleap Enterprise Edition.
IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation of resources without limits.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.