ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Mass General Brigham is an integrated academic health care system, uniting great minds to solve the hardest problems in medicine for our communities and the world. Mass General Brigham connects a full continuum of care across a system of academic medical centers, community and specialty hospitals, a health insurance plan, physician networks, community health centers, home care, and long-term care services. Mass General Brigham is a nonprofit organization that is committed to patient care, research, teaching, and service to the community. In addition, Mass General Brigham is one of the nation’s leading biomedical research organizations and a principal teaching affiliate of Harvard Medical School.

Mass General Brigham A.I CyberSecurity Scoring

MGB

Company Details

Linkedin ID:

mass-general-brigham

Employees number:

11,655

Number of followers:

140,095

NAICS:

62

Industry Type:

Hospitals and Health Care

Homepage:

massgeneralbrigham.org

IP Addresses:

69

Company ID:

MAS_6710814

Scan Status:

Completed

AI scoreMGB Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/mass-general-brigham.jpeg
MGB Hospitals and Health Care
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreMGB Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/mass-general-brigham.jpeg
MGB Hospitals and Health Care
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

MGB Company CyberSecurity News & History

Past Incidents
2
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Mass General Brigham IncorporatedBreach60311/2020
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: The New Hampshire Attorney General's Office reported a data breach involving Mass General Brigham Incorporated on December 18, 2020. The breach was due to human error where a file containing personal information, including names and Social Security numbers, was posted on a public website for a 14-hour period between November 23-24, 2020, affecting approximately 179 New Hampshire residents.

Mass General Brigham Health PlanBreach8547/2023
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: The Vermont Office of the Attorney General reported on June 28, 2024, a data breach incident involving Mass General Brigham Health Plan (MGBHP) that may have allowed unauthorized access to members' personal information between July 31, 2023, and April 2, 2024. The exposed information potentially included names, addresses, medical record numbers, dates of birth, email addresses, phone numbers, health insurance policy numbers, and Social Security numbers.

Mass General Brigham Incorporated
Breach
Severity: 60
Impact: 3
Seen: 11/2020
Blog:
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: The New Hampshire Attorney General's Office reported a data breach involving Mass General Brigham Incorporated on December 18, 2020. The breach was due to human error where a file containing personal information, including names and Social Security numbers, was posted on a public website for a 14-hour period between November 23-24, 2020, affecting approximately 179 New Hampshire residents.

Mass General Brigham Health Plan
Breach
Severity: 85
Impact: 4
Seen: 7/2023
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: The Vermont Office of the Attorney General reported on June 28, 2024, a data breach incident involving Mass General Brigham Health Plan (MGBHP) that may have allowed unauthorized access to members' personal information between July 31, 2023, and April 2, 2024. The exposed information potentially included names, addresses, medical record numbers, dates of birth, email addresses, phone numbers, health insurance policy numbers, and Social Security numbers.

Ailogo

MGB Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for MGB

Incidents vs Hospitals and Health Care Industry Average (This Year)

No incidents recorded for Mass General Brigham in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Mass General Brigham in 2025.

Incident Types MGB vs Hospitals and Health Care Industry Avg (This Year)

No incidents recorded for Mass General Brigham in 2025.

Incident History — MGB (X = Date, Y = Severity)

MGB cyber incidents detection timeline including parent company and subsidiaries

MGB Company Subsidiaries

SubsidiaryImage

Mass General Brigham is an integrated academic health care system, uniting great minds to solve the hardest problems in medicine for our communities and the world. Mass General Brigham connects a full continuum of care across a system of academic medical centers, community and specialty hospitals, a health insurance plan, physician networks, community health centers, home care, and long-term care services. Mass General Brigham is a nonprofit organization that is committed to patient care, research, teaching, and service to the community. In addition, Mass General Brigham is one of the nation’s leading biomedical research organizations and a principal teaching affiliate of Harvard Medical School.

Loading...
similarCompanies

MGB Similar Companies

The University of Texas Medical Branch

ABOUT THE UNIVERSITY OF TEXAS MEDICAL BRANCH: Texas' first academic health center opened its doors in 1891 and today has four campuses, five health sciences schools, six institutes for advanced study, a research enterprise that includes one of only two national laboratories dedicated to the safe stu

Rochester Regional Health

Rochester Regional Health, headquartered in Rochester, NY, is an integrated health services organization serving the people of Western New York, the Finger Lakes, St. Lawrence County, and beyond. We are dedicated to helping our community stay healthy and live fulfilling lives. Together, we find the

University of Maryland Medical System

The University of Maryland Medical System (UMMS) was created in 1984 when the state-owned University Hospital became a private, nonprofit organization. It has evolved into a multi-hospital system with academic, community and specialty service missions reaching every part of the state and beyond. UM

International SOS

The International SOS Group of Companies has been in the business of saving lives for over 40 years. Protecting global workforces from health and security threats, we deliver customised health, security risk management and wellbeing solutions to fuel our clients’ growth and productivity. In the even

Guy's and St Thomas'​ NHS Foundation Trust

One of the largest Trusts in the UK, Guy’s and St Thomas’ NHS Foundation Trust comprises five of the UK’s best known hospitals – Guy’s, St Thomas’, Evelina London Children’s Hospital, Royal Brompton and Harefield – as well as community services in Lambeth and Southwark, all with a long history of hi

NHG Health

NHG Health is a leading public healthcare provider in Singapore recognised for its quality clinical care and its commitment in enabling healthier lives through preventive health, innovative solutions and person-centred programmes tailored to every life stage. Our integrated health system, which span

SARquavitae

SARquavitae, personas que cuidan a las personas SARquavitae es la mayor plataforma de España de servicios sanitarios y sociales de atención a las personas. La plantilla, formada por 12.200 profesionales, ofrece más de 10.900 plazas repartidas por todo el territorio español y atiende a unas 200.0

Zuellig Pharma

Zuellig Pharma is a leading integrated healthcare solutions company in Asia with experience spanning over a century in the region. Partnering with multinational pharmaceutical manufacturers, governments, healthcare providers, and professionals, we broaden access to pharmaceutical and healthcare prod

Every day, 119,000 compassionate caregivers serve patients and communities through Providence St. Joseph Health, a national, Catholic, not-for-profit health system, driven by a belief that health is a human right. Rooted in the founding missions of the Sisters of Providence and the Sisters of St.

newsone

MGB CyberSecurity News

November 18, 2025 08:00 AM
Boston’s top cybersecurity companies are feeding a growing startup ecosystem

The new startup Realm.Security was founded by veterans of Boston-area firms Rapid7 and Carbon Black.

July 21, 2025 07:00 AM
Hackers exploit Microsoft SharePoint as firm works to patch

Vulnerabilities in the software have allowed hackers to access file systems and execute code, the US Cybersecurity and Infrastructure...

June 10, 2025 07:00 AM
The 2025 Tech Power Players in the cybersecurity sector

Tech power players like Corey Thomas are leading the way in Greater Boston's cybersecurity industry. Learn more in our 2025 list of New...

June 10, 2025 07:00 AM
How we made the Tech Power Players list

Instead of ranking the leaders, the Globe chose a dozen tech sectors — and the top people in each sector — that are key to the region's...

April 04, 2025 07:00 AM
Trump administration's $9 billion funding review could threaten life-saving research at Harvard and Bosto

News News: The Trump administration's $9 billion review of research funding tied to Harvard University could severely impact Boston...

March 25, 2025 07:00 AM
Want to know what your kids are doing on their phones? Boston-based Aura has a solution.

Newly enhanced AI tools from the cyber company aim to provide warnings about unhealthy behavior while maintaining the kids' sense of...

February 24, 2025 08:00 AM
Newton cyber company clears $1 billion in annual revenue

Cybersecurity tech company CyberArk just reached an important milestone: $1 billion in annual revenue. And being one of the cyber industry's...

February 05, 2025 08:00 AM
Israeli cybersecurity expert plans his comeback in Boston

Israeli cybersecurity expert Lior Div came to the United States more than a decade ago when he relocated his company, Cybereason, to Boston.

January 09, 2025 08:00 AM
PowerSchool reviewing impact of data breach affecting school districts in Mass. and other states

The educational software giant said it doesn't anticipate any of the compromised information “being shared or made public,” as a review of...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

MGB CyberSecurity History Information

Official Website of Mass General Brigham

The official website of Mass General Brigham is https://www.massgeneralbrigham.org/.

Mass General Brigham’s AI-Generated Cybersecurity Score

According to Rankiteo, Mass General Brigham’s AI-generated cybersecurity score is 730, reflecting their Moderate security posture.

How many security badges does Mass General Brigham’ have ?

According to Rankiteo, Mass General Brigham currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Mass General Brigham have SOC 2 Type 1 certification ?

According to Rankiteo, Mass General Brigham is not certified under SOC 2 Type 1.

Does Mass General Brigham have SOC 2 Type 2 certification ?

According to Rankiteo, Mass General Brigham does not hold a SOC 2 Type 2 certification.

Does Mass General Brigham comply with GDPR ?

According to Rankiteo, Mass General Brigham is not listed as GDPR compliant.

Does Mass General Brigham have PCI DSS certification ?

According to Rankiteo, Mass General Brigham does not currently maintain PCI DSS compliance.

Does Mass General Brigham comply with HIPAA ?

According to Rankiteo, Mass General Brigham is not compliant with HIPAA regulations.

Does Mass General Brigham have ISO 27001 certification ?

According to Rankiteo,Mass General Brigham is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Mass General Brigham

Mass General Brigham operates primarily in the Hospitals and Health Care industry.

Number of Employees at Mass General Brigham

Mass General Brigham employs approximately 11,655 people worldwide.

Subsidiaries Owned by Mass General Brigham

Mass General Brigham presently has no subsidiaries across any sectors.

Mass General Brigham’s LinkedIn Followers

Mass General Brigham’s official LinkedIn profile has approximately 140,095 followers.

NAICS Classification of Mass General Brigham

Mass General Brigham is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.

Mass General Brigham’s Presence on Crunchbase

No, Mass General Brigham does not have a profile on Crunchbase.

Mass General Brigham’s Presence on LinkedIn

Yes, Mass General Brigham maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/mass-general-brigham.

Cybersecurity Incidents Involving Mass General Brigham

As of December 09, 2025, Rankiteo reports that Mass General Brigham has experienced 2 cybersecurity incidents.

Number of Peer and Competitor Companies

Mass General Brigham has an estimated 30,707 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Mass General Brigham ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Data Breach at Mass General Brigham Incorporated

Description: A data breach occurred due to human error where a file containing personal information, including names and Social Security numbers, was posted on a public website for a 14-hour period between November 23-24, 2020.

Date Detected: 2020-11-24

Date Publicly Disclosed: 2020-12-18

Type: Data Breach

Attack Vector: Human Error

Vulnerability Exploited: Improper Data Handling

Incident : Data Breach

Title: Data Breach at Mass General Brigham Health Plan

Description: The Vermont Office of the Attorney General reported on June 28, 2024, a data breach incident involving Mass General Brigham Health Plan (MGBHP) that may have allowed unauthorized access to members' personal information between July 31, 2023, and April 2, 2024. The exposed information potentially included names, addresses, medical record numbers, dates of birth, email addresses, phone numbers, health insurance policy numbers, and Social Security numbers.

Date Detected: 2024-06-28

Date Publicly Disclosed: 2024-06-28

Type: Data Breach

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach MAS844072325

Data Compromised: Names, Social security numbers

Incident : Data Breach MAS548072825

Data Compromised: Names, Addresses, Medical record numbers, Dates of birth, Email addresses, Phone numbers, Health insurance policy numbers, Social security numbers

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Social Security Numbers, , Names, Addresses, Medical Record Numbers, Dates Of Birth, Email Addresses, Phone Numbers, Health Insurance Policy Numbers, Social Security Numbers and .

Which entities were affected by each incident ?

Incident : Data Breach MAS844072325

Entity Name: Mass General Brigham Incorporated

Entity Type: Healthcare

Industry: Healthcare

Location: New Hampshire

Customers Affected: 179

Incident : Data Breach MAS548072825

Entity Name: Mass General Brigham Health Plan

Entity Type: Healthcare

Industry: Healthcare

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach MAS844072325

Type of Data Compromised: Names, Social security numbers

Number of Records Exposed: 179

Sensitivity of Data: High

Incident : Data Breach MAS548072825

Type of Data Compromised: Names, Addresses, Medical record numbers, Dates of birth, Email addresses, Phone numbers, Health insurance policy numbers, Social security numbers

Sensitivity of Data: High

References

Where can I find more information about each incident ?

Incident : Data Breach MAS844072325

Source: New Hampshire Attorney General's Office

Date Accessed: 2020-12-18

Incident : Data Breach MAS548072825

Source: Vermont Office of the Attorney General

Date Accessed: 2024-06-28

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: New Hampshire Attorney General's OfficeDate Accessed: 2020-12-18, and Source: Vermont Office of the Attorney GeneralDate Accessed: 2024-06-28.

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Data Breach MAS844072325

Root Causes: Human Error

Additional Questions

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2020-11-24.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-06-28.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Names, Social Security numbers, , names, addresses, medical record numbers, dates of birth, email addresses, phone numbers, health insurance policy numbers, Social Security numbers and .

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were health insurance policy numbers, medical record numbers, names, Names, dates of birth, Social Security numbers, addresses, phone numbers and email addresses.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 179.0.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident are Vermont Office of the Attorney General and New Hampshire Attorney General's Office.

cve

Latest Global CVEs (Not Company-Specific)

Description

Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763126988 and Tuleap Enterprise Edition prior to 17.0-3 and 16.13-8 have missing CSRF protections which allow attackers to create or remove tracker triggers. This issue is fixed in Tuleap Community Edition version 17.0.99.1763126988 and Tuleap Enterprise Edition versions 17.0-3 and 16.13-8.

Risk Information
cvss3
Base: 4.6
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Description

Tuleap is a free and open source suite for management of software development and collaboration. Tuleap Community Editon versions prior to 17.0.99.1762456922 and Tuleap Enterprise Edition versions prior to 17.0-2, 16.13-7 and 16.12-10 are vulnerable to CSRF attacks through planning management API. Attackers have access to create, edit or remove plans. This issue is fixed in Tuleap Community Edition version 17.0.99.1762456922 and Tuleap Enterprise Edtion versions 17.0-2, 16.13-7 and 16.12-10.

Risk Information
cvss3
Base: 4.6
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Description

Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versions below 17.0.99.1762444754 and Tuleap Enterprise Edition versions prior to 17.0-2, 16.13-7 and 16.12-10 allow attackers trick victims into changing tracker general settings. This issue is fixed in version Tuleap Community Edition version 17.0.99.1762444754 and Tuleap Enterprise Edition versions 17.0-2, 16.13-7 and 16.12-10.

Risk Information
cvss3
Base: 4.6
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Description

Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.1762431347 of Tuleap Community Edition and Tuleap Enterprise Edition below 17.0-2, 16.13-7 and 16.12-10 allow attackers to access file release system information in projects they do not have access to. This issue is fixed in version 17.0.99.1762431347 of the Tuleap Community Edition and versions 17.0-2, 16.13-7 and 16.12-10 of Tuleap Enterprise Edition.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description

IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation of resources without limits.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=mass-general-brigham' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge