ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Empowering our clients with cutting edge technology to meet future healthcare needs today. Meditab, a leading software solutions company, founded in 1998 has been continuously changing the landscape of healthcare delivery through forward-thinking, innovative collaborations, exceptional service, and best-in-class technology. Our mission is simple -- to create the most advanced, intuitive technology solutions that enable healthcare providers to practice better medicine. We are unyielding in our effort to develop superior products that remain relevant and diversify how healthcare is delivered beyond the office. At Meditab, we strive to maximize productivity and live to invent a new age of healthcare, where technology fuels better quality of care for patients. Request a demo: https://www.meditab.com/demo

Meditab Software Inc. A.I CyberSecurity Scoring

MSI

Company Details

Linkedin ID:

meditab-software-inc-

Employees number:

612

Number of followers:

19,343

NAICS:

5415

Industry Type:

IT Services and IT Consulting

Homepage:

meditab.com

IP Addresses:

0

Company ID:

MED_2127421

Scan Status:

In-progress

AI scoreMSI Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/meditab-software-inc-.jpeg
MSI IT Services and IT Consulting
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreMSI Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/meditab-software-inc-.jpeg
MSI IT Services and IT Consulting
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

MSI Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Meditab Software Inc.Breach10053/2019
Rankiteo Explanation :
Attack threatening the organization’s existence

Description: Meditab Software Inc. suffered a massive breach of protected health information on March 2019. The data revealed contained highly sensitive information such as names, addresses, dates of birth, insurance information, payment information, Social Security numbers, doctor’s notes, prescription details, diagnoses, lab test results, and medical histories. After being alerted to the breach, the fax server was taken offline, and an investigation was launched to identify the cause of the breach. It is unclear how long the server was left unprotected and how many patients have been affected by the breach.

Meditab Software Inc.
Breach
Severity: 100
Impact: 5
Seen: 3/2019
Blog:
Rankiteo Explanation
Attack threatening the organization’s existence

Description: Meditab Software Inc. suffered a massive breach of protected health information on March 2019. The data revealed contained highly sensitive information such as names, addresses, dates of birth, insurance information, payment information, Social Security numbers, doctor’s notes, prescription details, diagnoses, lab test results, and medical histories. After being alerted to the breach, the fax server was taken offline, and an investigation was launched to identify the cause of the breach. It is unclear how long the server was left unprotected and how many patients have been affected by the breach.

Ailogo

MSI Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for MSI

Incidents vs IT Services and IT Consulting Industry Average (This Year)

No incidents recorded for Meditab Software Inc. in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Meditab Software Inc. in 2025.

Incident Types MSI vs IT Services and IT Consulting Industry Avg (This Year)

No incidents recorded for Meditab Software Inc. in 2025.

Incident History — MSI (X = Date, Y = Severity)

MSI cyber incidents detection timeline including parent company and subsidiaries

MSI Company Subsidiaries

SubsidiaryImage

Empowering our clients with cutting edge technology to meet future healthcare needs today. Meditab, a leading software solutions company, founded in 1998 has been continuously changing the landscape of healthcare delivery through forward-thinking, innovative collaborations, exceptional service, and best-in-class technology. Our mission is simple -- to create the most advanced, intuitive technology solutions that enable healthcare providers to practice better medicine. We are unyielding in our effort to develop superior products that remain relevant and diversify how healthcare is delivered beyond the office. At Meditab, we strive to maximize productivity and live to invent a new age of healthcare, where technology fuels better quality of care for patients. Request a demo: https://www.meditab.com/demo

Loading...
similarCompanies

MSI Similar Companies

CACI International Inc

At CACI International Inc (NYSE: CACI), our 25,000 talented and dynamic employees are ever vigilant in delivering distinctive expertise and technology to meet our customers’ greatest challenges in national security. We are a company of good character, relentless innovation, and long-standing excelle

Sopra Steria, a major Tech player in Europe with 51,000 employees in nearly 30 countries, is recognised for its consulting, digital services and solutions. It helps its clients drive their digital transformation and obtain tangible and sustainable benefits. The Group provides end-to-end solutions to

inDrive

inDrive is a global mobility and urban services platform. The inDrive app has been downloaded over 360 million times, and has been the second most downloaded mobility app for the third consecutive year. In addition to ride-hailing, inDrive provides an expanding list of urban services, including inte

Amadeus

We make the experience of travel better for everyone, everywhere by inspiring innovation, partnerships and responsibility to people, places and planet. Our technology powers the travel and tourism industry. We inspire more connected ways of thinking, centered around the traveler. Our platform c

GlobalLogic Latinoamérica

GlobalLogic, una empresa del grupo Hitachi, es líder en ingeniería digital en Latinoamérica. Ayudamos a diferentes marcas a diseñar y crear productos, plataformas y experiencias digitales innovadoras para el mundo moderno. Al integrar el diseño de experiencia, la ingeniería compleja y la exper

Tech Mahindra

Tech Mahindra offers technology consulting and digital solutions to global enterprises across industries, enabling transformative scale at unparalleled speed. With 150,000+ professionals across 90+ countries helping 1100+ clients, TechM provides a full spectrum of services including consulting, info

Mastercard

Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re building a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Ou

TD SYNNEX North America

We’re TD SYNNEX (NYSE: SNX), a leading distributor and solutions aggregator for the IT ecosystem. We’re 22,000 of the IT industry’s best and brightest, who share an unwavering passion for bringing compelling technology products, services and solutions to the world. We’re an innovative partner that

Infinite Computer Solutions

Infinite is a global leader in technology modernization, next-gen IT services and solutions, and digital engineering, with over two decades of experience helping clients turn digital transformation into business value. Leveraging an AI-first approach, we combine leading technologies, innovative plat

newsone

MSI CyberSecurity News

March 19, 2019 07:00 AM
Potentially Massive Breach of Protected Health Information Discovered

Sacramento, CA-based medical software provider Meditab Software Inc., and it's San Juan, PR-based affiliate, MedPharm Services have suffered a massive breach...

March 17, 2019 07:00 AM
A huge trove of medical records and prescriptions found exposed

A health tech company was leaking thousands of doctor's notes, medical records, and prescriptions daily after a security lapse left a server without a password.

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

MSI CyberSecurity History Information

Official Website of Meditab Software Inc.

The official website of Meditab Software Inc. is http://www.meditab.com.

Meditab Software Inc.’s AI-Generated Cybersecurity Score

According to Rankiteo, Meditab Software Inc.’s AI-generated cybersecurity score is 741, reflecting their Moderate security posture.

How many security badges does Meditab Software Inc.’ have ?

According to Rankiteo, Meditab Software Inc. currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Meditab Software Inc. have SOC 2 Type 1 certification ?

According to Rankiteo, Meditab Software Inc. is not certified under SOC 2 Type 1.

Does Meditab Software Inc. have SOC 2 Type 2 certification ?

According to Rankiteo, Meditab Software Inc. does not hold a SOC 2 Type 2 certification.

Does Meditab Software Inc. comply with GDPR ?

According to Rankiteo, Meditab Software Inc. is not listed as GDPR compliant.

Does Meditab Software Inc. have PCI DSS certification ?

According to Rankiteo, Meditab Software Inc. does not currently maintain PCI DSS compliance.

Does Meditab Software Inc. comply with HIPAA ?

According to Rankiteo, Meditab Software Inc. is not compliant with HIPAA regulations.

Does Meditab Software Inc. have ISO 27001 certification ?

According to Rankiteo,Meditab Software Inc. is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Meditab Software Inc.

Meditab Software Inc. operates primarily in the IT Services and IT Consulting industry.

Number of Employees at Meditab Software Inc.

Meditab Software Inc. employs approximately 612 people worldwide.

Subsidiaries Owned by Meditab Software Inc.

Meditab Software Inc. presently has no subsidiaries across any sectors.

Meditab Software Inc.’s LinkedIn Followers

Meditab Software Inc.’s official LinkedIn profile has approximately 19,343 followers.

NAICS Classification of Meditab Software Inc.

Meditab Software Inc. is classified under the NAICS code 5415, which corresponds to Computer Systems Design and Related Services.

Meditab Software Inc.’s Presence on Crunchbase

No, Meditab Software Inc. does not have a profile on Crunchbase.

Meditab Software Inc.’s Presence on LinkedIn

Yes, Meditab Software Inc. maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/meditab-software-inc-.

Cybersecurity Incidents Involving Meditab Software Inc.

As of December 18, 2025, Rankiteo reports that Meditab Software Inc. has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Meditab Software Inc. has an estimated 38,003 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Meditab Software Inc. ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

How does Meditab Software Inc. detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an containment measures with fax server taken offline, and remediation measures with investigation launched..

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Meditab Software Inc. Data Breach

Description: Meditab Software Inc. suffered a massive breach of protected health information in March 2019. The data revealed contained highly sensitive information such as names, addresses, dates of birth, insurance information, payment information, Social Security numbers, doctor’s notes, prescription details, diagnoses, lab test results, and medical histories.

Date Detected: March 2019

Type: Data Breach

Attack Vector: Fax Server Vulnerability

Vulnerability Exploited: Unprotected Fax Server

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach MED65512323

Data Compromised: Names, Addresses, Dates of birth, Insurance information, Payment information, Social security numbers, Doctor’s notes, Prescription details, Diagnoses, Lab test results, Medical histories

Systems Affected: Fax Server

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Information, Health Information, Financial Information and .

Which entities were affected by each incident ?

Incident : Data Breach MED65512323

Entity Name: Meditab Software Inc.

Entity Type: Company

Industry: Healthcare Software

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Breach MED65512323

Containment Measures: Fax server taken offline

Remediation Measures: Investigation launched

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach MED65512323

Type of Data Compromised: Personal information, Health information, Financial information

Sensitivity of Data: High

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Investigation launched, .

How does the company handle incidents involving personally identifiable information (PII) ?

Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by fax server taken offline and .

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Data Breach MED65512323

Investigation Status: Ongoing

Additional Questions

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on March 2019.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were names, addresses, dates of birth, insurance information, payment information, Social Security numbers, doctor’s notes, prescription details, diagnoses, lab test results, medical histories and .

Response to the Incidents

What containment measures were taken in the most recent incident ?

Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Fax server taken offline.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were payment information, lab test results, dates of birth, doctor’s notes, insurance information, medical histories, names, Social Security numbers, addresses, diagnoses and prescription details.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.

cve

Latest Global CVEs (Not Company-Specific)

Description

Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication middleware is not properly applied to API endpoints. This results in certain API endpoints being accessible without valid session credentials. This is dangerous for those who have exposed Zerobyte to be used outside of their internal network. A fix has been applied in both version 0.19.0 and 0.18.5. If immediate upgrade is not possible, restrict network access to the Zerobyte instance to trusted networks only using firewall rules or network segmentation. This is only a temporary mitigation; upgrading is strongly recommended.

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF) vulnerability exists in the application's filter configuration. The CSRF protection mechanism was **explicitly disabled**, allowing the application to process state-changing requests (POST) without verifying a valid CSRF token. An unauthenticated remote attacker can exploit this by hosting a malicious web page. If a logged-in administrator visits this page, their browser is forced to send unauthorized requests to the application. A successful exploit allows the attacker to silently create a new Administrator account with full privileges, leading to a complete takeover of the system and loss of confidentiality, integrity, and availability. The vulnerability has been patched in version 3.4.2. The fix re-enables the CSRF filter in `app/Config/Filters.php` and resolves associated AJAX race conditions by adjusting token regeneration settings. As a workaround, administrators can manually re-enable the CSRF filter in `app/Config/Filters.php` by uncommenting the protection line. However, this is not recommended without applying the full patch, as it may cause functionality breakage in the Sales module due to token synchronization issues.

Risk Information
cvss3
Base: 8.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Model Context Protocol (MCP) configurations from the `settings.json` file located within a project’s `.zed` subdirectory. A malicious MCP configuration can contain arbitrary shell commands that run on the host system with the privileges of the user running the IDE. This can be triggered automatically without any user interaction besides opening the project in the IDE. Version 0.218.2-pre fixes the issue by implementing worktree trust mechanism. As a workaround, users should carefully review the contents of project settings files (`./zed/settings.json`) before opening new projects in Zed.

Risk Information
cvss3
Base: 7.7
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Description

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Language Server Protocol (LSP) configurations from the `settings.json` file located within a project’s `.zed` subdirectory. A malicious LSP configuration can contain arbitrary shell commands that run on the host system with the privileges of the user running the IDE. This can be triggered when a user opens project file for which there is an LSP entry. A concerted effort by an attacker to seed a project settings file (`./zed/settings.json`) with malicious language server configurations could result in arbitrary code execution with the user's privileges if the user opens the project in Zed without reviewing the contents. Version 0.218.2-pre fixes the issue by implementing worktree trust mechanism. As a workaround, users should carefully review the contents of project settings files (`./zed/settings.json`) before opening new projects in Zed.

Risk Information
cvss3
Base: 7.7
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Description

Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 and prior to versions 7.6.21, 8.6.15, 9.1.17, and 10.1.10 relates to Storybook’s handling of environment variables defined in a `.env` file, which could, in specific circumstances, lead to those variables being unexpectedly bundled into the artifacts created by the `storybook build` command. When a built Storybook is published to the web, the bundle’s source is viewable, thus potentially exposing those variables to anyone with access. For a project to potentially be vulnerable to this issue, it must build the Storybook (i.e. run `storybook build` directly or indirectly) in a directory that contains a `.env` file (including variants like `.env.local`) and publish the built Storybook to the web. Storybooks built without a `.env` file at build time are not affected, including common CI-based builds where secrets are provided via platform environment variables rather than `.env` files. Storybook runtime environments (i.e. `storybook dev`) are not affected. Deployed applications that share a repo with your Storybook are not affected. Users should upgrade their Storybook—on both their local machines and CI environment—to version .6.21, 8.6.15, 9.1.17, or 10.1.10 as soon as possible. Maintainers additionally recommend that users audit for any sensitive secrets provided via `.env` files and rotate those keys. Some projects may have been relying on the undocumented behavior at the heart of this issue and will need to change how they reference environment variables after this update. If a project can no longer read necessary environmental variable values, either prefix the variables with `STORYBOOK_` or use the `env` property in Storybook’s configuration to manually specify values. In either case, do not include sensitive secrets as they will be included in the built bundle.

Risk Information
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=meditab-software-inc-' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge