Comparison Overview
Mercy

Mercy
15740 South Outer Forty Road, Chesterfield, 63017 , US
Last Update: 29/03/2026
Mercy, one of the 15 largest U.S. health systems and named the top large system in the U.S. for excellent patient experience by NRC Health, serves millions annually with nationally recognized care and one of the nation’s largest and highest performing Accountable Care O...

City of Hope
1500 E. Duarte Road, Duarte, CA, US, 91010
Last Update: 04/04/2026
City of Hope's mission is to deliver the cures of tomorrow to the people who need them today. Founded in 1913, City of Hope has grown into one of the largest cancer research and treatment organizations in the U.S. and one of the leading research centers for diabetes and...
Compliance Ranges Comparison

Mercy







City of Hope






Benchmark & Cyber Underwriting Signals
Incidents vs Hospitals and Health Care Industry Avg (This Year)
No incidents recorded for Mercy in 2026.
Incidents vs Hospitals and Health Care Industry Avg (This Year)
No incidents recorded for City of Hope in 2026.
Incident History - Mercy (X = Date, Y = Severity)
Mercy cyber incidents detection timeline including parent company and subsidiaries.
Incident History - City of Hope (X = Date, Y = Severity)
City of Hope cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Mercy

City of Hope
FAQ
Latest Global CVEs
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.