Comparison Overview

Montefiore Health System

VS

Bon Secours Mercy Health

Montefiore Health System

111 East 210th Street, None, Bronx, NY, US, 10467
Last Update: 2025-11-27
Between 750 and 799

Montefiore is one of New York’s premier academic health systems, renowned for its leading medical school, groundbreaking research and technology, and highly specialized, coordinated care for diverse populations in the New York region, across the country and globally. Visit Montefiore.org to learn more.

NAICS: 62
NAICS Definition: Health Care and Social Assistance
Employees: 11,269
Subsidiaries: 0
12-month incidents
0
Known data breaches
2
Attack type number
1

Bon Secours Mercy Health

Cincinnati, Ohio, US, 45237
Last Update: 2025-11-27
Between 750 and 799

On September 1, 2018 Bon Secours Health System and Mercy Health combined to become the United States’ fifth largest Catholic health care ministry and one of the nation’s 20 largest health care systems. With 48 hospitals, thousands of providers, over 1,000 points of care and over 60,000 employees Bon Secours Mercy Health serves communities across seven states and Ireland. We are dedicated to continually improving health care quality, safety and cost effectiveness. Our hospitals, care sites and clinicians are recognized for clinical and operational excellence. By utilizing robust measurement and reporting processes, we hold ourselves accountable for enhancing care and improving outcomes for our patients, residents and clients.

NAICS: 62
NAICS Definition: Health Care and Social Assistance
Employees: 30,908
Subsidiaries: 4
12-month incidents
0
Known data breaches
3
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/montefiore-health-system.jpeg
Montefiore Health System
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/bon-secours-mercy-health-system.jpeg
Bon Secours Mercy Health
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Montefiore Health System
100%
Compliance Rate
0/4 Standards Verified
Bon Secours Mercy Health
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Hospitals and Health Care Industry Average (This Year)

No incidents recorded for Montefiore Health System in 2025.

Incidents vs Hospitals and Health Care Industry Average (This Year)

No incidents recorded for Bon Secours Mercy Health in 2025.

Incident History — Montefiore Health System (X = Date, Y = Severity)

Montefiore Health System cyber incidents detection timeline including parent company and subsidiaries

Incident History — Bon Secours Mercy Health (X = Date, Y = Severity)

Bon Secours Mercy Health cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/montefiore-health-system.jpeg
Montefiore Health System
Incidents

Date Detected: 1/2017
Type:Breach
Attack Vector: Insider Threat
Motivation: Data Theft
Blog: Blog

Date Detected: 1/2013
Type:Breach
Attack Vector: Insider Threat
Motivation: Theft of Patient Account Information
Blog: Blog
https://images.rankiteo.com/companyimages/bon-secours-mercy-health-system.jpeg
Bon Secours Mercy Health
Incidents

Date Detected: 01/2020
Type:Breach
Attack Vector: Invoice Printing Error
Blog: Blog

Date Detected: 08/2016
Type:Breach
Blog: Blog

Date Detected: 4/2016
Type:Breach
Attack Vector: Inadvertent Exposure (Misconfigured Internet-Accessible Files)
Blog: Blog

FAQ

Bon Secours Mercy Health company demonstrates a stronger AI Cybersecurity Score compared to Montefiore Health System company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Bon Secours Mercy Health company has faced a higher number of disclosed cyber incidents historically compared to Montefiore Health System company.

In the current year, Bon Secours Mercy Health company and Montefiore Health System company have not reported any cyber incidents.

Neither Bon Secours Mercy Health company nor Montefiore Health System company has reported experiencing a ransomware attack publicly.

Both Bon Secours Mercy Health company and Montefiore Health System company have disclosed experiencing at least one data breach.

Neither Bon Secours Mercy Health company nor Montefiore Health System company has reported experiencing targeted cyberattacks publicly.

Neither Montefiore Health System company nor Bon Secours Mercy Health company has reported experiencing or disclosing vulnerabilities publicly.

Neither Montefiore Health System nor Bon Secours Mercy Health holds any compliance certifications.

Neither company holds any compliance certifications.

Bon Secours Mercy Health company has more subsidiaries worldwide compared to Montefiore Health System company.

Bon Secours Mercy Health company employs more people globally than Montefiore Health System company, reflecting its scale as a Hospitals and Health Care.

Neither Montefiore Health System nor Bon Secours Mercy Health holds SOC 2 Type 1 certification.

Neither Montefiore Health System nor Bon Secours Mercy Health holds SOC 2 Type 2 certification.

Neither Montefiore Health System nor Bon Secours Mercy Health holds ISO 27001 certification.

Neither Montefiore Health System nor Bon Secours Mercy Health holds PCI DSS certification.

Neither Montefiore Health System nor Bon Secours Mercy Health holds HIPAA certification.

Neither Montefiore Health System nor Bon Secours Mercy Health holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

Risk Information
cvss4
Base: 8.8
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

Risk Information
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

Risk Information
cvss3
Base: 5.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Description

File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Risk Information
cvss3
Base: 6.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L