Novant Health A.I CyberSecurity Scoring
Novant Health
Company Information
Website:http://www.novanthealth.org
Employees number:22,777
Number of followers:135,605
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:novanthealth.org
Novant Health Risk Score (AI oriented)
Between 650 and 699
Novant HealthHospitals and Health Care
Updated:
18/05/2026
18/05/2026
691/1000
Weak
B
Novant Health Global Score (TPRM)
xxxx
Novant HealthHospitals and Health Care
Score locked

Novant HealthWeak
Current Score
691B (WEAK)
01000
2 incidents
-70 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
692
MAY 2026
690
APRIL 2026
690
MARCH 2026
687
FEBRUARY 2026
686
JANUARY 2026
685
DECEMBER 2025
683
NOVEMBER 2025
750
Breach
25 Nov 2025 • Novant Health
Coastal Carolina Health Care, Western Orthopaedics and Florida Physician Specialists: Data breach exposes medical, financial, biometric data of 1.8 million
NYC Health and Hospitals Suffers Massive Data Breach Affecting 1.8 Million Individuals
680
CRITICAL-70
FLONORNOV1779136377
NYC Health and Hospitals Suffers Massive Data Breach Affecting 1.8 Million Individuals
New York City Health and Hospitals (NYCHH), the largest public health system in the U.S., has disclosed one of the most significant healthcare data breaches of 2026, exposing sensitive personal, medical, financial, and biometric information of at least 1.8 million individuals. The breach, detected on February 2, 2026, revealed unauthorized access to NYCHH systems between November 25, 2025, and February 11, 2026, with attackers exfiltrating files during that period.
The compromised data includes protected health information (PHI), identity documents, financial records, and biometric data, such as fingerprints and palm prints details that cannot be replaced if stolen. Affected individuals may have had Social Security numbers, driver’s license numbers, medical records, insurance details, billing information, and even precise geolocation data exposed. The breach’s scale and sensitivity make it one of the most consequential in recent years, given the irrevocable nature of biometric data.
NYCHH serves over a million New Yorkers, many of whom are uninsured or rely on public health programs like Medicaid. The organization has not identified the specific third-party vendor believed to be the initial entry point for the attack, though the incident aligns with a growing trend of healthcare breaches originating from compromised vendors. Hospitals increasingly depend on external partners for billing, electronic health records, and cybersecurity services, creating vulnerabilities when those vendors are breached.
The timeline of the attack raises concerns: despite detecting suspicious activity on February 2, the unauthorized access persisted until February 11, meaning attackers remained inside the system for 11 weeks and continued operations even after discovery. NYCHH has since implemented enhanced detection tools, credential resets, and updated remote access policies to prevent future intrusions.
This breach follows a string of major healthcare incidents in 2026, including breaches at Erie Family Health Centers (570,000 affected), Florida Physician Specialists (276,000), Coastal Carolina Health Care (110,000), and Western Orthopaedics (110,000), highlighting the persistent threat cybercriminals pose to the sector. NYCHH’s investigation remains ongoing, and the full scope of the exposure may evolve as the review of compromised files continues.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
749
SEPTEMBER 2025
749
AUGUST 2025
748
JULY 2025
747
AUGUST 2022
788
Breach
01 Aug 2022 • Novant Health
Novant Health
Novant Health Data Breach
713
CRITICAL-75
NOV13241022
Novant Health suffered a data breach that disclosed sensitive data, including email addresses, phone numbers, financial information - even doctor's appointment details of about 1.3 million patients.
Novant Health informed some of its patients following possible disclosure of protected health information (PHI) resulting from an incorrect configuration of a pixel, an online tracking tool.
The leaked data also potentially included computer IP addresses, emergency contact information, advanced care planning contacts, appointment types and dates, patients' physicians, and various information types into text boxes or selected from drop-down menus and buttons via its patient portal.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Novant Health ??
What was Novant Health's A.I Rankiteo Cyber Score in May 2026 ??
What was Novant Health's A.I Rankiteo Cyber Score in April 2026 ??
What was Novant Health's A.I Rankiteo Cyber Score in March 2026 ??
What was Novant Health's A.I Rankiteo Cyber Score in February 2026 ??
What was Novant Health's A.I Rankiteo Cyber Score in January 2026 ??
What was Novant Health's A.I Rankiteo Cyber Score in December 2025 ??
What was Novant Health's A.I Rankiteo Cyber Score in November 2025 ??
What was Novant Health's A.I Rankiteo Cyber Score in October 2025 ??
What was Novant Health's A.I Rankiteo Cyber Score in September 2025 ??
What was Novant Health's A.I Rankiteo Cyber Score in August 2025 ??
What was Novant Health's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Novant Health's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Novant Health ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Novant Health's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?