Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Nuance Communications

Nuance Communications Vendor Cyber Rating & Cyber Score

nuance.com

Nuance Communications is a technology pioneer with market leadership in conversational, ambient, and generative AI. A full-service partner trusted by 77 percent of U.S. hospitals and more than 75 percent of the Fortune 100 companies worldwide, Nuance creates intuitive solutions that amplify people's ability to help others. Nuance is a Microsoft company.


Nuance Communications A.I CyberSecurity Scoring

Nuance Communications
Company Information
Website:http://www.nuance.com
Employees number:3,973
Number of followers:153,889
NAICS:5112
Industry Type:Software Development
Homepage:nuance.com
Nuance Communications Risk Score (AI oriented)
Between 0 and 549
logo
Nuance CommunicationsSoftware Development
Updated:
02/04/2026
220/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Nuance Communications Global Score (TPRM)
xxxx
logo
Nuance CommunicationsSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Nuance Communications
Nuance CommunicationsCritical
Current Score
220C (CRITICAL)
01000
6 incidents
-128 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
246Before Incident
MAY 2026
234Before Incident
APRIL 2026
226Before Incident
MARCH 2026
214Before Incident
FEBRUARY 2026
328Before Incident
Breach
03 Feb 2026Nuance Communications
Microsoft, Nuance Communications and Geisinger Health System: Man accused in 2023 Geisinger data breach case faces more charges

Former Nuance Engineer Charged in 2023 Geisinger Health Data Breach Affecting 1.3 Million Patients

200After Incident
CRITICAL-128
GEINUAMIC1770196655
Former Nuance Engineer Charged in 2023 Geisinger Health Data Breach Affecting 1.3 Million Patients A California man, Max Vance (formerly Andre Burk), faces additional charges in connection with the 2023 data breach of Geisinger Health System, which exposed the personal and medical records of over 1.3 million patients. A superseding indictment filed in the U.S. Middle District Court on Tuesday accuses Vance of making false statements to FBI agents in January 2024, denying he had downloaded unauthorized data onto personal devices. Vance, a former principal healthcare interface engineer at Nuance Communications a Microsoft subsidiary providing IT services to hospitals was initially indicted in January 2024 for unauthorized access to a protected computer. Authorities allege that after being fired by Microsoft on November 27, 2023, for unrelated misconduct, Vance used his Nuance credentials to query Geisinger’s servers two days later. He extracted sensitive patient data, including names, dates of birth, addresses, medical record numbers, and treatment details, downloading it into two files before uploading them to his Microsoft Azure cloud account. The files were later transferred to his personal laptop and a Samsung hard drive, with evidence recovered during a search of his El Cajon apartment. Geisinger detected the breach on November 29, 2023, but delayed notifying affected patients until June 24, 2024, citing the need to avoid interfering with a federal investigation. The breach has since led to multiple civil lawsuits, including a class-action suit with preliminary approval of a $5 million settlement covering 1,308,363 individuals. Plaintiffs argue the delayed notification increased risks of identity theft. Vance, who legally changed his name in 2021 and relocated to California in 2022, is currently detained at Lycoming County Prison in Pennsylvania. Representing himself, he has filed motions challenging his detention and evidence admissibility. The case remains under federal investigation.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Unauthorized data exfiltration (potential financial gain or malicious intent)
IMPACT
Financial Loss: $5 million (settlement amount)Data Compromised: Personal and medical records of 1.3 million patientsSystems Affected: Geisinger Health System serversCustomer Complaints: Multiple civil lawsuits, including a class-action suitBrand Reputation Impact: Yes (delayed notification, identity theft risks)Legal Liabilities: Class-action lawsuit, potential regulatory finesIdentity Theft Risk: Increased risk due to exposure of PII and medical records
DATA BREACH
Personal Identifiable Information (PII)Medical recordsNumber Of Records Exposed: 1,308,363Sensitivity Of Data: High (names, dates of birth, addresses, medical record numbers, treatment details)Data Exfiltration: Yes (transferred to personal devices and cloud storage)Personally Identifiable Information: Yes (names, dates of birth, addresses, medical record numbers)
JANUARY 2026
327Before Incident
DECEMBER 2025
319Before Incident
NOVEMBER 2025
402Before Incident
OCTOBER 2025
301Before Incident
SEPTEMBER 2025
291Before Incident
AUGUST 2025
282Before Incident
JULY 2025
273Before Incident
JUNE 2024
258Before Incident
Breach
28 Jun 2024Nuance Communications
Geisinger Health and Nuance Communications: Stolen data complaint against Geisinger Health, Nuance Communications settled for $5M

$5 Million Settlement Approved in Geisinger-Nuance Medical Data Breach Affecting 1.3 Million Patients

130After Incident
CRITICAL-128
NUAGEI1773772921
$5 Million Settlement Approved in Geisinger-Nuance Medical Data Breach Affecting 1.3 Million Patients A Pennsylvania judge has approved a $5 million settlement resolving a class-action lawsuit against Geisinger Health and Nuance Communications following the theft of 1.3 million patient records by a former Nuance employee. The breach, which exposed sensitive data including names, birthdates, addresses, medical record numbers, treatment details, and insurance information stemmed from Geisinger’s partnership with Nuance, a Microsoft subsidiary specializing in AI-driven clinical documentation tools. The lawsuit was filed on June 28, 2024, with the settlement finalized earlier this month. While the agreement does not require either company to admit wrongdoing, it includes $30,000 in additional payments to cover litigation costs and awards for the five plaintiffs who initiated the case. Victims have until March 18 to file claims, though the exact payout per individual will depend on how many of the 1.3 million affected patients participate. As of March 5, only 97,000 victims had registered for direct cash compensation. Affected individuals may also opt for complimentary credit monitoring, though participation in the settlement class is required to access the benefit. Notably, there is no evidence that the stolen data has surfaced on the dark web or been misused. Geisinger, a nonprofit health system serving 45 Pennsylvania counties, operates 10 hospitals and 126 care sites, treating over 3 million patients annually. The breach highlights ongoing risks in third-party data handling within the healthcare sector.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $5,000,000 (settlement)Data Compromised: 1.3 million recordsBrand Reputation Impact: YesLegal Liabilities: Class-action lawsuitIdentity Theft Risk: Yes
DATA BREACH
NamesBirthdatesAddressesMedical record numbersTreatment detailsInsurance informationNumber Of Records Exposed: 1.3 millionSensitivity Of Data: HighPersonally Identifiable Information: Yes
NOVEMBER 2023
314Before Incident
Breach
29 Nov 2023Nuance Communications
Geisinger Health

Geisinger Health and Nuance Communications Patient Data Breach (2023)

185After Incident
CRITICAL-129
GEI5102451112125
A former employee of Nuance Communications (a Microsoft-owned IT services vendor) accessed Geisinger Health’s patient records without authorization two days after their employment termination on November 29, 2023. The breach exposed the personal and health information of over 1.3 million patients, including full names, dates of birth, addresses, medical record numbers, race, gender, phone numbers, facility abbreviations, Social Security numbers (SSNs), and health insurance details. Initially, Geisinger stated no financial or credit card data was compromised, but court documents later confirmed SSNs and sensitive medical information were exposed. The incident led to a $5 million class-action settlement, with affected patients eligible to file claims until March 2026. The former employee faces federal criminal charges for the unauthorized access, which occurred after law enforcement concluded its investigation. The breach severely undermined patient trust and triggered legal, financial, and reputational repercussions for Geisinger Health.
INCIDENT DETAILS -
TYPE
data breachinsider threatunauthorized access
MOTIVATION
unauthorized data accesspotential financial gain (unconfirmed)malicious intent
IMPACT
Financial Loss: $5 million (settlement amount)full namesdates of birthSocial Security numbers (SSNs)addressesadmit/discharge/transfer codesmedical record numbersrace and gender informationphone numbersfacility name abbreviationshealth insurance informationmedical informationGeisinger Health patient records systemclass action lawsuit filednegative publicityloss of patient trust$5 million settlementfederal charges against former employeehigh (due to SSN exposure)initially reported as not compromised, later confirmed as exposed (health insurance info)
DATA BREACH
personally identifiable information (PII)protected health information (PHI)financial information (health insurance details)Number Of Records Exposed: 1.3 millionSensitivity Of Data: high (includes SSNs, medical records, and insurance info)confirmed (data accessed by unauthorized former employee)full namesSSNsdates of birthaddressesphone numbersmedical record numbersrace/gender info
JUNE 2023
634Before Incident
Ransomware
16 Jun 2023Nuance Communications
Nuance Communications (Microsoft-owned)

Nuance MOVEit Transfer Data Breach Settlement

263After Incident
CRITICAL-371
NUA844081825
Nuance, a Microsoft subsidiary specializing in medical transcription and speech recognition, was ensnared in the 2023 Clop ransomware gang’s mass exploitation of the MOVEit Transfer vulnerability, a supply-chain attack affecting over 2,600 organizations and 77M+ individuals globally. The breach exposed 1.225 million people’s personal data from Nuance’s MOVEit environment, supplied by downstream healthcare providers. Plaintiffs in a class-action lawsuit alleged Nuance’s negligence in failing to implement 'reasonable security measures,' though the company denied liability, citing reliance on Progress Software’s widely used (but flawed) product and lack of direct contracts with affected individuals.Nuance settled for $8.5 million—covering compensation and credit-monitoring—despite insisting it acted swiftly (patching systems, taking MOVEit offline, and investigating). The healthcare sector’s heightened regulatory scrutiny and media attention amplified the fallout. While Nuance framed itself as a victim of the Clop campaign, the breach underscored systemic risks in third-party supply-chain dependencies. The settlement, though modest compared to other MOVEit-related payouts, reflects the growing legal and reputational costs of ransomware-driven data exfiltration in critical industries.
INCIDENT DETAILS -
TYPE
Data BreachSupply-Chain AttackClass Action Lawsuit
MOTIVATION
Financial GainData Theft for Extortion
IMPACT
Financial Loss: $8.5 million (settlement amount)Data Compromised: 1.225 million individuals' dataNuance's MOVEit Transfer environmentTemporary shutdown of MOVEit instance for patchingInvestigation and remediation effortsClass action lawsuit filed by affected individualsNegative media coverageRegulatory scrutiny due to healthcare data exposureClass action lawsuit settlementPotential regulatory fines (unconfirmed)High (due to exposed PII/PHI)
DATA BREACH
Personally Identifiable Information (PII)Protected Health Information (PHI)Number Of Records Exposed: 1,225,000Sensitivity Of Data: High (healthcare-related)Data Exfiltration: Yes (by Clop ransomware gang)Patient recordsMedical transcription data
Breach
16 Jun 2023Nuance Communications
Geisinger Health

Geisinger Health and Nuance Communications Data Breach (2023)

263After Incident
CRITICAL-371
GEI4702447112225
A Pennsylvania district court approved a $5 million settlement for a 2023 data breach at Geisinger Health, involving a former Nuance Communications employee (Nuance is now owned by Microsoft). The breach exposed over 1 million patients' sensitive data, including names, dates of birth, addresses, medical record numbers, race, gender, phone numbers, admit/discharge codes, and facility abbreviations. The employee, terminated just two days before the incident, accessed and potentially exfiltrated the data, leading to criminal charges and an ongoing federal investigation. Notification to affected patients was delayed per law enforcement’s request. The breach underscored insider threat risks in healthcare, with the consolidated class-action lawsuit highlighting reputational, financial, and legal repercussions. The final approval hearing is set for March 2026, with claims submissions due shortly after.
INCIDENT DETAILS -
TYPE
Data Breach (Insider Threat)
MOTIVATION
Financial GainUnauthorized Data Access
IMPACT
Financial Loss: $5 million (settlement)NamesDates of BirthAddressesMedical Record NumbersRaceGenderPhone NumbersAdmit/Discharge CodesFacility Name AbbreviationsCustomer Complaints: Class action lawsuit filedBrand Reputation Impact: Negative (publicized breach, legal action)Legal Liabilities: $5 million settlement, criminal charges against former employeeIdentity Theft Risk: High (PII exposed)
DATA BREACH
Personally Identifiable Information (PII)Protected Health Information (PHI)Number Of Records Exposed: 1,000,000+Sensitivity Of Data: High (medical and personal identifiers)Data Exfiltration: Potential (accessed and possibly obtained)NamesDates of BirthAddressesPhone NumbersMedical Record Numbers
JUNE 2023
768Before Incident
Breach
31 May 2023Nuance Communications
Nuance Communications Inc.

Nuance Communications MOVEit Data Breach (2023)

633After Incident
CRITICAL-135
NUA0103101101425
Nuance Communications Inc., a Microsoft subsidiary specializing in clinical support for healthcare organizations, experienced a data breach in May 2023 due to a vulnerability in the MOVEit file transfer software. Cybercriminals exploited this flaw, gaining unauthorized access to sensitive personal and protected health information (PHI) of an estimated 1,225,054 individuals between May 27 and May 31, 2023. The breach exposed data such as medical records, financial details, and personally identifiable information (PII), leading to risks of identity theft, fraud, and financial harm.The company agreed to an $8.5 million class-action settlement, offering affected individuals credit monitoring, identity theft protection, and reimbursements (up to $10,000 for documented losses). The incident highlighted Nuance’s alleged negligence in securing third-party software, resulting in prolonged legal and financial repercussions. The breach’s impact extended beyond financial losses, eroding trust in Nuance’s data protection capabilities, particularly in the healthcare sector, where PHI confidentiality is critical.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessThird-Party Vulnerability Exploitation
MOTIVATION
Financial GainData Theft
IMPACT
Financial Loss: $8.5 million (settlement fund)Personal InformationProtected Health Information (PHI)MOVEit file transfer softwareCustomer Complaints: Class action lawsuit filed by affected individualsBrand Reputation Impact: Negative (settlement and public disclosure of breach)Legal Liabilities: $8.5 million settlement, potential regulatory fines (undisclosed)Identity Theft Risk: High (credit monitoring and identity theft protection offered to victims)
DATA BREACH
Personal InformationProtected Health Information (PHI)Medical DataNumber Of Records Exposed: 1,225,054Sensitivity Of Data: High (includes PHI and personally identifiable information)Data Exfiltration: YesPersonally Identifiable Information: Yes (names, addresses, medical data, etc.)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Nuance Communications ?
?
What was Nuance Communications's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Nuance Communications's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Nuance Communications's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Nuance Communications's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Nuance Communications's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Nuance Communications's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Nuance Communications's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Nuance Communications's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Nuance Communications's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Nuance Communications's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Nuance Communications's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Nuance Communications's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Nuance Communications ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Nuance Communications's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Nuance Communications Cyber Scoring History | Rankiteo