Comparison Overview

Ochsner Health

VS

Sutter Health

Ochsner Health

1514 Jefferson Highway, None, New Orleans, Louisiana, US, 70121
Last Update: 2025-12-17

Ochsner Health is the leading nonprofit healthcare provider in the Gulf South, delivering expert care at its 46 hospitals and more than 370 health and urgent care centers. For 13 consecutive years, U.S. News & World Report has recognized Ochsner as the No. 1 hospital in Louisiana. Additionally, Ochsner Children’s has been recognized as the No. 1 hospital for kids in Louisiana for four consecutive years. Ochsner inspires healthier lives and stronger communities through a combination of standard-setting expertise, quality and digital connectivity not found anywhere else in the region. In 2024, Ochsner Health cared for more than 1.5 million people from every state in the nation and 63 countries. Ochsner’s workforce includes more than 40,000 dedicated team members and over 4,900 employed and affiliated physicians. To learn more about how Ochsner empowers people to get well and stay well, visit https://www.ochsner.org/. When Alton Ochsner and four other physicians opened New Orleans’ first group practice with multiple specialties in 1942, they envisioned providing people with the highest quality medical care, making sure patients received personalized and complete care. Ochsner is a healthcare system that always reaches out to the communities it serves and is a model for what a healthcare system should be. Learn more: https://www.youtube.com/watch?v=Dh-urNwAH9c

NAICS: 62
NAICS Definition: Health Care and Social Assistance
Employees: 16,836
Subsidiaries: 1
12-month incidents
0
Known data breaches
0
Attack type number
0

Sutter Health

2200 River Plaza Drive, None, Sacramento, California, US, 95833
Last Update: 2025-12-15
Between 650 and 699

Sutter Health is a not-for-profit, people-centered healthcare system providing comprehensive care throughout California. Sutter Health is committed to innovative, high-quality patient care and community partnerships, and innovative, high-quality patient care. Today, Sutter Health is pursuing a bold new plan to reach more people and make excellent healthcare more connected and accessible. The health system’s 57,000+ staff and clinicians and 12,000+ affiliated physicians currently serve more than 3 million patients with a focus on expanding opportunities to serve patients, people and communities better. Sutter Health provides exceptional, affordable care through its hospitals, medical groups, ambulatory surgery centers, urgent care clinics, telehealth, home health and hospice services. Dedicated to transforming healthcare, at Sutter Health, getting better never stops. Learn more about how Sutter Health is transforming healthcare at sutterhealth.org and vitals.sutterhealth.org.

NAICS: 62
NAICS Definition: Health Care and Social Assistance
Employees: 23,594
Subsidiaries: 0
12-month incidents
1
Known data breaches
5
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/ochsner-health-system-.jpeg
Ochsner Health
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/sutter-health.jpeg
Sutter Health
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Ochsner Health
100%
Compliance Rate
0/4 Standards Verified
Sutter Health
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Hospitals and Health Care Industry Average (This Year)

No incidents recorded for Ochsner Health in 2025.

Incidents vs Hospitals and Health Care Industry Average (This Year)

Sutter Health has 19.05% more incidents than the average of same-industry companies with at least one recorded incident.

Incident History — Ochsner Health (X = Date, Y = Severity)

Ochsner Health cyber incidents detection timeline including parent company and subsidiaries

Incident History — Sutter Health (X = Date, Y = Severity)

Sutter Health cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/ochsner-health-system-.jpeg
Ochsner Health
Incidents

No Incident

https://images.rankiteo.com/companyimages/sutter-health.jpeg
Sutter Health
Incidents

Date Detected: 6/2025
Type:Breach
Attack Vector: Website Tracking Technologies (Pixels, Cookies, Web Beacons, JavaScript)
Motivation: Data Collection for Marketing/Third-Party Use
Blog: Blog

Date Detected: 11/2023
Type:Breach
Attack Vector: Zero-day vulnerability in MOVEit Transfer programme
Blog: Blog

Date Detected: 5/2023
Type:Breach
Attack Vector: Exploitation of MOVEit Transfer Server Vulnerability
Blog: Blog

FAQ

Ochsner Health company demonstrates a stronger AI Cybersecurity Score compared to Sutter Health company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Sutter Health company has historically faced a number of disclosed cyber incidents, whereas Ochsner Health company has not reported any.

In the current year, Sutter Health company has reported more cyber incidents than Ochsner Health company.

Neither Sutter Health company nor Ochsner Health company has reported experiencing a ransomware attack publicly.

Sutter Health company has disclosed at least one data breach, while Ochsner Health company has not reported such incidents publicly.

Neither Sutter Health company nor Ochsner Health company has reported experiencing targeted cyberattacks publicly.

Neither Ochsner Health company nor Sutter Health company has reported experiencing or disclosing vulnerabilities publicly.

Neither Ochsner Health nor Sutter Health holds any compliance certifications.

Neither company holds any compliance certifications.

Ochsner Health company has more subsidiaries worldwide compared to Sutter Health company.

Sutter Health company employs more people globally than Ochsner Health company, reflecting its scale as a Hospitals and Health Care.

Neither Ochsner Health nor Sutter Health holds SOC 2 Type 1 certification.

Neither Ochsner Health nor Sutter Health holds SOC 2 Type 2 certification.

Neither Ochsner Health nor Sutter Health holds ISO 27001 certification.

Neither Ochsner Health nor Sutter Health holds PCI DSS certification.

Neither Ochsner Health nor Sutter Health holds HIPAA certification.

Neither Ochsner Health nor Sutter Health holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.

Risk Information
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description

Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.

Risk Information
cvss3
Base: 8.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description

A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms/libs/Ct_Config.php of the component Backend System Configuration Module. The manipulation of the argument Cj_Add/Cj_Edit results in code injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.

Risk Information
cvss2
Base: 5.8
Severity: LOW
AV:N/AC:L/Au:M/C:P/I:P/A:P
cvss3
Base: 4.7
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the component Backend App Configuration Module. The manipulation of the argument CT_App_Paytype leads to code injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Risk Information
cvss2
Base: 5.8
Severity: LOW
AV:N/AC:L/Au:M/C:P/I:P/A:P
cvss3
Base: 4.7
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.

Risk Information
cvss4
Base: 1.0
Severity: HIGH
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X