Comparison Overview

OSF HealthCare

VS

Cardinal Health

OSF HealthCare

124 SW Adams St, Peoria, 61602, US
Last Update: 2026-01-17
Between 650 and 699

OSF HealthCare is an integrated health system founded by The Sisters of the Third Order of St. Francis. Headquartered in Peoria, Illinois, OSF HealthCare has 17 hospitals – 11 acute care, five critical access and one continuing care – with 2,305 licensed beds throughout Illinois and Michigan. OSF employs more than 26,000 Mission Partners across 171 locations; has two colleges of nursing; operates OSF Home Care Services, an extensive network of home health and hospice services; owns Pointcore, Inc., comprised of health care-related businesses; OSF HealthCare Foundation, the philanthropic arm for the organization; and OSF Ventures, which provides investment capital for promising health care innovation startups. In 2020, OSF OnCall was established as a digital health operating unit and includes a hospital-at-home program. OSF OnCall delivers care and services when, where and how patients prefer to receive them. OSF HealthCare has been recognized by Fortune as one of the most innovative companies in the country. OSF consistently earns recognition for showing dedication to the well-being of its Mission Partners: •America’s Best-in-State Employers | Forbes Magazine | 2018-2025 •150 Top Places to Work in Healthcare | Becker’s Healthcare | 2019, 2022-2025 •Best Employers for Women | Forbes Magazine | 2020 OSF HealthCare is an Equal Opportunity Employer (EOE). By engaging with this page, you acknowledge and agree to follow our social media terms of use, which you can find here: https://www.osfhealthcare.org/patients-visitors/terms-conditions/social-terms

NAICS: 62
NAICS Definition: Health Care and Social Assistance
Employees: 12,123
Subsidiaries: 2
12-month incidents
0
Known data breaches
1
Attack type number
3

Cardinal Health

7000 Cardinal Place, Dublin, OH, US, 43017
Last Update: 2026-01-21
Between 800 and 849

Cardinal Health is a distributor of pharmaceuticals and specialty products; a supplier of home-health and direct-to-patient products and services; an operator of nuclear pharmacies and manufacturing facilities; a provider of performance and data solutions; and a global manufacturer and distributor of medical and laboratory products. Our company’s customer-centric focus drives continuous improvement and leads to innovative solutions that improve people’s lives every day. Disclaimer: LinkedIn is a third-party site unaffiliated with Cardinal Health. Cardinal Health is not responsible for the privacy or security policies or practices on LinkedIn or on any of the third-party websites that we may link to through LinkedIn. You should carefully review the privacy and security practices of LinkedIn and linked third-party websites. We do not necessarily endorse any information found here nor are we responsible for the accuracy of any information, opinions, claims, or advice found here or shared here by our followers. By posting content, ideas, or pictures, you grant Cardinal Health a non-exclusive, royalty-free, perpetual, and worldwide license to use your content and any images posted by you, including the rights to copy, distribute, transmit, display, reproduce, edit, translate, and reformat, and incorporate into a collective work. Cardinal Health reserves all rights relating to the company's LinkedIn account, including removing postings and prohibiting individuals from participating on the page.

NAICS: 62
NAICS Definition: Health Care and Social Assistance
Employees: 34,491
Subsidiaries: 2
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/osf-healthcare.jpeg
OSF HealthCare
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/cardinal-health.jpeg
Cardinal Health
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
OSF HealthCare
100%
Compliance Rate
0/4 Standards Verified
Cardinal Health
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Hospitals and Health Care Industry Average (This Year)

No incidents recorded for OSF HealthCare in 2026.

Incidents vs Hospitals and Health Care Industry Average (This Year)

No incidents recorded for Cardinal Health in 2026.

Incident History — OSF HealthCare (X = Date, Y = Severity)

OSF HealthCare cyber incidents detection timeline including parent company and subsidiaries

Incident History — Cardinal Health (X = Date, Y = Severity)

Cardinal Health cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/osf-healthcare.jpeg
OSF HealthCare
Incidents

Date Detected: 9/2025
Type:Breach
Attack Vector: Unauthorized third-party access
Blog: Blog

Date Detected: 10/2021
Type:Ransomware
Blog: Blog

Date Detected: 05/2021
Type:Data Leak
Blog: Blog
https://images.rankiteo.com/companyimages/cardinal-health.jpeg
Cardinal Health
Incidents

No Incident

FAQ

Cardinal Health company demonstrates a stronger AI Cybersecurity Score compared to OSF HealthCare company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

OSF HealthCare company has historically faced a number of disclosed cyber incidents, whereas Cardinal Health company has not reported any.

In the current year, Cardinal Health company and OSF HealthCare company have not reported any cyber incidents.

OSF HealthCare company has confirmed experiencing a ransomware attack, while Cardinal Health company has not reported such incidents publicly.

OSF HealthCare company has disclosed at least one data breach, while the other Cardinal Health company has not reported such incidents publicly.

Neither Cardinal Health company nor OSF HealthCare company has reported experiencing targeted cyberattacks publicly.

Neither OSF HealthCare company nor Cardinal Health company has reported experiencing or disclosing vulnerabilities publicly.

Neither OSF HealthCare nor Cardinal Health holds any compliance certifications.

Neither company holds any compliance certifications.

Both Cardinal Health company and OSF HealthCare company have a similar number of subsidiaries worldwide.

Cardinal Health company employs more people globally than OSF HealthCare company, reflecting its scale as a Hospitals and Health Care.

Neither OSF HealthCare nor Cardinal Health holds SOC 2 Type 1 certification.

Neither OSF HealthCare nor Cardinal Health holds SOC 2 Type 2 certification.

Neither OSF HealthCare nor Cardinal Health holds ISO 27001 certification.

Neither OSF HealthCare nor Cardinal Health holds PCI DSS certification.

Neither OSF HealthCare nor Cardinal Health holds HIPAA certification.

Neither OSF HealthCare nor Cardinal Health holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Risk Information
cvss3
Base: 9.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Description

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

Risk Information
cvss3
Base: 9.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description

Azure Entra ID Elevation of Privilege Vulnerability

Risk Information
cvss3
Base: 9.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Description

Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, instances configured with the "ldap" component enabled are vulnerable to LDAP search filter injection techniques via the login endpoint. The 401 error response message can be used to determine whether or not a search was successful, allowing for brute force methods to discover LDAP entries on the server such as user IDs and user attributes. This issue has been fixed in version 0.10.0.

Risk Information
cvss4
Base: 2.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server. Versions 3.7.0 and above allow an authenticated user to execute arbitrary system commands on the host server by injecting shell metacharacters into backup filenames. The BackupManager fails to sanitize the filenames of uploaded backups. The system persists user-uploaded files directly to the host filesystem using the raw originalname provided in the request. This allows an attacker to stage a file containing shell metacharacters (e.g., $(id).tar.gz) at a predictable path, which is later referenced during the restore process. The successful storage of the file is what allows the subsequent restore command to reference and execute it. This issue has been fixed in version 4.7.0.

Risk Information
cvss3
Base: 8.0
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H