Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
OSF HealthCare

OSF HealthCare Vendor Cyber Rating & Cyber Score

osfhealthcare.org

OSF HealthCare is an integrated health system founded by The Sisters of the Third Order of St. Francis and headquartered in Peoria, Illinois. The system includes 18 inpatient facilities encompassing 16 licensed hospitals, two of which operate dual campuses in separate communities. Among these hospitals, 10 are acute care facilities, five are critical access hospitals and one is a continuing care facility. OSF has 2,141 licensed beds throughout Illinois and Michigan. OSF employs more than 27,000 Mission Partners across 170+ locations. These include OSF HealthCare Children’s Hospital of Illinois, the third largest pediatric hospital in the state, and OSF OnCall, its digital health operating entity that offers hospital-at-home care. In


OSF HealthCare A.I CyberSecurity Scoring

OSF HealthCare
Company Information
Website:http://www.osfhealthcare.org
Employees number:12,514
Number of followers:47,984
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:osfhealthcare.org
OSF HealthCare Risk Score (AI oriented)
Between 650 and 699
logo
OSF HealthCareHospitals and Health Care
Updated:
05/04/2026
658/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
OSF HealthCare Global Score (TPRM)
xxxx
logo
OSF HealthCareHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

OSF HealthCare
OSF HealthCareWeak
Current Score
658B (WEAK)
01000
4 incidents
-53 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
665Before Incident
JUNE 2026
664Before Incident
MAY 2026
660Before Incident
APRIL 2026
660Before Incident
MARCH 2026
657Before Incident
FEBRUARY 2026
655Before Incident
JANUARY 2026
653Before Incident
DECEMBER 2025
662Before Incident
NOVEMBER 2025
660Before Incident
OCTOBER 2025
658Before Incident
SEPTEMBER 2025
693Before Incident
Breach
01 Sep 2025OSF HealthCare
OSF HealthCare, Cerner and OSF Saint Clare Medical Center: Data breach exposes sensitive patient information across multiple OSF facilities

OSF Healthcare Patient Data Breach via Former Vendor Cerner

640After Incident
CRITICAL-53
OSFCEROSF1766606283
Cybersecurity Incident at OSF HealthCare Exposes Patient Data via Former Vendor Cerner OSF HealthCare disclosed a cybersecurity incident involving its former electronic health record (EHR) vendor, Cerner, which may have exposed sensitive patient information. The breach, detected in September, stemmed from unauthorized access to legacy Cerner systems as early as January 2024. While OSF confirmed the incident did not affect its own systems or hospital operations, it impacted multiple healthcare facilities, though only patients of OSF Saint Clare Medical Center in Princeton were formally notified. Cerner, which no longer provides services to OSF, identified the breach and launched an investigation, securing the compromised systems and engaging external cybersecurity experts. Law enforcement requested a delay in notifying affected parties to avoid interfering with the probe. OSF began notifying patients in November after Cerner completed a data review, providing a list of individuals whose information may have been accessed. Exposed data includes patient names, Social Security numbers, medical record details (such as diagnoses, medications, test results, and treatment information), and physician names. As a precaution, OSF and Cerner are offering two years of complimentary credit monitoring and identity restoration services to affected patients. The incident highlights broader vulnerabilities in third-party healthcare IT systems, with Cerner confirming the breach extended beyond OSF facilities.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Patient names, Social Security numbers, medical record numbers, physicians, diagnoses, medications, test results, images, and details related to care and treatmentSystems Affected: Legacy Cerner systemsOperational Impact: No impact on hospital operationsIdentity Theft Risk: High (due to exposure of SSNs and medical records)
DATA BREACH
Personal Identifiable Information (PII)Protected Health Information (PHI)Sensitivity Of Data: HighPersonally Identifiable Information: Names, Social Security numbers, medical record numbers, diagnoses, medications, test results, images, and treatment details
AUGUST 2025
693Before Incident
JANUARY 2025
696Before Incident
Cyber Attack
01 Jan 2025OSF HealthCare
Cerner, OSF Healthcare and OSF Saint Clare Medical Center: Hospital cyberattacks grow more sophisticated as AI lowers barriers, putting patient data at risk

Cyberattack on OSF Healthcare Exposes Patient Data Across Northern Illinois

679After Incident
CRITICAL-17
CEROSF1771973986
Cyberattack on OSF Healthcare Exposes Patient Data Across Northern Illinois In late December 2025, OSF Saint Clare Medical Center in Princeton disclosed a data breach affecting its medical records system provider, Cerner. The incident, first detected in January 2025, involved unauthorized access to sensitive patient information, including names, Social Security numbers, medical records, diagnoses, medications, and test results. Law enforcement requested a delay in notifying patients until September to avoid interfering with the investigation. OSF later confirmed that multiple facilities were impacted, though further details remain undisclosed. The breach highlights a growing trend of cyberattacks targeting healthcare systems, driven by their complex IT infrastructure, 24/7 operational demands, and the high stakes of downtime where even an hour offline can disrupt surgeries, patient portals, and critical test results. Cybersecurity experts, including Jon Pisani of PSM Partners, note that hospitals’ interconnected systems and urgency to restore services make them prime targets for ransomware and data theft. The rise of AI has further lowered the barrier for attackers, enabling faster data parsing and more efficient exploitation of vulnerabilities. However, AI tools used by employees can also introduce risks if sensitive information is inadvertently exposed on public platforms. Human error remains a key entry point for cybercriminals, with phishing emails often serving as the initial attack vector. Once inside, hackers may monitor communications, alter emails, or exfiltrate data before demanding ransom. Unlike ransomware, which can be mitigated with backups, data leaks pose long-term risks, as stolen information may be publicly disseminated even after systems are restored. In response, hospitals are adopting layered security measures, such as zero-trust models, restricted access, and continuous monitoring. Morris Hospital, which experienced a similar breach in 2023, implemented additional safeguards and offered free identity monitoring to affected individuals. Both OSF and Morris provided credit monitoring services and advised patients to monitor financial and medical records for suspicious activity. While healthcare systems continue to bolster defenses, experts caution that cybersecurity is an evolving challenge. As Pisani noted, new threats emerge as old vulnerabilities are addressed, ensuring that hospitals with their vast stores of valuable data will remain persistent targets.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Theft
IMPACT
Data Compromised: Sensitive patient information, including names, Social Security numbers, medical records, diagnoses, medications, and test resultsSystems Affected: Medical records system (Cerner)Operational Impact: Disruption to surgeries, patient portals, and critical test resultsBrand Reputation Impact: HighIdentity Theft Risk: High
DATA BREACH
Personally Identifiable InformationMedical RecordsSensitivity Of Data: HighData Exfiltration: YesNamesSocial Security Numbers
OCTOBER 2021
724Before Incident
Ransomware
01 Oct 2021OSF HealthCare
OSF HealthCare

Data Exfiltration at OSF Healthcare

611After Incident
CRITICAL-113
OSF22412822
OSF Healthcare in Illinois was attacked and data was exfiltrated from their systems by threat actor Xing Team. Xing Team started dumping patients data which apparently belonged to 53,907 OSF patients. The dumped data included patient names and contact information; dates of birth; Social Security numbers; driver’s license numbers; state or government identification numbers; treatment and diagnosis information and codes; physician names, dates of service, hospital units, prescription information and medical record numbers; and Medicare, Medicaid or other health insurance information. OSF Healthcare offered complimentary credit monitoring and identity protection services through Experian.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
patient namescontact informationdates of birthSocial Security numbersdriver’s license numbersstate or government identification numberstreatment and diagnosis information and codesphysician namesdates of servicehospital unitsprescription informationmedical record numbersMedicareMedicaid or other health insurance information
DATA BREACH
patient namescontact informationdates of birthSocial Security numbersdriver’s license numbersstate or government identification numberstreatment and diagnosis information and codesphysician namesdates of servicehospital unitsprescription informationmedical record numbersMedicareMedicaid or other health insurance informationSensitivity Of Data: High
MAY 2021
778Before Incident
Data Leak
01 May 2021OSF HealthCare
OSF HealthCare

OSF HealthCare Data Breach

719After Incident
CRITICAL-59
OSF19491222
OSF HealthCare is committed to protecting the security and privacy of patient information suffered from a data breach incident after an unauthorized party gained access to their systems. The compromised information includes Dates of birth, Social Security numbers, driver's license numbers, state or government identification numbers, codes for diagnoses and treatments, names of the treating physicians, dates of their services, hospital units, prescription information, and medical records numbers, as well as Medicare, Medicaid, or other insurance information, are all examples of patient data. Financial account information, credit or debit card information, or login credentials for an online financial account were also present in the files involved in the incident for a smaller group of patients. They took this incident seriously and took preventive steps.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Dates of birthSocial Security numbersDriver's license numbersState or government identification numbersCodes for diagnoses and treatmentsNames of the treating physiciansDates of their servicesHospital unitsPrescription informationMedical records numbersMedicare, Medicaid, or other insurance informationFinancial account informationCredit or debit card informationLogin credentials for an online financial account
DATA BREACH
Personal InformationMedical InformationFinancial InformationSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for OSF HealthCare ?
?
What was OSF HealthCare's A.I Rankiteo Cyber Score in June 2026 ?
?
What was OSF HealthCare's A.I Rankiteo Cyber Score in May 2026 ?
?
What was OSF HealthCare's A.I Rankiteo Cyber Score in April 2026 ?
?
What was OSF HealthCare's A.I Rankiteo Cyber Score in March 2026 ?
?
What was OSF HealthCare's A.I Rankiteo Cyber Score in February 2026 ?
?
What was OSF HealthCare's A.I Rankiteo Cyber Score in January 2026 ?
?
What was OSF HealthCare's A.I Rankiteo Cyber Score in December 2025 ?
?
What was OSF HealthCare's A.I Rankiteo Cyber Score in November 2025 ?
?
What was OSF HealthCare's A.I Rankiteo Cyber Score in October 2025 ?
?
What was OSF HealthCare's A.I Rankiteo Cyber Score in September 2025 ?
?
What was OSF HealthCare's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on OSF HealthCare's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with OSF HealthCare ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view OSF HealthCare's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?