ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Prisma Health is the largest not-for-profit health organization in South Carolina, serving more than 1.2 million patients annually. Our facilities in the Greenville and Columbia surrounding markets are dedicated to improving the health of all South Carolinians through improved clinical quality, access to care and patient experience, while also addressing the rising cost of health care. Our Purpose: Inspire health. Serve with compassion. Be the difference.

Prisma Health A.I CyberSecurity Scoring

Prisma Health

Company Details

Linkedin ID:

prisma-health

Employees number:

12,865

Number of followers:

79,883

NAICS:

62

Industry Type:

Hospitals and Health Care

Homepage:

prismahealth.org

IP Addresses:

0

Company ID:

PRI_1565881

Scan Status:

In-progress

AI scorePrisma Health Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/prisma-health.jpeg
Prisma Health Hospitals and Health Care
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscorePrisma Health Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/prisma-health.jpeg
Prisma Health Hospitals and Health Care
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

Prisma Health Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Prisma HealthData Leak85310/2019
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: Prisma Health claims that staff members and volunteers at various hospitals in the Midlands have had their personal information posted online. An employee at Prisma Health had their login information stolen, which led to the discovery of the issue. Given that Prisma Health cited multiple dates for the theft, it is unclear from their statement if these were two incidences involving the same doctor or distinct doctors. Affected personal information includes a person's entire name, address, date of birth, and medical information. Social Security numbers and details about health insurance may have been impacted in some cases.

Prisma Health
Data Leak
Severity: 85
Impact: 3
Seen: 10/2019
Blog:
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: Prisma Health claims that staff members and volunteers at various hospitals in the Midlands have had their personal information posted online. An employee at Prisma Health had their login information stolen, which led to the discovery of the issue. Given that Prisma Health cited multiple dates for the theft, it is unclear from their statement if these were two incidences involving the same doctor or distinct doctors. Affected personal information includes a person's entire name, address, date of birth, and medical information. Social Security numbers and details about health insurance may have been impacted in some cases.

Ailogo

Prisma Health Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for Prisma Health

Incidents vs Hospitals and Health Care Industry Average (This Year)

No incidents recorded for Prisma Health in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Prisma Health in 2025.

Incident Types Prisma Health vs Hospitals and Health Care Industry Avg (This Year)

No incidents recorded for Prisma Health in 2025.

Incident History — Prisma Health (X = Date, Y = Severity)

Prisma Health cyber incidents detection timeline including parent company and subsidiaries

Prisma Health Company Subsidiaries

SubsidiaryImage

Prisma Health is the largest not-for-profit health organization in South Carolina, serving more than 1.2 million patients annually. Our facilities in the Greenville and Columbia surrounding markets are dedicated to improving the health of all South Carolinians through improved clinical quality, access to care and patient experience, while also addressing the rising cost of health care. Our Purpose: Inspire health. Serve with compassion. Be the difference.

Loading...
similarCompanies

Prisma Health Similar Companies

Inova Health

Inova is Northern Virginia’s leading nonprofit healthcare provider, offering world-class clinical excellence to everyone in our communities with a warm, human touch. Our 22,000+ team members collaborate to achieve individual and group health goals in partnership with every one of the 2M+ individuals

St. Luke's University Health Network

Founded in 1872, St. Luke’s University Health Network (SLUHN) is a fully integrated, regional, non-profit network of more than 23,000 employees providing services at 16 campuses and 350+ outpatient sites. With annual net revenue of $4 billion, the Network’s service area includes 11 counties in two s

Hospital for Special Surgery

HSS is the world’s leading academic medical center focused on musculoskeletal health. At its core is Hospital for Special Surgery, nationally ranked No. 1 in orthopedics (for the 16th consecutive year), No. 3 in rheumatology by U.S. News & World Report (2025-2026), and the best pediatric orthopedic

UnitedHealthcare

When it comes to your health, everything matters. That’s why UnitedHealthcare is helping people live healthier lives and making the health system work better for everyone. Our health plans are there for you in moments big and small, delivering a simple experience, affordable coverage, and supportive

Beth Israel Lahey Health

Beth Israel Lahey Health is a new, integrated system providing patients with better care wherever they are. Care informed by world-class research and education. We are doctors and nurses, technicians and social workers, innovators and educators, and so many others. All with a shared vision for what

UPMC is a world-renowned, nonprofit health care provider and insurer committed to delivering exceptional, people-centered care and community services. Headquartered in Pittsburgh and affiliated with the University of Pittsburgh Schools of the Health Sciences, UPMC is shaping the future of health thr

Adventist Health

Adventist Health is a faith-inspired, nonprofit integrated health system serving more than 100 communities on the West Coast and Hawaii with over 440 sites of care. Founded on Adventist heritage and values, Adventist Health provides care in hospitals, clinics, home care agencies, hospice agencies, a

OhioHealth

OhioHealth is a nationally recognized, not-for-profit, faith-based health system of more than 35,000 associates, providers and volunteers. We lead with our mission to improve the health of those we serve throughout our 16 hospitals and 200+ urgent, primary and specialty care sites spanning 50 Ohio c

One of the nation’s largest and most respected providers of hospital and healthcare services, Universal Health Services, Inc. (NYSE: UHS) has built an impressive record of achievement and performance, growing since its inception into a Fortune 300 corporation. Headquartered in King of Prussia, PA, U

newsone

Prisma Health CyberSecurity News

October 30, 2025 07:00 AM
PHOTOS: Prisma Health brings treats and fun to pediatric patients

Prisma Health Children's Hospital–Midlands held its annual Halloween “reverse trick-or-treat” parade for pediatric inpatients and their...

October 28, 2025 07:00 AM
Palo Alto Networks Secures the AI Agent Revolution with the Launch of Prisma AIRS 2.0

PRNewswire/ -- Palo Alto Networks (NASDAQ: PANW), the global cybersecurity leader, today announced Prisma® AIRS™ 2.0, a major platform...

October 28, 2025 07:00 AM
Palo Alto Networks launches AI-driven security offerings to tackle cyberattacks

Palo Alto Networks is expanding its artificial intelligence-powered cybersecurity offerings, as clients seek to secure their business...

October 22, 2025 07:00 AM
Prisma Health unveils $128M outpatient clinic in Northeast Columbia

Prisma Health has officially opened its new $128 million Northeast Medical Park in Columbia, marking a significant expansion in outpatient...

October 02, 2025 07:00 AM
Richland One and Prisma Health offer free flu shots in Midlands

Richland One is partnering with Prisma Health to offer free flu shots across the Midlands starting in October.The flu shot clinics,...

September 11, 2025 07:00 AM
Prisma Health launches new sickle cell clinics in South Carolina

GREENVILLE, S.C. - Prisma Health has launched two new clinics in South Carolina to provide care for sickle cell patients.

September 05, 2025 07:00 AM
Sustaining Life during a ”Digital Darkness” Event

Recording available The Role of IT and Engineering in Safeguarding Patient Care during an Emergency Overview A healthcare organization's...

August 22, 2025 07:00 AM
Cybersecurity firms’ revenue zooms as hospitals adopt AI-driven defenses

In the spring of 2025, DaVita Inc., one of the largest dialysis providers in the United States, found itself at the center of a digital...

July 29, 2025 07:00 AM
Siemens Healthineers, Prisma Health Expand Value Partnership with $50 Million Investment in Radiation Therapy

Siemens Healthineers and Prisma Health expand Value Partnership to improve cancer care in South Carolina and Tennessee, including Ethos...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Prisma Health CyberSecurity History Information

Official Website of Prisma Health

The official website of Prisma Health is http://careers.prismahealth.org.

Prisma Health’s AI-Generated Cybersecurity Score

According to Rankiteo, Prisma Health’s AI-generated cybersecurity score is 768, reflecting their Fair security posture.

How many security badges does Prisma Health’ have ?

According to Rankiteo, Prisma Health currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Prisma Health have SOC 2 Type 1 certification ?

According to Rankiteo, Prisma Health is not certified under SOC 2 Type 1.

Does Prisma Health have SOC 2 Type 2 certification ?

According to Rankiteo, Prisma Health does not hold a SOC 2 Type 2 certification.

Does Prisma Health comply with GDPR ?

According to Rankiteo, Prisma Health is not listed as GDPR compliant.

Does Prisma Health have PCI DSS certification ?

According to Rankiteo, Prisma Health does not currently maintain PCI DSS compliance.

Does Prisma Health comply with HIPAA ?

According to Rankiteo, Prisma Health is not compliant with HIPAA regulations.

Does Prisma Health have ISO 27001 certification ?

According to Rankiteo,Prisma Health is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Prisma Health

Prisma Health operates primarily in the Hospitals and Health Care industry.

Number of Employees at Prisma Health

Prisma Health employs approximately 12,865 people worldwide.

Subsidiaries Owned by Prisma Health

Prisma Health presently has no subsidiaries across any sectors.

Prisma Health’s LinkedIn Followers

Prisma Health’s official LinkedIn profile has approximately 79,883 followers.

NAICS Classification of Prisma Health

Prisma Health is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.

Prisma Health’s Presence on Crunchbase

Yes, Prisma Health has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/prisma-health-d097.

Prisma Health’s Presence on LinkedIn

Yes, Prisma Health maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/prisma-health.

Cybersecurity Incidents Involving Prisma Health

As of November 27, 2025, Rankiteo reports that Prisma Health has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Prisma Health has an estimated 30,007 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Prisma Health ?

Incident Types: The types of cybersecurity incidents that have occurred include Data Leak.

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Prisma Health Data Breach

Description: Prisma Health reported that personal information of staff members and volunteers at various hospitals in the Midlands has been posted online due to stolen login information of an employee.

Type: Data Breach

Attack Vector: Stolen Credentials

Vulnerability Exploited: Stolen Login Information

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Data Leak.

How does the company identify the attack vectors used in incidents ?

Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Stolen Login Information.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach PRI33923423

Data Compromised: Full name, Address, Date of birth, Medical information, Social security numbers, Health insurance details

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Information, Medical Information, Health Insurance Details and .

Which entities were affected by each incident ?

Incident : Data Breach PRI33923423

Entity Name: Prisma Health

Entity Type: Healthcare Provider

Industry: Healthcare

Location: Midlands

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach PRI33923423

Type of Data Compromised: Personal information, Medical information, Health insurance details

Sensitivity of Data: High

Personally Identifiable Information: Full NameAddressDate of BirthSocial Security Numbers

Initial Access Broker

How did the initial access broker gain entry for each incident ?

Incident : Data Breach PRI33923423

Entry Point: Stolen Login Information

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Data Breach PRI33923423

Root Causes: Stolen Login Information

Additional Questions

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Full Name, Address, Date of Birth, Medical Information, Social Security Numbers, Health Insurance Details and .

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Date of Birth, Social Security Numbers, Medical Information, Health Insurance Details, Full Name and Address.

Initial Access Broker

What was the most recent entry point used by an initial access broker ?

Most Recent Entry Point: The most recent entry point used by an initial access broker was an Stolen Login Information.

cve

Latest Global CVEs (Not Company-Specific)

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.

Risk Information
cvss4
Base: 7.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=prisma-health' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge