Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Rochester Regional Health

Rochester Regional Health Vendor Cyber Rating & Cyber Score

rochesterregional.org

Rochester Regional Health, headquartered in Rochester, NY, is an integrated health services organization serving the people of Western New York, the Finger Lakes, St. Lawrence County, and beyond. We are dedicated to helping our community stay healthy and live fulfilling lives. Together, we find the best way forward to where you want to be. From western to northern New York, rest assured; we’ve got you covered. We see you. We’re with you. We’re here to uplift you—to treat people, not symptoms. To treat you well. Our experience is nation-leading, neighbor-driven, and rooted in generations of real-life care. Today, we offer comprehensive care from 500+ locations, including 8 hospitals; more than 300 primary and specialty practices,


RRH A.I CyberSecurity Scoring

RRH
Company Information
Website:http://www.rochesterregional.org
Employees number:11,135
Number of followers:40,913
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:rochesterregional.org
RRH Risk Score (AI oriented)
Between 650 and 699
logo
RRHHospitals and Health Care
Updated:
16/06/2026
674/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
RRH Global Score (TPRM)
xxxx
logo
RRHHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

RRH
RRHWeak
Current Score
674B (WEAK)
01000
2 incidents
-66 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
677Before Incident
JULY 2026
676Before Incident
JUNE 2026
673Before Incident
MAY 2026
672Before Incident
APRIL 2026
670Before Incident
MARCH 2026
669Before Incident
FEBRUARY 2026
667Before Incident
JANUARY 2026
729Before Incident
Breach
01 Jan 2026RRH
Xsolis, Inc. and Rochester Regional Health: Rochester Regional Health data breach: Letters sent to 18,600 patients after third-party vendor Xsolis hack

Rochester Regional Health Patients Notified of Data Breach After Phishing Attack

663After Incident
CRITICAL-66
ROCXSO1781563504
Rochester Regional Health Patients Notified of Data Breach After Phishing Attack Rochester Regional Health has confirmed a data breach affecting approximately 18,600 patients following unauthorized access to a third-party vendor’s system. The incident stemmed from a phishing attack in January, potentially exposing personal and protected health information. Patients received notification letters from Xsolis, Inc., a former vendor whose services ended in 2021. However, the letters contained errors including an incorrect name, "Rochester Regional Medical Center" leading many recipients to dismiss them as scams. Social media reactions reflected widespread skepticism, with some patients discarding the notices before verifying their legitimacy. This is not the first breach for Rochester Regional Health, which experienced similar incidents in 2020 and 2023. In December, the health system secured $15 million in state funding to bolster its cybersecurity defenses. Cybersecurity experts, including Rochester Institute of Technology professor Jonathan Weissman, warned that stolen healthcare data can be exploited for medical fraud, identity theft, and targeted scams. Children’s information is particularly vulnerable, as misuse may go undetected for years. Xsolis stated the unauthorized activity has been contained, with no evidence of data misuse to date. Affected patients were offered free 12-month identity monitoring. Rochester Regional Health emphasized its commitment to patient data security, noting it holds partners to strict privacy standards. The health system has requested corrections to the erroneous notifications.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Personal and protected health informationSystems Affected: Third-party vendor (Xsolis, Inc.) systemCustomer Complaints: Widespread skepticism and dismissal of noticesBrand Reputation Impact: Negative social media reactions and skepticismIdentity Theft Risk: High (medical fraud, identity theft, targeted scams)
DATA BREACH
Type Of Data Compromised: Personal and protected health informationNumber Of Records Exposed: 18,600Sensitivity Of Data: High (health records, personally identifiable information)Personally Identifiable Information: Yes
DECEMBER 2025
729Before Incident
NOVEMBER 2025
728Before Incident
OCTOBER 2025
727Before Incident
SEPTEMBER 2025
727Before Incident
JANUARY 2025
778Before Incident
Breach
01 Jan 2025RRH
Xsolis and Rochester Regional Health: Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Rochester Regional Health Patients Receive Confusing Breach Notifications After Vendor Incident

718After Incident
CRITICAL-60
ROCXSO1781634267
Rochester Regional Health Patients Receive Confusing Breach Notifications After Vendor Incident Patients of Rochester Regional Health recently received mailed notifications regarding a data breach linked to a third-party vendor, Xsolis a case and utilization management services provider previously used by the healthcare system. The breach, discovered by the vendor, exposed sensitive patient information, though the hospital itself was not directly compromised. The notifications sparked confusion and skepticism among recipients due to several errors. The letters incorrectly identified the facility as "Rochester Regional Medical Center" instead of its proper name, Rochester Regional Health. Many recipients initially dismissed the notices as scams, particularly given the hospital’s history of prior breaches in 2020 and 2023. Rochester Regional Health later confirmed the legitimacy of the breach notifications, attributing the miscommunication to the vendor’s handling of the incident. The incident highlights ongoing challenges in third-party risk management and the importance of clear, accurate breach disclosures in maintaining patient trust.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Sensitive patient informationCustomer Complaints: Confusion and skepticism among recipientsBrand Reputation Impact: Negative impact due to errors in notifications and prior breach historyIdentity Theft Risk: Potential risk due to exposure of sensitive patient information
DATA BREACH
Type Of Data Compromised: Sensitive patient informationSensitivity Of Data: HighPersonally Identifiable Information: Likely included

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for RRH ?
?
What was RRH's A.I Rankiteo Cyber Score in July 2026 ?
?
What was RRH's A.I Rankiteo Cyber Score in June 2026 ?
?
What was RRH's A.I Rankiteo Cyber Score in May 2026 ?
?
What was RRH's A.I Rankiteo Cyber Score in April 2026 ?
?
What was RRH's A.I Rankiteo Cyber Score in March 2026 ?
?
What was RRH's A.I Rankiteo Cyber Score in February 2026 ?
?
What was RRH's A.I Rankiteo Cyber Score in January 2026 ?
?
What was RRH's A.I Rankiteo Cyber Score in December 2025 ?
?
What was RRH's A.I Rankiteo Cyber Score in November 2025 ?
?
What was RRH's A.I Rankiteo Cyber Score in October 2025 ?
?
What was RRH's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on RRH's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with RRH ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view RRH's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?