RRH A.I CyberSecurity Scoring
RRH
Company Information
Website:http://www.rochesterregional.org
Employees number:11,135
Number of followers:40,913
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:rochesterregional.org
RRH Risk Score (AI oriented)
Between 650 and 699
RRHHospitals and Health Care
Updated:
16/06/2026
16/06/2026
674/1000
Weak
B
RRH Global Score (TPRM)
xxxx
RRHHospitals and Health Care
Score locked

RRHWeak
Current Score
674B (WEAK)
01000
2 incidents
-66 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
677
JULY 2026
676
JUNE 2026
673
MAY 2026
672
APRIL 2026
670
MARCH 2026
669
FEBRUARY 2026
667
JANUARY 2026
729
Breach
01 Jan 2026 • RRH
Xsolis, Inc. and Rochester Regional Health: Rochester Regional Health data breach: Letters sent to 18,600 patients after third-party vendor Xsolis hack
Rochester Regional Health Patients Notified of Data Breach After Phishing Attack
663
CRITICAL-66
ROCXSO1781563504
Rochester Regional Health Patients Notified of Data Breach After Phishing Attack
Rochester Regional Health has confirmed a data breach affecting approximately 18,600 patients following unauthorized access to a third-party vendor’s system. The incident stemmed from a phishing attack in January, potentially exposing personal and protected health information.
Patients received notification letters from Xsolis, Inc., a former vendor whose services ended in 2021. However, the letters contained errors including an incorrect name, "Rochester Regional Medical Center" leading many recipients to dismiss them as scams. Social media reactions reflected widespread skepticism, with some patients discarding the notices before verifying their legitimacy.
This is not the first breach for Rochester Regional Health, which experienced similar incidents in 2020 and 2023. In December, the health system secured $15 million in state funding to bolster its cybersecurity defenses.
Cybersecurity experts, including Rochester Institute of Technology professor Jonathan Weissman, warned that stolen healthcare data can be exploited for medical fraud, identity theft, and targeted scams. Children’s information is particularly vulnerable, as misuse may go undetected for years. Xsolis stated the unauthorized activity has been contained, with no evidence of data misuse to date.
Affected patients were offered free 12-month identity monitoring. Rochester Regional Health emphasized its commitment to patient data security, noting it holds partners to strict privacy standards. The health system has requested corrections to the erroneous notifications.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
729
NOVEMBER 2025
728
OCTOBER 2025
727
SEPTEMBER 2025
727
JANUARY 2025
778
Breach
01 Jan 2025 • RRH
Xsolis and Rochester Regional Health: Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation
Rochester Regional Health Patients Receive Confusing Breach Notifications After Vendor Incident
718
CRITICAL-60
ROCXSO1781634267
Rochester Regional Health Patients Receive Confusing Breach Notifications After Vendor Incident
Patients of Rochester Regional Health recently received mailed notifications regarding a data breach linked to a third-party vendor, Xsolis a case and utilization management services provider previously used by the healthcare system. The breach, discovered by the vendor, exposed sensitive patient information, though the hospital itself was not directly compromised.
The notifications sparked confusion and skepticism among recipients due to several errors. The letters incorrectly identified the facility as "Rochester Regional Medical Center" instead of its proper name, Rochester Regional Health. Many recipients initially dismissed the notices as scams, particularly given the hospital’s history of prior breaches in 2020 and 2023.
Rochester Regional Health later confirmed the legitimacy of the breach notifications, attributing the miscommunication to the vendor’s handling of the incident. The incident highlights ongoing challenges in third-party risk management and the importance of clear, accurate breach disclosures in maintaining patient trust.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for RRH ??
What was RRH's A.I Rankiteo Cyber Score in July 2026 ??
What was RRH's A.I Rankiteo Cyber Score in June 2026 ??
What was RRH's A.I Rankiteo Cyber Score in May 2026 ??
What was RRH's A.I Rankiteo Cyber Score in April 2026 ??
What was RRH's A.I Rankiteo Cyber Score in March 2026 ??
What was RRH's A.I Rankiteo Cyber Score in February 2026 ??
What was RRH's A.I Rankiteo Cyber Score in January 2026 ??
What was RRH's A.I Rankiteo Cyber Score in December 2025 ??
What was RRH's A.I Rankiteo Cyber Score in November 2025 ??
What was RRH's A.I Rankiteo Cyber Score in October 2025 ??
What was RRH's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on RRH's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with RRH ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view RRH's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?