Company Details
ssm-health-care
19,235
87,085
62
ssmhealth.com
19
SSM_7239795
Completed

SSM Health Company CyberSecurity Posture
ssmhealth.comSSM Health is a Catholic, not-for-profit, fully integrated health system dedicated to advancing innovative, sustainable, and compassionate care for patients and communities throughout the Midwest and beyond. The organization’s 40,000 team members and 13,900 providers are committed to fulfilling SSM Health’s Mission: “Through our exceptional health care services, we reveal the healing presence of God.” With care delivery sites in Illinois, Missouri, Oklahoma and Wisconsin, SSM Health includes hospitals, physician offices, outpatient and virtual care services, comprehensive home care and hospice services, a fully transparent pharmacy benefit company, a health insurance company and an accountable care organization. It is one of the largest employers in every community it serves. For more information, visit ssmhealth.com Visit jobs.ssmhealth.com to fulfill your calling with SSM Health. Together – We Care.
Company Details
ssm-health-care
19,235
87,085
62
ssmhealth.com
19
SSM_7239795
Completed
Between 700 and 749

SSM Health Global Score (TPRM)XXXX

Description: The U.S. Department of Health and Human Services reported that SSM Health Insurance Company experienced a data breach on December 11, 2020. This breach affected 4,492 individuals and involved paper/films. There was no business associate present during the breach.
Description: SSM Health Care Corporation, a major U.S. healthcare provider, was targeted in a cyberattack allegedly orchestrated by Owen Flowers, one of the two British teenagers charged in the UK for cybercrimes. The attack involved infiltration and attempted damage to SSM Health’s systems, potentially compromising sensitive healthcare data, operational integrity, or patient services. While the exact extent of the breach remains undisclosed, the involvement of a healthcare entity suggests high-risk exposure, including possible disruption to medical services, unauthorized access to patient records (e.g., personal, financial, or treatment-related data), or systemic outages. The attack’s connection to a broader campaign—including attempts against Sutter Health—highlights its coordinated and malicious nature. Given the critical role of healthcare infrastructure, such incidents can threaten patient safety, erode trust in the organization, and trigger regulatory penalties. The case’s international dimension (UK-US) and the defendants’ alleged ties to other high-profile attacks (e.g., Transport for London) underscore the severity of the threat.


SSM Health has 20.48% more incidents than the average of same-industry companies with at least one recorded incident.
SSM Health has 29.87% more incidents than the average of all companies with at least one recorded incident.
SSM Health reported 1 incidents this year: 1 cyber attacks, 0 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.
SSM Health cyber incidents detection timeline including parent company and subsidiaries

SSM Health is a Catholic, not-for-profit, fully integrated health system dedicated to advancing innovative, sustainable, and compassionate care for patients and communities throughout the Midwest and beyond. The organization’s 40,000 team members and 13,900 providers are committed to fulfilling SSM Health’s Mission: “Through our exceptional health care services, we reveal the healing presence of God.” With care delivery sites in Illinois, Missouri, Oklahoma and Wisconsin, SSM Health includes hospitals, physician offices, outpatient and virtual care services, comprehensive home care and hospice services, a fully transparent pharmacy benefit company, a health insurance company and an accountable care organization. It is one of the largest employers in every community it serves. For more information, visit ssmhealth.com Visit jobs.ssmhealth.com to fulfill your calling with SSM Health. Together – We Care.


Ramsay Health Care is a trusted provider of private hospital and healthcare services in Australia, Europe and the United Kingdom. Every year, millions of patients put their trust in Ramsay, confident in our ability to deliver safe, high-quality healthcare with outstanding clinical outcomes. We ope
About Aveanna It all started with a simple idea: How can we help people live better lives by providing better homecare? That idea became a company called Aveanna, dedicated to bringing new possibilities and new hope to those we serve. At Aveanna, we believe that the ultimate place for caring is rig

Bupa's purpose is helping people live longer, healthier, happier lives and making a better world. We are an international healthcare company serving over 38 million customers worldwide. With no shareholders, we reinvest profits into providing more and better healthcare for the benefit of current an

The University of Maryland Medical System (UMMS) was created in 1984 when the state-owned University Hospital became a private, nonprofit organization. It has evolved into a multi-hospital system with academic, community and specialty service missions reaching every part of the state and beyond. UM

Sanford Health is the largest rural health system in the U.S. Our organization is dedicated to transforming the health care experience and providing access to world-class health care in America’s heartland. Headquartered in Sioux Falls, South Dakota, we serve more than one million patients and 220,0

We are Erasmus MC. Our roots lie in Rotterdam, a city and port of international standing. We are the most innovative university medical center in the Netherlands and one of the world’s leading centers of scientific research. We are committed to achieving a healthy population and pursuing excellence

Express Scripts by Evernorth provides pharmacy benefits services with a clear mission: To simplify complexities and provide holistic, condition-focused care and clinically superior pharmacy benefit solutions for our clients and the people they serve. Guided by our core values of service, patient ca

BayCare is a leading not-for-profit academic health care system that connects individuals and families to a wide range of services at 16 hospitals, including a children’s hospital, and hundreds of other convenient locations throughout the Tampa Bay and central Florida regions. The system is West Cen
Johns Hopkins Medicine is a governing structure for the University’s School of Medicine and the health system, coordinating their research, teaching, patient care, and related enterprises. The Johns Hopkins Hospital opened in 1889, followed four years later by the university’s School of Medicine
.png)
An aging population and dated hospital rehab units are driving health systems to build rehab hospitals with joint-venture partners.
SSM Health agreed to a class action lawsuit settlement to resolve claims that it disclosed patients' private information to third parties without their...
It can be very overwhelming scrolling through job board after job board in search of a position that fits your wants and needs.
Cybersecurity failures are putting vulnerable hospitals at risk, prompting healthcare leaders to call for stronger national policies and...
An AHA blog published today highlights how SSM Health is confronting workplace violence with a comprehensive, team-based hospital safety...
Workplace violence prevention in health care has become one of the most urgent priorities for hospitals and health care systems nationwide.
The National Crime Agency has arrested and charged two suspected teenage members of the Scattered Spider cybercrime gang over the Transport...
Google patches sixth Chrome zero-day, Microsoft to force install Copilot app in October, Two more Scattered Spider teen suspects arrested.
Talha Jubair, 19, from London, is suspected of more than 120 cyberattacks, including attacks on Transport for London and American companies.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of SSM Health is http://www.ssmhealth.com.
According to Rankiteo, SSM Health’s AI-generated cybersecurity score is 742, reflecting their Moderate security posture.
According to Rankiteo, SSM Health currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, SSM Health is not certified under SOC 2 Type 1.
According to Rankiteo, SSM Health does not hold a SOC 2 Type 2 certification.
According to Rankiteo, SSM Health is not listed as GDPR compliant.
According to Rankiteo, SSM Health does not currently maintain PCI DSS compliance.
According to Rankiteo, SSM Health is not compliant with HIPAA regulations.
According to Rankiteo,SSM Health is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
SSM Health operates primarily in the Hospitals and Health Care industry.
SSM Health employs approximately 19,235 people worldwide.
SSM Health presently has no subsidiaries across any sectors.
SSM Health’s official LinkedIn profile has approximately 87,085 followers.
SSM Health is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
Yes, SSM Health has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/ssm-health-cardinal-glennon-children-s-hospital.
Yes, SSM Health maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/ssm-health-care.
As of December 12, 2025, Rankiteo reports that SSM Health has experienced 2 cybersecurity incidents.
SSM Health has an estimated 31,002 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack and Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with national crime agency (nca), and .
Title: SSM Health Insurance Data Breach
Description: The U.S. Department of Health and Human Services reported that SSM Health Insurance Company experienced a data breach due to unauthorized access/disclosure on December 11, 2020, affecting 4,492 individuals. The breach involved paper/films and did not have a business associate present.
Date Detected: 2020-12-11
Type: Data Breach
Attack Vector: Unauthorized Access/Disclosure
Title: Cyberattack on Transport for London (TfL) and Alleged Attacks on U.S. Healthcare Companies by British Teenagers
Description: Two British teenagers, Thalha Jubair (19) and Owen Flowers (18), were charged under the Computer Misuse Act for a cyberattack on Transport for London (TfL) in 2024. Flowers is also accused of conspiring to infiltrate and damage U.S. healthcare entities SSM Health Care Corporation and Sutter Health. Both pleaded not guilty in a U.K. court. The trial is scheduled for June 8, 2026, with both defendants remanded in custody. The U.S. DOJ has not publicly filed charges against Flowers, while charges against Jubair were unsealed in September 2024.
Date Publicly Disclosed: 2024-09
Type: cyberattack
Threat Actor: Thalha JubairOwen Flowers
Common Attack Types: The most common types of attacks the company has faced is Breach.

Brand Reputation Impact: potential reputational damage to TfLpotential reputational damage to SSM Health Care Corporationpotential reputational damage to Sutter Health
Legal Liabilities: Computer Misuse Act charges (U.K.)potential U.S. charges for healthcare attacks
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Paper/Films.

Entity Name: SSM Health Insurance Company
Entity Type: Health Insurance Company
Industry: Healthcare
Customers Affected: 4,492

Entity Name: Transport for London (TfL)
Entity Type: government agency
Industry: transportation
Location: London, U.K.

Entity Name: SSM Health Care Corporation
Entity Type: private organization
Industry: healthcare
Location: U.S.

Entity Name: Sutter Health
Entity Type: private organization
Industry: healthcare
Location: U.S.

Third Party Assistance: National Crime Agency (Nca).
Third-Party Assistance: The company involves third-party assistance in incident response through National Crime Agency (NCA), .

Type of Data Compromised: Paper/Films
Number of Records Exposed: 4,492

Regulations Violated: Computer Misuse Act (U.K.),
Legal Actions: criminal charges filed (U.K.), potential extradition or U.S. charges,
Ensuring Regulatory Compliance: The company ensures compliance with regulatory requirements through criminal charges filed (U.K.), potential extradition or U.S. charges, .

Source: U.S. Department of Health and Human Services

Source: The Record

Source: BBC (Neil Henderson)

Source: U.S. Department of Justice (unsealed charges for Jubair)
Date Accessed: 2024-09
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: U.S. Department of Health and Human Services, and Source: The Record, and Source: BBC (Neil Henderson), and Source: U.S. Department of Justice (unsealed charges for Jubair)Date Accessed: 2024-09.

Investigation Status: ongoing (trial scheduled for June 8, 2026)

High Value Targets: Tfl, Ssm Health Care Corporation, Sutter Health,
Data Sold on Dark Web: Tfl, Ssm Health Care Corporation, Sutter Health,
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as National Crime Agency (Nca), .
Last Attacking Group: The attacking group in the last incident was an Thalha JubairOwen Flowers.
Most Recent Incident Detected: The most recent incident detected was on 2020-12-11.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-09.
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was national crime agency (nca), .
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 4.5K.
Most Significant Legal Action: The most significant legal action taken for a regulatory violation was criminal charges filed (U.K.), potential extradition or U.S. charges, .
Most Recent Source: The most recent source of information about an incident are U.S. Department of Health and Human Services, The Record, BBC (Neil Henderson) and U.S. Department of Justice (unsealed charges for Jubair).
Current Status of Most Recent Investigation: The current status of the most recent investigation is ongoing (trial scheduled for June 8, 2026).
.png)
LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing errors; SyntaxError from express.json() includes user input in the error message, which gets reflected in responses. User input (including HTML/JavaScript) can be exposed in error responses, creating an XSS risk if Content-Type isn't strictly enforced. This issue does not have a fix at the time of publication.
LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests are sent to define and modify the prompts via PATCH endpoint for prompt groups (/api/prompts/groups/:groupId). However, the request bodies are not sufficiently validated for proper input, enabling users to modify prompts in a way that was not intended as part of the front end system. The patchPromptGroup function passes req.body directly to updatePromptGroup() without filtering sensitive fields. This issue is fixed in version 0.8.1.
LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the iconURL parameter of the POST request can be modified by an attacker. The malicious code is then stored in the chat which can then be shared to other users. When sharing chats with a potentially malicious “tracker”, resources loaded can lead to loss of privacy for users who view the chat link that is sent to them. This issue is fixed in version 0.8.1.
MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and other critical files, potentially resulting in privilege escalation. This issue is fixed in version 2.4.0.
MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.