Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Trinity Health

Trinity Health Vendor Cyber Rating & Cyber Score

trinity-health.org

Trinity Health is one of the largest not-for-profit, Catholic health care systems in the nation. It is a family of 123,000 colleagues and nearly 27,000 physicians and clinicians caring for diverse communities across 26 states. Nationally recognized for care and experience, the Trinity Health system includes 88 hospitals, 135 continuing care locations, the second largest PACE program in the country, 136 urgent care locations and many other health and well-being services. Based in Livonia, Michigan, its annual operating revenue is $21.5 billion with $1.4 billion returned to its communities in the form of charity care and other community benefit programs.


Trinity Health A.I CyberSecurity Scoring

Trinity Health
Company Information
Website:http://www.trinity-health.org
Employees number:17,122
Number of followers:135,718
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:trinity-health.org
Trinity Health Risk Score (AI oriented)
Between 650 and 699
logo
Trinity HealthHospitals and Health Care
Updated:
04/04/2026
679/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Trinity Health Global Score (TPRM)
xxxx
logo
Trinity HealthHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Trinity Health
Trinity HealthWeak
Current Score
679B (WEAK)
01000
4 incidents
-51 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
686Before Incident
JULY 2026
684Before Incident
JUNE 2026
684Before Incident
MAY 2026
681Before Incident
APRIL 2026
680Before Incident
MARCH 2026
678Before Incident
FEBRUARY 2026
676Before Incident
JANUARY 2026
724Before Incident
Breach
13 Jan 2026Trinity Health
OCHIN, Mosaic, Reid Health and Trinity Health: Health Gorilla Data Breach Investigation

Health Gorilla Data Breach Exposes Sensitive Patient Information

673After Incident
CRITICAL-51
TRIMOSOCHREI1774651014
Health Gorilla Data Breach Exposes Sensitive Patient Information Health Gorilla, a Silicon Valley-based healthcare interoperability platform founded in 2014, is under investigation following a data breach that may have exposed sensitive patient information. The incident, disclosed on January 13, 2026, involved an unauthorized disclosure of health data through its health information exchange (HIE) network. The breach potentially compromised a wide range of personally identifiable information (PII) and medical records, including: - Names, dates of birth, and addresses - Driver’s license and insurance card details - Financial information - Clinical data (diagnoses, conditions, lab results, medications, and care plans) Health Gorilla reported that the data may have been accessed for treatment purposes, but investigators have not confirmed whether the requests or authorizations were legitimate. In response, the affected health organizations Mosaic, OCHIN, Reid Health, Trinity Health, and UMass Memorial Health were temporarily suspended from the HIE while the investigation continues. Class action law firm Shamis & Gentile P.A. is examining potential legal claims for affected individuals, who may be eligible for compensation. The full scope and impact of the breach remain under review.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Personally identifiable information (PII) and medical records, including names, dates of birth, addresses, driver’s license and insurance card details, financial information, and clinical data (diagnoses, conditions, lab results, medications, and care plans)Systems Affected: Health information exchange (HIE) networkOperational Impact: Temporary suspension of affected health organizations from the HIE networkLegal Liabilities: Potential legal claims being examined by class action law firm Shamis & Gentile P.A.Identity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Personally identifiable information (PII) and medical recordsSensitivity Of Data: High (includes clinical data, financial information, and personal identifiers)Personally Identifiable Information: Names, dates of birth, addresses, driver’s license and insurance card details, financial information
DECEMBER 2025
723Before Incident
NOVEMBER 2025
723Before Incident
OCTOBER 2025
721Before Incident
SEPTEMBER 2025
720Before Incident
DECEMBER 2022
717Before Incident
Breach
16 Dec 2022Trinity Health
Trinity Health: Trinity Health Data Breach Lawsuit Investigation

Trinity Health Data Breach Exposes Sensitive Patient Information

664After Incident
CRITICAL-53
TRI1773772378
Trinity Health Data Breach Exposes Sensitive Patient Information Trinity Health, one of the largest not-for-profit Catholic healthcare systems in the U.S., reported a data breach involving unauthorized access to sensitive patient information. The incident, discovered on January 5, 2023, occurred on December 16, 2022, and was linked to an automated Health Information Exchange (HIE). The breach stemmed from a request by Health Gorilla, an HIE member, for patient data under the guise of treatment purposes. However, Trinity Health’s HIE partner could not verify whether Health Gorilla or the recipient entities had proper authorization to access the information. Exposed data included driver’s licenses, medical records, clinical care details, insurance information, patient names, and other personally identifiable information (PII). The breach affected at least 51 individuals in Massachusetts, with potential impacts across Trinity Health’s network of 92 hospitals in 25 states. Trinity Health, headquartered in Livonia, Michigan, employs over 133,000 staff and serves millions of patients. The organization reported the breach to the Massachusetts and Vermont attorneys general in March 2026, though the delay between discovery and notification remains unclear. Legal firm Shamis & Gentile P.A. is investigating the incident, noting that affected individuals may be eligible for compensation. The breach highlights vulnerabilities in third-party data-sharing systems within healthcare.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Driver’s licenses, medical records, clinical care details, insurance information, patient names, and other PIISystems Affected: Health Information Exchange (HIE) systemBrand Reputation Impact: Potential reputational damage due to unauthorized data exposureLegal Liabilities: Potential legal actions and regulatory finesIdentity Theft Risk: High
DATA BREACH
Driver’s licensesMedical recordsClinical care detailsInsurance informationPatient namesPersonally identifiable information (PII)Number Of Records Exposed: At least 51 confirmed, potentially millionsSensitivity Of Data: HighPersonally Identifiable Information: Yes
JANUARY 2021
764Before Incident
Breach
01 Jan 2021Trinity Health
Trinity Health Corp.

Trinity Health Data Breach via Accellion File Transfer Appliance (January 2021)

678After Incident
CRITICAL-86
TRI1002810112025
Trinity Health Corp. experienced a data breach in January 2021 due to a vulnerability in the Accellion File Transfer Appliance, exposing sensitive patient data. The compromised information included names, addresses, emails, dates of birth, Social Security numbers, medical records (healthcare providers, services, lab results, medications, immunization types), payment details, credit card information, and claims data. Approximately 18,153 California residents were affected, leading to a $450,000 class-action settlement. Victims could claim up to $1,000 for out-of-pocket losses (e.g., identity theft, credit monitoring, card replacements) and a pro rata cash payment (ranging from $11 to $231, depending on claim participation). The breach stemmed from unauthorized access to patient files, raising concerns over inadequate data protection measures. While Trinity Health denied liability, the settlement addressed financial and reputational damages, including potential fraud risks for affected individuals.
INCIDENT DETAILS -
TYPE
Data BreachClass Action Settlement
MOTIVATION
Financial GainData Theft
IMPACT
Financial Loss: $450,000 (settlement fund)NamesAddressesEmailsDates of birthHealth care providersDates and types of health care servicesMedical record numbersImmunization typesLab resultsMedicationsPayments, payer names, and claims informationSocial Security numbersCredit card informationAccellion File Transfer Appliance (FTA)Customer Complaints: Class action lawsuit filed by affected individualsBrand Reputation Impact: Negative (class action settlement and public disclosure)Legal Liabilities: $450,000 settlement (including attorneys' fees, administration costs, and class member payments)Identity Theft Risk: High (SSNs, credit card info, and medical data exposed)Payment Information Risk: High (credit card information and payment details compromised)
DATA BREACH
Personally Identifiable Information (PII)Protected Health Information (PHI)Payment InformationNumber Of Records Exposed: 18,153 (California residents)Sensitivity Of Data: High (includes SSNs, medical records, and credit card info)Data Exfiltration: Yes (files accessed by unauthorized party)NamesAddressesEmailsDates of birthSocial Security numbersMedical record numbersCredit card information
APRIL 2020
786Before Incident
Cyber Attack
01 Apr 2020Trinity Health
Trinity Health

Data Breach at Trinity Health

760After Incident
HIGH-26
TRI913072725
The Maine Office of the Attorney General reported a data breach involving Trinity Health on October 23, 2020. The breach, reported to have occurred between April 18, 2020, and May 16, 2020, was due to a cyber-attack on Blackbaud's network, affecting 6,288 individuals, including at least 6 Maine residents, and compromising financial account details among other types of information.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
financial account detailsother types of information
DATA BREACH
financial account detailsother types of information

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Trinity Health ?
?
What was Trinity Health's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Trinity Health's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Trinity Health's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Trinity Health's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Trinity Health's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Trinity Health's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Trinity Health's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Trinity Health's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Trinity Health's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Trinity Health's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Trinity Health's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Trinity Health's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Trinity Health ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Trinity Health's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?