Company Details
vcu-health-system
11,234
56,401
62
careers.vcuhealth.org
23
VCU_9776794
Completed

VCU Health Company CyberSecurity Posture
careers.vcuhealth.orgWe are a strong, passionate team of more than 12,500 who take pride in caring for every person who comes through our doors. We lift each other up so we can provide the very best and safest care to those who need us most. Together. Every day. With the support of our university, we make up an academic medical center committed to excellence in patient care, innovation and training tomorrow’s health care workforce. We continue to educate, research and evolve – staying on the cutting edge of care. As a community of innovators, every team member can contribute a spark of ingenuity igniting a force to discover the next cure, hold the next hand, solve the greatest challenges and create the health care of tomorrow. We foster an atmosphere of respect and welcoming for all communities. We infuse our teams with diverse talent that inspires everyone to contribute openly and freely, maximizing their impact and creating meaningful change for our patients and community. Join our team and help us create a new kind of patient experience. Join VCU Health. EEO Statement: VCU Health System strictly prohibits and does not tolerate discrimination against, or harassment of, team members, applicants, or any other covered persons because of age, race, ethnicity, religion, culture, language, physical or mental disability, socioeconomic status, sex (sexual orientation, gender identity or expression and pregnancy), protected veteran status, marital status, genetic information, or any other protected characteristics under applicable federal, state, or local law. Pay Transparency Provisions: VCU Health System complies with the Pay Transparency Provisions.
Company Details
vcu-health-system
11,234
56,401
62
careers.vcuhealth.org
23
VCU_9776794
Completed
Between 700 and 749

VCU Health Global Score (TPRM)XXXX

Description: Virginia Commonwealth University Health System suffered from a data breach incident, 2,700 people's minor child’s electronic medical records unwarranted accesses were made to their medical records. According to an investigation, certain community physician groups' workers and an employee of a contracted vendor gained access to patient service information at the VCU Health System without having valid business grounds. The incidences led to the individual employers firing the workers.
Description: VCU Health System notified about 4,700 individuals that their or their minor child’s electronic health information was inappropriately accessed. There is no indication that the private health information has been or will be used for any malicious purposes.
Description: VCU Health System experienced a cyber attack for the second time which was reported by a patient that it's personal information has been compromised. It was found that clinical information, name, social security number, diagnosis and medications” had been inappropriately accessed by an employee. The client notified the Health system through a letter about the security breach.


No incidents recorded for VCU Health in 2025.
No incidents recorded for VCU Health in 2025.
No incidents recorded for VCU Health in 2025.
VCU Health cyber incidents detection timeline including parent company and subsidiaries

We are a strong, passionate team of more than 12,500 who take pride in caring for every person who comes through our doors. We lift each other up so we can provide the very best and safest care to those who need us most. Together. Every day. With the support of our university, we make up an academic medical center committed to excellence in patient care, innovation and training tomorrow’s health care workforce. We continue to educate, research and evolve – staying on the cutting edge of care. As a community of innovators, every team member can contribute a spark of ingenuity igniting a force to discover the next cure, hold the next hand, solve the greatest challenges and create the health care of tomorrow. We foster an atmosphere of respect and welcoming for all communities. We infuse our teams with diverse talent that inspires everyone to contribute openly and freely, maximizing their impact and creating meaningful change for our patients and community. Join our team and help us create a new kind of patient experience. Join VCU Health. EEO Statement: VCU Health System strictly prohibits and does not tolerate discrimination against, or harassment of, team members, applicants, or any other covered persons because of age, race, ethnicity, religion, culture, language, physical or mental disability, socioeconomic status, sex (sexual orientation, gender identity or expression and pregnancy), protected veteran status, marital status, genetic information, or any other protected characteristics under applicable federal, state, or local law. Pay Transparency Provisions: VCU Health System complies with the Pay Transparency Provisions.


University Health Network (UHN) is Canada's largest research hospital, which includes Toronto General and Toronto Western Hospitals, Princess Margaret Cancer Centre, the Toronto Rehabilitation Institute and the Michener Institute for Education at UHN. The scope of research and complexity of cases at

SARquavitae, personas que cuidan a las personas SARquavitae es la mayor plataforma de España de servicios sanitarios y sociales de atención a las personas. La plantilla, formada por 12.200 profesionales, ofrece más de 10.900 plazas repartidas por todo el territorio español y atiende a unas 200.0

The NHS was launched in 1948. It was born out of a long-held ideal that good healthcare should be available to all, regardless of wealth – one of the NHS's core principles. With the exception of some charges, such as prescriptions, optical services and dental services, the NHS in England remains

Cencora, a company building on the legacy of AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving the lives of people and animals around the world. We connect manufacturers, providers, and patients to ensure that anyone can get the therapies they need, w

As a world-class academic and health care system, Duke Health strives to transform medicine and health locally and globally through innovative scientific research, rapid translation of breakthrough discoveries, educating future clinical and scientific leaders, advocating and practicing evidence-base

Since its beginning in 1902, Cedars-Sinai has evolved to meet the healthcare needs of one of the most diverse regions in the nation, continually setting new standards for quality and innovation in patient care, research, teaching and community service. Today, Cedars-Sinai is widely known for its na

Beginning with a single community in 1981, Sunrise Senior Living has grown to more than 270 communities throughout the U.S. and Canada. Each of our communities continues the mission laid out by founders Paul and Terry Klaassen more than 40 years ago: to champion quality of life for all seniors. Jo

Anteriormente Organización Sanitas Internacional, Keralty es un grupo empresarial de valor en salud, con más de 40 años de experiencia conformado por empresas de aseguramiento y prestación de servicios de salud y una red propia hospitalaria y asistencial. También forman parte de Keralty institucion

ELSAN, groupe leader de l’hospitalisation privée en France, compte aujourd’hui plus de 28 000 collaborateurs et 7500 médecins libéraux qui exercent dans les 212 établissements et centres du groupe. Ils prennent en charge plus de 4,8 millions de patients par an. Notre mission : offrir à chac
.png)
Pursuing her doctorate in computer science, Hala Ali wins national recognition for her research into memory forensics.
Seung Duk Lee, M.D., Ph.D., with his patient, Quanda Jordan, during her recovery at VCU Health. (Kevin Morley, VCU Enterprise Marketing and...
VCU uses AI in business education and research, preparing students for careers while tackling ethics and energy issues.
Compumedics USA Inc., a vendor that provides diagnostic and research technologies for sleep disorders for use in sleep study clinics,...
California-based Molina Healthcare, which manages Medicaid and Medicare programs, will close its Henrico office at the end of the month and lay off 268 workers.
Richmond Mayor Danny Avula has “no appetite” to sue over nearly $56 million the Virginia Commonwealth University Health System agreed to pay the city for a...
BizSense Beat is a weekly collaboration between VPM News and Richmond BizSense that brings you the top business stories during NPR's Morning...
Find out how Virginia Commonwealth University (VCU) Health's Adult Sickle Cell Medical Home Program improved patient engagement,...
The event, held at the Engineering Research Building, highlighted VCU's 26-year commitment to advancing STEM education through robotics.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of VCU Health is careers.vcuhealth.org.
According to Rankiteo, VCU Health’s AI-generated cybersecurity score is 742, reflecting their Moderate security posture.
According to Rankiteo, VCU Health currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, VCU Health is not certified under SOC 2 Type 1.
According to Rankiteo, VCU Health does not hold a SOC 2 Type 2 certification.
According to Rankiteo, VCU Health is not listed as GDPR compliant.
According to Rankiteo, VCU Health does not currently maintain PCI DSS compliance.
According to Rankiteo, VCU Health is not compliant with HIPAA regulations.
According to Rankiteo,VCU Health is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
VCU Health operates primarily in the Hospitals and Health Care industry.
VCU Health employs approximately 11,234 people worldwide.
VCU Health presently has no subsidiaries across any sectors.
VCU Health’s official LinkedIn profile has approximately 56,401 followers.
VCU Health is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
No, VCU Health does not have a profile on Crunchbase.
Yes, VCU Health maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/vcu-health-system.
As of December 19, 2025, Rankiteo reports that VCU Health has experienced 3 cybersecurity incidents.
VCU Health has an estimated 31,350 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach and Data Leak.
Detection and Response: The company detects and responds to cybersecurity incidents through an remediation measures with firing the workers involved..
Title: Data Breach at Virginia Commonwealth University Health System
Description: Virginia Commonwealth University Health System suffered from a data breach incident where 2,700 people's minor child’s electronic medical records were accessed without valid business grounds by certain community physician groups' workers and an employee of a contracted vendor.
Type: Data Breach
Attack Vector: Unauthorized Access
Threat Actor: Workers of certain community physician groupsEmployee of a contracted vendor
Title: Unauthorized Access to Electronic Health Information at VCU Health System
Description: VCU Health System notified about 4,700 individuals that their or their minor child’s electronic health information was inappropriately accessed. There is no indication that the private health information has been or will be used for any malicious purposes.
Type: Data Breach
Attack Vector: Unauthorized Access
Title: Data Breach at VCU Health System
Description: VCU Health System experienced a cyber attack for the second time which was reported by a patient that it's personal information has been compromised. It was found that clinical information, name, social security number, diagnosis and medications had been inappropriately accessed by an employee. The client notified the Health system through a letter about the security breach.
Type: Data Breach
Attack Vector: Insider Threat
Vulnerability Exploited: Employee Access
Threat Actor: Employee
Common Attack Types: The most common types of attacks the company has faced is Data Leak.


Data Compromised: Electronic Health Information

Data Compromised: Clinical information, Name, Social security number, Diagnosis, Medications
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Electronic Medical Records Of Minor Children, , Electronic Health Information, Clinical Information, Name, Social Security Number, Diagnosis, Medications and .

Entity Name: Virginia Commonwealth University Health System
Entity Type: Healthcare
Industry: Healthcare
Location: Virginia, USA
Customers Affected: 2700

Entity Name: VCU Health System
Entity Type: Healthcare Provider
Industry: Healthcare
Customers Affected: 4700

Entity Name: VCU Health System
Entity Type: Healthcare Provider
Industry: Healthcare

Remediation Measures: Firing the workers involved

Type of Data Compromised: Electronic medical records of minor children
Number of Records Exposed: 2700
Sensitivity of Data: High

Type of Data Compromised: Electronic Health Information
Number of Records Exposed: 4700
Sensitivity of Data: High

Type of Data Compromised: Clinical information, Name, Social security number, Diagnosis, Medications
Sensitivity of Data: High
Personally Identifiable Information: namesocial security number
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Firing the workers involved, .
Last Attacking Group: The attacking group in the last incident were an Workers of certain community physician groupsEmployee of a contracted vendor and Employee.
Most Significant Data Compromised: The most significant data compromised in an incident were Electronic Health Information, clinical information, name, social security number, diagnosis, medications and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were social security number, name, medications, Electronic Health Information, clinical information and diagnosis.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 740.0.
.png)
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of live queries.
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) of computing resources and a denial of service (DoS) of the Kibana process via a crafted HTTP request.
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function handler in the Vega AST evaluator.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.