Company Details
vitas-healthcare
6,836
85,727
62
vitas.com
0
VIT_3170889
In-progress

VITAS Healthcare Company CyberSecurity Posture
vitas.comThe nation’s leading provider of end-of-life care, and we have the resources and expertise to support your personal and professional growth. With nearly 12,000 employees, VITAS was named a 2025 Top Workplace in Healthcare. We are committed to providing compassionate care to hospice patients and supporting their families. VITAS team members find fulfillment working for a people-focused organization dedicated to making a difference in the lives of others. We also take care of each other, supporting our team members with resources, mentoring, and flexibility to do what’s right at the bedside. Here, you will be trusted as an expert in your field and as a valued team member whose efforts are vital to our mission. Join the team at VITAS and do work that matters: Your Passion. Our Purpose. Endless Possibilities.
Company Details
vitas-healthcare
6,836
85,727
62
vitas.com
0
VIT_3170889
In-progress
Between 600 and 649

VITAS Healthcare Global Score (TPRM)XXXX

Description: VITAS Healthcare, a Florida-based hospice provider operating in 15 states, experienced a data breach between **September 21 and October 27, 2025**, when an unauthorized party accessed and downloaded **personal information of current and former patients** via a compromised vendor account. The breach was discovered on **October 24, 2025**, prompting immediate containment measures, including system security reinforcement, engagement of cybersecurity experts, and law enforcement notification. While the exact number of affected individuals and the specific types of compromised data (e.g., Social Security numbers, medical records, addresses) were not disclosed, VITAS confirmed no evidence of misuse yet. As a precaution, the company offered **24 months of free credit monitoring and identity protection services**, alongside a dedicated hotline and website for support. The incident underscores vulnerabilities in healthcare data security, particularly due to third-party vendor risks, and aligns with a broader trend of rising breaches in the sector (725+ large breaches reported in 2024 alone).
Description: VITAS Hospice Services, LLC, a leading U.S. hospice care provider, suffered a data breach after an unauthorized party compromised a vendor’s account, gaining access to its systems between **September 21 and October 27, 2025**. The intruder exfiltrated highly sensitive personal and medical data of **current and former patients**, including **Social Security numbers, passport IDs, bank/debit card details, driver’s license numbers, medical records (ICD codes, Medicare IDs), and health savings account information**.The breach exposed **over 22,000 daily patients** across 15 states and D.C. to risks of **identity theft, financial fraud, and medical identity misuse**. VITAS offered **24 months of credit monitoring, dark web surveillance, and $1M identity theft insurance** via Epiq. Legal investigations are underway for potential **class-action lawsuits**, citing damages from **emotional distress, time spent mitigating risks, and financial losses**. The incident underscores vulnerabilities in **third-party vendor security** and the severe consequences of **healthcare data exposure**, particularly for a hospice provider handling end-of-life care records.
Description: PITTSBURGH, Dec. 03, 2025 (GLOBE NEWSWIRE) -- VITAS Hospice Services, LLC (“VITAS”),1 recently announced a cybersecurity incident, which impacted the personal information of countless individuals. Lynch Carpenter, LLP is investigating claims against VITAS related to this data breach. For an attorney to review your case, visit our site HERE. In the incident, an unauthorized person gained access to VITAS’s network and may have acquired records containing personally identifiable information (“PII”) and protected health information (“PHI”) that includes individuals’ names in combination with: • address • date of birth • Social Security number • driver’s license number • insurance information • medical information such as diagnosis, medications, and lab results If your information was impacted in this incident, you may be entitled to compensation. For an attorney to review your case, visit our site HERE. If you have received any other data breach notice letters in the last 30 days, please contact us here. About Lynch Carpenter Lynch Carpenter is a national class action law firm with offices in Pennsylvania, California, and Illinois. Our firm has represented millions of clients in data privacy matters for more than a decade and has earned national acclaim for complex litigation for plaintiffs across the country. To learn more, please visit www.lynchcarpenter.com. For more information, please call Jerry Wells at (412) 322-9243, or email him at [email protected]. _____


VITAS Healthcare has 163.16% more incidents than the average of same-industry companies with at least one recorded incident.
VITAS Healthcare has 212.5% more incidents than the average of all companies with at least one recorded incident.
VITAS Healthcare reported 2 incidents this year: 0 cyber attacks, 0 ransomware, 0 vulnerabilities, 2 data breaches, compared to industry peers with at least 1 incident.
VITAS Healthcare cyber incidents detection timeline including parent company and subsidiaries

The nation’s leading provider of end-of-life care, and we have the resources and expertise to support your personal and professional growth. With nearly 12,000 employees, VITAS was named a 2025 Top Workplace in Healthcare. We are committed to providing compassionate care to hospice patients and supporting their families. VITAS team members find fulfillment working for a people-focused organization dedicated to making a difference in the lives of others. We also take care of each other, supporting our team members with resources, mentoring, and flexibility to do what’s right at the bedside. Here, you will be trusted as an expert in your field and as a valued team member whose efforts are vital to our mission. Join the team at VITAS and do work that matters: Your Passion. Our Purpose. Endless Possibilities.

Care You Can Count On Whether you are searching for your next career opportunity or looking for care for yourself or a family member, you’ll find what you need at Scripps. Founded in 1924 by philanthropist Ellen Browning Scripps, Scripps is a non-profit integrated health care delivery system based

BayCare is a leading not-for-profit academic health care system that connects individuals and families to a wide range of services at 16 hospitals, including a children’s hospital, and hundreds of other convenient locations throughout the Tampa Bay and central Florida regions. The system is West Cen

As a nationally ranked academic medical center and one of Alabama’s largest employers, UAB Medicine is about teamwork, support, mentorship, and collaboration. Employees are empowered to lead, learn, and innovate as they deliver world-class care to every patient, every family, every time. When you ar
NYC Health + Hospitals is the nation’s largest public health care delivery system. We are an integrated network of hospitals, trauma centers, neighborhood health centers, nursing homes, and post-acute care centers. We are a home care agency and a health plan, MetroPlus. The health system provides es

Committed to Life - We save and improve human lives with affordable, accessible, and innovative healthcare products and the highest quality in clinical care. Fresenius is a global healthcare company headquartered in Bad Homburg v. d. Höhe, Germany. In fiscal year 2024, Fresenius generated €21.5 bil

Health Care Service Corporation serves nearly 23 million people across the United States through its portfolio of health benefit solutions. HCSC provides health coverage options for employers large and small, individuals and families, and Medicare and Medicaid plans. HCSC also offers related health

Welcome to the official LinkedIn page for McKesson Corporation. We're an impact-driven healthcare organization dedicated to “Advancing Health Outcomes For All.” As a global healthcare company, we touch virtually every aspect of health. Our leaders empower our people to lead with a growth mindset an

The Hospital Authority (HA) is a statutory body established under the Hospital Authority Ordinance in 1990. We have been responsible for managing Hong Kong's public hospitals services since December 1991. We are accountable to the Hong Kong Special Administrative Region Government through the Secret

Beginning with a single community in 1981, Sunrise Senior Living has grown to more than 270 communities throughout the U.S. and Canada. Each of our communities continues the mission laid out by founders Paul and Terry Klaassen more than 40 years ago: to champion quality of life for all seniors. Jo
.png)
VITAS Hospice Services, LLC, the largest for-profit hospice chain in the United States, has notified the California and Texas attorneys...
A new video released by VITAS Healthcare during National Care at Home Month spotlights the hospice story of Stacy Noland and her mother,...
VITAS learned of breach in October, but the security issue has not yet been reported yet to a federal database of similar hacks.
The personal information of current and former hospice patients may have been exposed in a cyberattack targeting VITAS Healthcare,...
Strauss Borrelli PLLC, a leading data breach law firm, is investigating VITAS Hospice Services, LLC (“VITAS”) regarding its recent data...
Data breach at VITAS exposed sensitive patient and family info, including SSNs and medical records. Check if you're affected and secure your...
If you were affected by the VITAS Hospice Services, LLC data breach, you may be entitled to compensation.
More Florida residents can now choose VITAS Healthcare, the nation's leading provider of end-of-life care, for their hospice and palliative...
In honor of National Care at Home Month, VITAS Healthcare, the nation's leading provider of end-of-life care, invites healthcare...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of VITAS Healthcare is https://www.vitas.com.
According to Rankiteo, VITAS Healthcare’s AI-generated cybersecurity score is 629, reflecting their Poor security posture.
According to Rankiteo, VITAS Healthcare currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, VITAS Healthcare is not certified under SOC 2 Type 1.
According to Rankiteo, VITAS Healthcare does not hold a SOC 2 Type 2 certification.
According to Rankiteo, VITAS Healthcare is not listed as GDPR compliant.
According to Rankiteo, VITAS Healthcare does not currently maintain PCI DSS compliance.
According to Rankiteo, VITAS Healthcare is not compliant with HIPAA regulations.
According to Rankiteo,VITAS Healthcare is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
VITAS Healthcare operates primarily in the Hospitals and Health Care industry.
VITAS Healthcare employs approximately 6,836 people worldwide.
VITAS Healthcare presently has no subsidiaries across any sectors.
VITAS Healthcare’s official LinkedIn profile has approximately 85,727 followers.
VITAS Healthcare is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
No, VITAS Healthcare does not have a profile on Crunchbase.
Yes, VITAS Healthcare maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/vitas-healthcare.
As of December 04, 2025, Rankiteo reports that VITAS Healthcare has experienced 3 cybersecurity incidents.
VITAS Healthcare has an estimated 30,377 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo->font, freeing the font string but leaving _drawInfo->font pointing to freed memory while _drawInfo->family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo->font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo->font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.
FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files that the server later executes (or stores in an executable location) without sufficient validation, sanitization, or execution restrictions. An authenticated remote attacker can upload a crafted PHP file and cause the application or web server to execute it, resulting in remote code execution (RCE).
PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated directly into a backend SQL query.
NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application and database.
NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations to modify the program executables and libraries.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.