ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

*Job seekers: please be aware of fraudulent job postings and phishing scams via LinkedIn. Henry Ford Health only contacts applicants through our human resources department and via a corporate email address. Here are some tips to be aware of: http://ow.ly/Kc0o50EKory Serving communities across Michigan and beyond, Henry Ford Health is committed to partnering with patients & members along their entire health journey. Henry Ford Health provides a full continuum of services – from primary and preventative care, to complex and specialty care, health insurance, a full suite of home health offerings, virtual care, pharmacy, eye care & other healthcare retail. It is one of the nation’s leading academic medical centers, recognized for clinical excellence in cancer care, cardiology and cardiovascular surgery, neurology and neurosurgery, orthopedics and sports medicine, and multi-organ transplants. Consistently ranked among the top five NIH-funded institutions in Michigan, Henry Ford Health engages in thousands of research projects annually. Equally committed to educating the next generation of health professionals, Henry Ford Health trains more than 4,000 medical students, residents and fellows every year across 50+ accredited programs. With more than 50,000 valued team members, Henry Ford Health is also among Michigan’s largest and most diverse employers. President and CEO Bob Riney leads the health system and serves a growing number of customers across more than 550 sites across Michigan. That includes: 13 acute care hospitals; 3 behavioral health facilities including two world-class addiction treatment centers; a state-of-the-art orthopedics and sports medicine facility; multiple cancer care destinations including the Brigitte Harris Cancer Pavilion, Henry Ford Health’s premier location in Detroit; & more options than ever for primary care for patients and families across the region.

Henry Ford Health A.I CyberSecurity Scoring

HFH

Company Details

Linkedin ID:

henry-ford-health

Employees number:

20,343

Number of followers:

121,801

NAICS:

62

Industry Type:

Hospitals and Health Care

Homepage:

henryford.com

IP Addresses:

4

Company ID:

HEN_2535154

Scan Status:

Completed

AI scoreHFH Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/henry-ford-health.jpeg
HFH Hospitals and Health Care
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreHFH Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/henry-ford-health.jpeg
HFH Hospitals and Health Care
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

HFH Company CyberSecurity News & History

Past Incidents
2
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Henry Ford HealthData Leak60302/2011
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: Henry Ford Health System has compromised patient information after an employee lost a flash drive with information on 2,777 patients. The drive stored information including names, medical record numbers, test information and results. Henry Ford officials said no Social Security numbers or health insurance identification numbers.

Henry Ford HealthData Leak85312/2017
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: Henry Ford Health System has compromised patient information after a system got hacked that exposed 18,500 patients' personal information. The compromised information included the patient's name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, and health insurer. Neither Social Security numbers nor credit card information was revealed. People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked.

Henry Ford Health
Data Leak
Severity: 60
Impact: 3
Seen: 02/2011
Blog:
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: Henry Ford Health System has compromised patient information after an employee lost a flash drive with information on 2,777 patients. The drive stored information including names, medical record numbers, test information and results. Henry Ford officials said no Social Security numbers or health insurance identification numbers.

Henry Ford Health
Data Leak
Severity: 85
Impact: 3
Seen: 12/2017
Blog:
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: Henry Ford Health System has compromised patient information after a system got hacked that exposed 18,500 patients' personal information. The compromised information included the patient's name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, and health insurer. Neither Social Security numbers nor credit card information was revealed. People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked.

Ailogo

HFH Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for HFH

Incidents vs Hospitals and Health Care Industry Average (This Year)

No incidents recorded for Henry Ford Health in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Henry Ford Health in 2025.

Incident Types HFH vs Hospitals and Health Care Industry Avg (This Year)

No incidents recorded for Henry Ford Health in 2025.

Incident History — HFH (X = Date, Y = Severity)

HFH cyber incidents detection timeline including parent company and subsidiaries

HFH Company Subsidiaries

SubsidiaryImage

*Job seekers: please be aware of fraudulent job postings and phishing scams via LinkedIn. Henry Ford Health only contacts applicants through our human resources department and via a corporate email address. Here are some tips to be aware of: http://ow.ly/Kc0o50EKory Serving communities across Michigan and beyond, Henry Ford Health is committed to partnering with patients & members along their entire health journey. Henry Ford Health provides a full continuum of services – from primary and preventative care, to complex and specialty care, health insurance, a full suite of home health offerings, virtual care, pharmacy, eye care & other healthcare retail. It is one of the nation’s leading academic medical centers, recognized for clinical excellence in cancer care, cardiology and cardiovascular surgery, neurology and neurosurgery, orthopedics and sports medicine, and multi-organ transplants. Consistently ranked among the top five NIH-funded institutions in Michigan, Henry Ford Health engages in thousands of research projects annually. Equally committed to educating the next generation of health professionals, Henry Ford Health trains more than 4,000 medical students, residents and fellows every year across 50+ accredited programs. With more than 50,000 valued team members, Henry Ford Health is also among Michigan’s largest and most diverse employers. President and CEO Bob Riney leads the health system and serves a growing number of customers across more than 550 sites across Michigan. That includes: 13 acute care hospitals; 3 behavioral health facilities including two world-class addiction treatment centers; a state-of-the-art orthopedics and sports medicine facility; multiple cancer care destinations including the Brigitte Harris Cancer Pavilion, Henry Ford Health’s premier location in Detroit; & more options than ever for primary care for patients and families across the region.

Loading...
similarCompanies

HFH Similar Companies

NYC Health + Hospitals

NYC Health + Hospitals is the nation’s largest public health care delivery system. We are an integrated network of hospitals, trauma centers, neighborhood health centers, nursing homes, and post-acute care centers. We are a home care agency and a health plan, MetroPlus. The health system provides es

AdventHealth

AdventHealth is a connected network of care that helps people feel whole – body, mind and spirit. More than 100,000 team members across a national footprint provide whole-person care to nearly nine million people annually through more than 2,000 care sites that include hospitals, physician practices

NHG Health

NHG Health is a leading public healthcare provider in Singapore recognised for its quality clinical care and its commitment in enabling healthier lives through preventive health, innovative solutions and person-centred programmes tailored to every life stage. Our integrated health system, which span

Labcorp

Clear and confident health care decisions begin with questions. At Labcorp, we’re constantly in pursuit of answers. As a global leader of innovative and comprehensive laboratory services, we help doctors, hospitals, pharmaceutical companies, researchers and patients make clear and confident decisi

Northside Hospital

Northside Hospital — a certified Great Place To Work® — is one of Georgia’s top health systems. We have acute-care hospitals in Atlanta, Canton, Cumming, Duluth and Lawrenceville and hundreds of outpatient locations across the state. Northside Hospital leads the U.S. in newborn deliveries and is amo

Rochester Regional Health

Rochester Regional Health, headquartered in Rochester, NY, is an integrated health services organization serving the people of Western New York, the Finger Lakes, St. Lawrence County, and beyond. We are dedicated to helping our community stay healthy and live fulfilling lives. Together, we find the

Atrium Health Wake Forest Baptist

Atrium Health Wake Forest Baptist is a nationally recognized academic medical center and health system based in Winston-Salem, NC, part of Advocate Health, the third-largest nonprofit health system in the United States. Atrium Health Wake Forest Baptist’s two main components are an integrated clin

Community Health Systems

Community Health Systems is one of the nation’s leading healthcare providers. Developing and operating healthcare delivery systems across 14 states, CHS is committed to helping people get well and live healthier. CHS affiliates operate 70 acute-care hospitals and more than 1,000 other sites of care,

Allina Health

People at Allina Health have a career of making a difference in the lives of the millions of patients we see each year at our 90+ clinics, 12 hospitals and through a wide variety of specialty care services in Minnesota and western Wisconsin. We’re a not-for-profit organization committed to enrichin

newsone

HFH CyberSecurity News

November 11, 2025 08:00 AM
How Michigan hospitals are tackling burnout among nurses

In west Michigan, nurses are using an app to redirect nonmedical work to other workers. In Jackson, some nurses are working virtually.

September 23, 2025 07:00 AM
What the changes to H-1B visas might mean for healthcare

Healthcare employers of all sizes are grappling to determine how changes to the H-1B visa program will affect their ability to expand their...

September 22, 2025 07:00 AM
BD and Henry Ford Health Sign Pharmacy Automation Partnership to Revolutionize Medication Storage and Prescription Delivery

FRANKLIN LAKES, N.J., Sept. 22, 2025 /PRNewswire/ -- BD (Becton, Dickinson and Company) (NYSE: BDX), a leading…...

September 03, 2025 07:00 AM
Quipt Home Medical Completes Strategic Acquisition of Hart Medical Adding $60 Million in Revenue

Transaction Strengthens Health System Partnerships, Expands Midwest Footprint, and Reinforces Long-Term Growth Strategy.

August 26, 2025 08:23 AM
Henry Ford Health MyChart privacy class action settlement

Henry Ford Health agreed to a class action lawsuit settlement to resolve claims it shared patient data with third parties without consent.

August 25, 2025 07:00 AM
Cleary University's New Program Offers 50% Tuition Grant to Businesses

Radio Station WHMI 93.5 FM — Livingston County Michigan News, Weather, Traffic, Sports, School Updates, and the Best Classic Hits for Howell...

August 22, 2025 07:00 AM
Detroit police manhunt for suspect who shot ex-wife

Detroit police search for Mario Green, 65, who shot and killed his ex-wife at Henry Ford Hospital. White Dodge Charger, license DXC 7067.

July 23, 2025 07:00 AM
Henry Ford Health, Michigan State University launch $10M VC fund

Henry Ford Health, Michigan State University and the MSU Research Foundation have created a $10 million venture fund to invest in early-stage healthcare...

June 24, 2025 07:00 AM
Ascension Seals the Deal

Ascension is on a soul-searching journey. Just look at all of the recent activity from the national hospital operator:.

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

HFH CyberSecurity History Information

Official Website of Henry Ford Health

The official website of Henry Ford Health is http://www.henryford.com.

Henry Ford Health’s AI-Generated Cybersecurity Score

According to Rankiteo, Henry Ford Health’s AI-generated cybersecurity score is 769, reflecting their Fair security posture.

How many security badges does Henry Ford Health’ have ?

According to Rankiteo, Henry Ford Health currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Henry Ford Health have SOC 2 Type 1 certification ?

According to Rankiteo, Henry Ford Health is not certified under SOC 2 Type 1.

Does Henry Ford Health have SOC 2 Type 2 certification ?

According to Rankiteo, Henry Ford Health does not hold a SOC 2 Type 2 certification.

Does Henry Ford Health comply with GDPR ?

According to Rankiteo, Henry Ford Health is not listed as GDPR compliant.

Does Henry Ford Health have PCI DSS certification ?

According to Rankiteo, Henry Ford Health does not currently maintain PCI DSS compliance.

Does Henry Ford Health comply with HIPAA ?

According to Rankiteo, Henry Ford Health is not compliant with HIPAA regulations.

Does Henry Ford Health have ISO 27001 certification ?

According to Rankiteo,Henry Ford Health is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Henry Ford Health

Henry Ford Health operates primarily in the Hospitals and Health Care industry.

Number of Employees at Henry Ford Health

Henry Ford Health employs approximately 20,343 people worldwide.

Subsidiaries Owned by Henry Ford Health

Henry Ford Health presently has no subsidiaries across any sectors.

Henry Ford Health’s LinkedIn Followers

Henry Ford Health’s official LinkedIn profile has approximately 121,801 followers.

NAICS Classification of Henry Ford Health

Henry Ford Health is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.

Henry Ford Health’s Presence on Crunchbase

No, Henry Ford Health does not have a profile on Crunchbase.

Henry Ford Health’s Presence on LinkedIn

Yes, Henry Ford Health maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/henry-ford-health.

Cybersecurity Incidents Involving Henry Ford Health

As of December 11, 2025, Rankiteo reports that Henry Ford Health has experienced 2 cybersecurity incidents.

Number of Peer and Competitor Companies

Henry Ford Health has an estimated 30,928 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Henry Ford Health ?

Incident Types: The types of cybersecurity incidents that have occurred include Data Leak.

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Data Breach at Henry Ford Health System

Description: Henry Ford Health System has compromised patient information after an employee lost a flash drive with information on 2,777 patients. The drive stored information including names, medical record numbers, test information and results. Henry Ford officials said no Social Security numbers or health insurance identification numbers were compromised.

Type: Data Breach

Attack Vector: Physical Loss

Vulnerability Exploited: Loss of Physical Media

Threat Actor: Employee

Motivation: Accidental

Incident : Data Breach

Title: Henry Ford Health System Data Breach

Description: Henry Ford Health System has compromised patient information after a system got hacked that exposed 18,500 patients' personal information. The compromised information included the patient's name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, and health insurer. Neither Social Security numbers nor credit card information was revealed.

Type: Data Breach

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Data Leak.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach HEN19214123

Data Compromised: Names, Medical record numbers, Test information and results

Incident : Data Breach HEN2285323

Data Compromised: Name, Date of birth, Medical record number, Provider's name, Date of service, Department's name, Location, Medical condition, Health insurer

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Medical Record Numbers, Test Information And Results, , Personal Information, Health Information and .

Which entities were affected by each incident ?

Incident : Data Breach HEN19214123

Entity Name: Henry Ford Health System

Entity Type: Healthcare

Industry: Healthcare

Customers Affected: 2777

Incident : Data Breach HEN2285323

Entity Name: Henry Ford Health System

Entity Type: Healthcare Provider

Industry: Healthcare

Customers Affected: 18500

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach HEN19214123

Type of Data Compromised: Names, Medical record numbers, Test information and results

Number of Records Exposed: 2777

Sensitivity of Data: High

Incident : Data Breach HEN2285323

Type of Data Compromised: Personal information, Health information

Number of Records Exposed: 18500

Sensitivity of Data: High

Personally Identifiable Information: namedate of birthmedical record number

Lessons Learned and Recommendations

What recommendations were made to prevent future incidents ?

Incident : Data Breach HEN2285323

Recommendations: People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked.

What recommendations has the company implemented to improve cybersecurity ?

Implemented Recommendations: The company has implemented the following recommendations to improve cybersecurity: People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked..

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident was an Employee.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were names, medical record numbers, test information and results, , name, date of birth, medical record number, provider's name, date of service, department's name, location, medical condition, health insurer and .

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were medical record numbers, names, test information and results, location, medical record number, date of birth, medical condition, name, department's name, provider's name, health insurer and date of service.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 469.0.

Lessons Learned and Recommendations

What was the most significant recommendation implemented to improve cybersecurity ?

Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was People can take steps to safeguard themselves by requesting new medical record numbers if they believe their data has been hacked..

cve

Latest Global CVEs (Not Company-Specific)

Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.

Risk Information
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.

Risk Information
cvss3
Base: 9.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Description

Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.

Risk Information
cvss3
Base: 8.2
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Description

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.

Risk Information
cvss3
Base: 8.4
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Description

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Risk Information
cvss3
Base: 5.4
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=henry-ford-health' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge