Company Details
ssm-health-care
19,235
87,085
62
ssmhealth.com
19
SSM_7239795
Completed

SSM Health Company CyberSecurity Posture
ssmhealth.comSSM Health is a Catholic, not-for-profit, fully integrated health system dedicated to advancing innovative, sustainable, and compassionate care for patients and communities throughout the Midwest and beyond. The organization’s 40,000 team members and 13,900 providers are committed to fulfilling SSM Health’s Mission: “Through our exceptional health care services, we reveal the healing presence of God.” With care delivery sites in Illinois, Missouri, Oklahoma and Wisconsin, SSM Health includes hospitals, physician offices, outpatient and virtual care services, comprehensive home care and hospice services, a fully transparent pharmacy benefit company, a health insurance company and an accountable care organization. It is one of the largest employers in every community it serves. For more information, visit ssmhealth.com Visit jobs.ssmhealth.com to fulfill your calling with SSM Health. Together – We Care.
Company Details
ssm-health-care
19,235
87,085
62
ssmhealth.com
19
SSM_7239795
Completed
Between 700 and 749

SSM Health Global Score (TPRM)XXXX

Description: The U.S. Department of Health and Human Services reported that SSM Health Insurance Company experienced a data breach on December 11, 2020. This breach affected 4,492 individuals and involved paper/films. There was no business associate present during the breach.
Description: SSM Health Care Corporation, a major U.S. healthcare provider, was targeted in a cyberattack allegedly orchestrated by Owen Flowers, one of the two British teenagers charged in the UK for cybercrimes. The attack involved infiltration and attempted damage to SSM Health’s systems, potentially compromising sensitive healthcare data, operational integrity, or patient services. While the exact extent of the breach remains undisclosed, the involvement of a healthcare entity suggests high-risk exposure, including possible disruption to medical services, unauthorized access to patient records (e.g., personal, financial, or treatment-related data), or systemic outages. The attack’s connection to a broader campaign—including attempts against Sutter Health—highlights its coordinated and malicious nature. Given the critical role of healthcare infrastructure, such incidents can threaten patient safety, erode trust in the organization, and trigger regulatory penalties. The case’s international dimension (UK-US) and the defendants’ alleged ties to other high-profile attacks (e.g., Transport for London) underscore the severity of the threat.


SSM Health has 20.48% more incidents than the average of same-industry companies with at least one recorded incident.
SSM Health has 29.87% more incidents than the average of all companies with at least one recorded incident.
SSM Health reported 1 incidents this year: 1 cyber attacks, 0 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.
SSM Health cyber incidents detection timeline including parent company and subsidiaries

SSM Health is a Catholic, not-for-profit, fully integrated health system dedicated to advancing innovative, sustainable, and compassionate care for patients and communities throughout the Midwest and beyond. The organization’s 40,000 team members and 13,900 providers are committed to fulfilling SSM Health’s Mission: “Through our exceptional health care services, we reveal the healing presence of God.” With care delivery sites in Illinois, Missouri, Oklahoma and Wisconsin, SSM Health includes hospitals, physician offices, outpatient and virtual care services, comprehensive home care and hospice services, a fully transparent pharmacy benefit company, a health insurance company and an accountable care organization. It is one of the largest employers in every community it serves. For more information, visit ssmhealth.com Visit jobs.ssmhealth.com to fulfill your calling with SSM Health. Together – We Care.


People are at the heart of everything we do, and the inspiration for our legacy of outstanding outcomes, innovation, strong community partnerships, philanthropy and transparency. Corewell Health is a not-for-profit health system that provides health care and coverage with an exceptional team of 65,0

UC San Diego Health and Health Sciences has been caring for the community and producing physicians for more than 50 years. In 1966, we established our first medical center. Two years later, in 1968, UC San Diego School of Medicine opened for business. Today, UC San Diego Health is the only academic

MultiCare’s roots in the Pacific Northwest go back to 1882, with the founding of Tacoma’s first hospital. Over the years, we’ve grown from a Tacoma-centric, hospital-based organization into the largest, community-based, locally governed health system in the state of Washington. Today, our comprehe

One of the largest Trusts in the UK, Guy’s and St Thomas’ NHS Foundation Trust comprises five of the UK’s best known hospitals – Guy’s, St Thomas’, Evelina London Children’s Hospital, Royal Brompton and Harefield – as well as community services in Lambeth and Southwark, all with a long history of hi

Nationwide Children’s is one of America's largest pediatric hospitals, an international leader in research and is ranked in all 10 specialties on U.S. News & World Report’s 2025-26 “America’s Best Children’s Hospitals” list. Our staff, comprised of 1,600 medical professionals and over 16,000 employe

Founded in 2003, Omega Healthcare Management Services® (Omega Healthcare) empowers healthcare to thrive via intelligent solutions that optimize revenue cycle operations, administrative workflows, care coordination, and clinical research on a global scale. The company works with providers, payers, li
A Dasa é a maior rede de saúde integrada do Brasil. Faz parte da vida de mais de 20 milhões de pessoas por ano, com alta tecnologia, experiência intuitiva e atitude à frente do tempo. Com mais de 50 mil colaboradores e 250 mil médicos parceiros, existe para ser a saúde que as pessoas desejam e que

Our mission is to improve the health and well-being of North Carolinians and others whom we serve. We accomplish this by providing leadership and excellence in the interrelated areas of patient care, education and research. UNC Health and its 33,000 employees, continue to serve as North Carolina’s
Ardent Health is a leading provider of healthcare in communities across the country. With a focus on consumer-friendly processes and investments in innovative services and technologies, Ardent is passionate about making healthcare better and easier to access. Through its subsidiaries, Ardent owns an
.png)
An aging population and dated hospital rehab units are driving health systems to build rehab hospitals with joint-venture partners.
SSM Health agreed to a class action lawsuit settlement to resolve claims that it disclosed patients' private information to third parties without their...
It can be very overwhelming scrolling through job board after job board in search of a position that fits your wants and needs.
Cybersecurity failures are putting vulnerable hospitals at risk, prompting healthcare leaders to call for stronger national policies and...
An AHA blog published today highlights how SSM Health is confronting workplace violence with a comprehensive, team-based hospital safety...
Workplace violence prevention in health care has become one of the most urgent priorities for hospitals and health care systems nationwide.
The National Crime Agency has arrested and charged two suspected teenage members of the Scattered Spider cybercrime gang over the Transport...
Google patches sixth Chrome zero-day, Microsoft to force install Copilot app in October, Two more Scattered Spider teen suspects arrested.
Talha Jubair, 19, from London, is suspected of more than 120 cyberattacks, including attacks on Transport for London and American companies.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of SSM Health is http://www.ssmhealth.com.
According to Rankiteo, SSM Health’s AI-generated cybersecurity score is 742, reflecting their Moderate security posture.
According to Rankiteo, SSM Health currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, SSM Health is not certified under SOC 2 Type 1.
According to Rankiteo, SSM Health does not hold a SOC 2 Type 2 certification.
According to Rankiteo, SSM Health is not listed as GDPR compliant.
According to Rankiteo, SSM Health does not currently maintain PCI DSS compliance.
According to Rankiteo, SSM Health is not compliant with HIPAA regulations.
According to Rankiteo,SSM Health is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
SSM Health operates primarily in the Hospitals and Health Care industry.
SSM Health employs approximately 19,235 people worldwide.
SSM Health presently has no subsidiaries across any sectors.
SSM Health’s official LinkedIn profile has approximately 87,085 followers.
SSM Health is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
Yes, SSM Health has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/ssm-health-cardinal-glennon-children-s-hospital.
Yes, SSM Health maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/ssm-health-care.
As of December 11, 2025, Rankiteo reports that SSM Health has experienced 2 cybersecurity incidents.
SSM Health has an estimated 30,929 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack and Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with national crime agency (nca), and .
Title: SSM Health Insurance Data Breach
Description: The U.S. Department of Health and Human Services reported that SSM Health Insurance Company experienced a data breach due to unauthorized access/disclosure on December 11, 2020, affecting 4,492 individuals. The breach involved paper/films and did not have a business associate present.
Date Detected: 2020-12-11
Type: Data Breach
Attack Vector: Unauthorized Access/Disclosure
Title: Cyberattack on Transport for London (TfL) and Alleged Attacks on U.S. Healthcare Companies by British Teenagers
Description: Two British teenagers, Thalha Jubair (19) and Owen Flowers (18), were charged under the Computer Misuse Act for a cyberattack on Transport for London (TfL) in 2024. Flowers is also accused of conspiring to infiltrate and damage U.S. healthcare entities SSM Health Care Corporation and Sutter Health. Both pleaded not guilty in a U.K. court. The trial is scheduled for June 8, 2026, with both defendants remanded in custody. The U.S. DOJ has not publicly filed charges against Flowers, while charges against Jubair were unsealed in September 2024.
Date Publicly Disclosed: 2024-09
Type: cyberattack
Threat Actor: Thalha JubairOwen Flowers
Common Attack Types: The most common types of attacks the company has faced is Breach.

Brand Reputation Impact: potential reputational damage to TfLpotential reputational damage to SSM Health Care Corporationpotential reputational damage to Sutter Health
Legal Liabilities: Computer Misuse Act charges (U.K.)potential U.S. charges for healthcare attacks
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Paper/Films.

Entity Name: SSM Health Insurance Company
Entity Type: Health Insurance Company
Industry: Healthcare
Customers Affected: 4,492

Entity Name: Transport for London (TfL)
Entity Type: government agency
Industry: transportation
Location: London, U.K.

Entity Name: SSM Health Care Corporation
Entity Type: private organization
Industry: healthcare
Location: U.S.

Entity Name: Sutter Health
Entity Type: private organization
Industry: healthcare
Location: U.S.

Third Party Assistance: National Crime Agency (Nca).
Third-Party Assistance: The company involves third-party assistance in incident response through National Crime Agency (NCA), .

Type of Data Compromised: Paper/Films
Number of Records Exposed: 4,492

Regulations Violated: Computer Misuse Act (U.K.),
Legal Actions: criminal charges filed (U.K.), potential extradition or U.S. charges,
Ensuring Regulatory Compliance: The company ensures compliance with regulatory requirements through criminal charges filed (U.K.), potential extradition or U.S. charges, .

Source: U.S. Department of Health and Human Services

Source: The Record

Source: BBC (Neil Henderson)

Source: U.S. Department of Justice (unsealed charges for Jubair)
Date Accessed: 2024-09
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: U.S. Department of Health and Human Services, and Source: The Record, and Source: BBC (Neil Henderson), and Source: U.S. Department of Justice (unsealed charges for Jubair)Date Accessed: 2024-09.

Investigation Status: ongoing (trial scheduled for June 8, 2026)

High Value Targets: Tfl, Ssm Health Care Corporation, Sutter Health,
Data Sold on Dark Web: Tfl, Ssm Health Care Corporation, Sutter Health,
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as National Crime Agency (Nca), .
Last Attacking Group: The attacking group in the last incident was an Thalha JubairOwen Flowers.
Most Recent Incident Detected: The most recent incident detected was on 2020-12-11.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-09.
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was national crime agency (nca), .
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 4.5K.
Most Significant Legal Action: The most significant legal action taken for a regulatory violation was criminal charges filed (U.K.), potential extradition or U.S. charges, .
Most Recent Source: The most recent source of information about an incident are U.S. Department of Health and Human Services, U.S. Department of Justice (unsealed charges for Jubair), The Record and BBC (Neil Henderson).
Current Status of Most Recent Investigation: The current status of the most recent investigation is ongoing (trial scheduled for June 8, 2026).
.png)
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.