Company Details
stlukeshealthsystem
11,181
47,676
62
stlukesonline.org
1
ST._8454485
Completed


St. Luke's Health System Vendor Cyber Rating & Cyber Score
stlukesonline.orgAs the only Idaho-based, not-for-profit health system, St. Luke’s Health System is dedicated to our mission “To improve the health of people in the communities we serve.” Today that means not only treating you when you’re sick or hurt, but doing everything we can to help you be as healthy as possible. Working together, we share resources, skills, and knowledge to provide the best possible care, no matter which of our hospitals you choose. Each St. Luke’s Health System hospital is nationally recognized for excellence in patient care, with prestigious awards and designations reflecting the exceptional care that is synonymous with the St. Luke's name.
Company Details
stlukeshealthsystem
11,181
47,676
62
stlukesonline.org
1
ST._8454485
Completed
Between 750 and 799

SLHS Global Score (TPRM)XXXX

Description: St. Luke’s suffered a data breach after one of its business vendors suffered a cyber security incident that affected certain patients and customers. The vendor provides the hospital statement processing and billing services and the unauthorized actor obtained the personal information and protected health information of patients who were billed in May 2022. However, St. Luke communicated with those who may have been impacted by the incident.


No incidents recorded for St. Luke's Health System in 2026.
No incidents recorded for St. Luke's Health System in 2026.
No incidents recorded for St. Luke's Health System in 2026.
SLHS cyber incidents detection timeline including parent company and subsidiaries

As the only Idaho-based, not-for-profit health system, St. Luke’s Health System is dedicated to our mission “To improve the health of people in the communities we serve.” Today that means not only treating you when you’re sick or hurt, but doing everything we can to help you be as healthy as possible. Working together, we share resources, skills, and knowledge to provide the best possible care, no matter which of our hospitals you choose. Each St. Luke’s Health System hospital is nationally recognized for excellence in patient care, with prestigious awards and designations reflecting the exceptional care that is synonymous with the St. Luke's name.

Founded in 1866, University Hospitals serves the needs of patients through an integrated network of 23 hospitals (including 5 joint ventures), more than 50 health centers and outpatient facilities, and over 200 physician offices in 16 counties throughout northern Ohio. The system’s flagship quaterna

Atrium Health, part of Advocate Health, is redefining how, when and where care is delivered. We are rethinking methods of care delivery to reach more people and bringing human kindness to every step of their health journey. Our dedication to elevating health care for every individual, every teammate

A Amil é uma empresa do setor de saúde que atua no Brasil combinando expertise e liderança para coordenar todos os agentes desse mercado - criando relações sustentáveis para conhecer e atender às necessidades de cada cliente e permitir que ele aproveite o melhor da vida. Diariamente, nos preocupamo

Every day, 119,000 compassionate caregivers serve patients and communities through Providence St. Joseph Health, a national, Catholic, not-for-profit health system, driven by a belief that health is a human right. Rooted in the founding missions of the Sisters of Providence and the Sisters of St.

We are Nova Scotia Health. We are rural and urban. We are in hospitals, health centres and community. We serve individuals and communities from Yarmouth to Cape Breton, from Amherst to Halifax, and everything in between. We are researchers and learners, looking for new ways to prevent and treat dis

Our mission is to improve the health and well-being of North Carolinians and others whom we serve. We accomplish this by providing leadership and excellence in the interrelated areas of patient care, education and research. UNC Health and its 40,000 teammates, continue to serve as North Carolina’s

Rush University Medical Center is an academic medical center that includes a 671-bed hospital serving adults and children, the 61-bed Johnston R. Bowman Health Center and Rush University. Rush University is home to one of the first medical colleges in the Midwest and one of the nation's top-ranked n
Northwestern Medicine is the collaboration between Northwestern Memorial HealthCare and Northwestern University Feinberg School of Medicine around a strategic vision to transform the future of health care. It encompasses the research, teaching, and patient care activities of the academic medical cen
Clear and confident health care decisions begin with questions. At Labcorp, we’re constantly in pursuit of answers. As a global leader of innovative and comprehensive laboratory services, we help doctors, hospitals, pharmaceutical companies, researchers and patients make clear and confident decisi
.png)
St. Luke's is the only Idaho-based, not-for-profit health system, with 8 medical centers, a children's hospital, and several hundred primary care and...
Our healthcare data breach statistics clearly show an upward trend in data breaches since 2009, when OCR first started publishing data...
AI meetups in Boise, ID for 2026 offer hands-on networking for builders. This guide covers events like AI Tinkerers Boise, Idaho AI Week,...
Our monthly AMA on r/cybersecurity on Reddit has begun! Our topic is “I've been a CISO more than once. Ask me anything about how the job...
PRNewswire/ -- St. Luke's University Health Network has implemented a next‑generation enterprise imaging solution that dramatically enhances...
St. Luke's University Health Network has launched a Sectra enterprise imaging solution to streamline medical image storage and improve...
This week's Department of Know is hosted by Rich Stroffolino with guests Krista Arndt, associate CISO, St. Luke's University Health Network,...
New Zealand's Health Minister has tasked the Ministry of Health with reviewing the ManageMyHealth portal cybersecurity breach.
Healthcare cybersecurity isn't just about technology—it's about people, trust, and the future of care. Healthcare leaders today are...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of St. Luke's Health System is http://www.stlukesonline.org.
According to Rankiteo, St. Luke's Health System’s AI-generated cybersecurity score is 750, reflecting their Fair security posture.
According to Rankiteo, St. Luke's Health System currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, St. Luke's Health System has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, St. Luke's Health System is not certified under SOC 2 Type 1.
According to Rankiteo, St. Luke's Health System does not hold a SOC 2 Type 2 certification.
According to Rankiteo, St. Luke's Health System is not listed as GDPR compliant.
According to Rankiteo, St. Luke's Health System does not currently maintain PCI DSS compliance.
According to Rankiteo, St. Luke's Health System is not compliant with HIPAA regulations.
According to Rankiteo,St. Luke's Health System is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
St. Luke's Health System operates primarily in the Hospitals and Health Care industry.
St. Luke's Health System employs approximately 11,181 people worldwide.
St. Luke's Health System presently has no subsidiaries across any sectors.
St. Luke's Health System’s official LinkedIn profile has approximately 47,676 followers.
St. Luke's Health System is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
No, St. Luke's Health System does not have a profile on Crunchbase.
Yes, St. Luke's Health System maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/stlukeshealthsystem.
As of March 30, 2026, Rankiteo reports that St. Luke's Health System has experienced 1 cybersecurity incidents.
St. Luke's Health System has an estimated 32,295 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with communicated with those who may have been impacted by the incident..
Title: St. Luke's Data Breach
Description: St. Luke’s suffered a data breach after one of its business vendors suffered a cyber security incident that affected certain patients and customers. The vendor provides the hospital statement processing and billing services and the unauthorized actor obtained the personal information and protected health information of patients who were billed in May 2022.
Type: Data Breach
Threat Actor: Unauthorized Actor
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Personal information, Protected health information
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Information, Protected Health Information and .

Entity Name: St. Luke's
Entity Type: Hospital
Industry: Healthcare
Customers Affected: Patients and customers who were billed in May 2022

Communication Strategy: Communicated with those who may have been impacted by the incident

Type of Data Compromised: Personal information, Protected health information
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Communicated with those who may have been impacted by the incident.
Last Attacking Group: The attacking group in the last incident was an Unauthorized Actor.
Most Significant Data Compromised: The most significant data compromised in an incident were Personal Information, Protected Health Information and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Protected Health Information and Personal Information.
.png)
A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the component Parameter Handler. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manipulation of the argument Status results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-side request forgery. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /logs of the component Endpoint. This manipulation of the argument filename causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in elecV2 elecV2P up to 3.8.3. The affected element is the function path.join of the file /log/ of the component Wildcard Handler. The manipulation results in path traversal. The attack may be performed from remote. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.