Company Details
vancouver-coastal-health
12,070
92,465
62
vch.ca
46
VAN_2219870
Completed


Vancouver Coastal Health Vendor Cyber Rating & Cyber Score
vch.caJoin a team connected by collaboration, support and most importantly, the goal of providing quality patient care. We value career growth with employer-supported training, encourage a culture where everyone’s voice is heard and strive to create a supportive team environment. To learn more, visit vch.ca/careers Facebook - https://www.facebook.com/VCHhealthcare/ Twitter - https://twitter.com/VCHhealthcare YouTube - https://www.youtube.com/@VCHhealthcare Instagram - https://www.instagram.com/vchhealthcare/
Company Details
vancouver-coastal-health
12,070
92,465
62
vch.ca
46
VAN_2219870
Completed
Between 750 and 799

VCH Global Score (TPRM)XXXX

Description: Vancouver Coastal Health experienced an attack. Malicious ransomware was discovered in data related to its Employee and Family Assistance Program on May 21. There is no evidence any data has been removed or misused from Employee and Family Assistance Program computers.


No incidents recorded for Vancouver Coastal Health in 2026.
No incidents recorded for Vancouver Coastal Health in 2026.
No incidents recorded for Vancouver Coastal Health in 2026.
VCH cyber incidents detection timeline including parent company and subsidiaries

Join a team connected by collaboration, support and most importantly, the goal of providing quality patient care. We value career growth with employer-supported training, encourage a culture where everyone’s voice is heard and strive to create a supportive team environment. To learn more, visit vch.ca/careers Facebook - https://www.facebook.com/VCHhealthcare/ Twitter - https://twitter.com/VCHhealthcare YouTube - https://www.youtube.com/@VCHhealthcare Instagram - https://www.instagram.com/vchhealthcare/

As a world-class academic and health care system, Duke Health strives to transform medicine and health locally and globally through innovative scientific research, rapid translation of breakthrough discoveries, educating future clinical and scientific leaders, advocating and practicing evidence-base

Kindred’s mission is to help our patients reach their highest potential for health and healing with intensive medical and rehabilitative care through a compassionate patient experience. Kindred’s 61 long-term acute care hospitals (LTACHs), along with 18 community-based, short-term acute care hospit

BayCare is a leading not-for-profit academic health care system that connects individuals and families to a wide range of services at 16 hospitals, including a children’s hospital, and hundreds of other convenient locations throughout the Tampa Bay and central Florida regions. The system is West Cen
One of the largest Trusts in the UK, Guy’s and St Thomas’ NHS Foundation Trust comprises five of the UK’s best known hospitals – Guy’s, St Thomas’, Evelina London Children’s Hospital, Royal Brompton and Harefield – as well as community services in Lambeth and Southwark, all with a long history of hi

At OHSU, we deliver breakthroughs for better health. We're driven by the belief that better health starts with innovations in the lab, in the classroom, at the bedside and in our communities. From cancer to Alzheimer's to cardiovascular care, we collaborate every day to identify and deliver new wa
Headquartered in Arizona, Banner Health is one of the largest nonprofit health care systems in the country. The system owns and operates 33 acute-care hospitals, Banner Health Network, Banner – University Medicine, academic and employed physician groups, long-term care centers, outpatient surgery ce

At The Ohio State University Wexner Medical Center you will find more than a job – you can establish a career that allows you to actually change the face of medicine. As central Ohio's only academic medical center, we emphasize learning, development and innovation in order to offer the very best in

The Medical University of South Carolina (MUSC) is a public institution of higher learning the purpose of which is to preserve and optimize human life in South Carolina and beyond. The university provides an interprofessional environment for learning and discovery through education of health care p

Novant Health is an integrated network of more than 850 locations, including 19 hospitals, more than 700 physician clinics and urgent care centers, outpatient facilities, and imaging and pharmacy services. This network supports a seamless and personalized healthcare experience for communities in Nor
.png)
Following encouraging outcomes from its first year, a school-based vision assessment pilot program is set to continue in the Vancouver...
Explore Canada's highest-paying and most in-demand jobs. Find the best career opportunities and industries to work in for 2026..
On Friday computers around the world running Windows 10 crashed, causing hiccups for health-care workers and patients.
The global IT outage has caused widespread disruption across multiple industries, including significant issues within the health-care sector...
The First Nations Health Authority says it's investigating a cybersecurity incident, which may have impacted personal information.
Recent hacking of B.C. health employers association underscores ongoing vulnerabilities.
The agency that represents B.C.'s healthcare employers denies that it was the latest victim of a Russian cybercrime gang.
UBC experts are available for comment on the second wave of the COVID-19 outbreak and various related topics. Interviews will be conducted...
The Medisys Health Group reported a ransomware data breach involving the personal information of about 60,000 of its clients.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Vancouver Coastal Health is http://careers.vch.ca/.
According to Rankiteo, Vancouver Coastal Health’s AI-generated cybersecurity score is 753, reflecting their Fair security posture.
According to Rankiteo, Vancouver Coastal Health currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Vancouver Coastal Health has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Vancouver Coastal Health is not certified under SOC 2 Type 1.
According to Rankiteo, Vancouver Coastal Health does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Vancouver Coastal Health is not listed as GDPR compliant.
According to Rankiteo, Vancouver Coastal Health does not currently maintain PCI DSS compliance.
According to Rankiteo, Vancouver Coastal Health is not compliant with HIPAA regulations.
According to Rankiteo,Vancouver Coastal Health is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Vancouver Coastal Health operates primarily in the Hospitals and Health Care industry.
Vancouver Coastal Health employs approximately 12,070 people worldwide.
Vancouver Coastal Health presently has no subsidiaries across any sectors.
Vancouver Coastal Health’s official LinkedIn profile has approximately 92,465 followers.
Vancouver Coastal Health is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
No, Vancouver Coastal Health does not have a profile on Crunchbase.
Yes, Vancouver Coastal Health maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/vancouver-coastal-health.
As of March 30, 2026, Rankiteo reports that Vancouver Coastal Health has experienced 1 cybersecurity incidents.
Vancouver Coastal Health has an estimated 32,295 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.
Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Entity Name: Vancouver Coastal Health
Entity Type: Healthcare
Industry: Healthcare
Location: Vancouver
Most Recent Incident Detected: The most recent incident detected was on 2023-05-21.
.png)
A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument lanIp leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI. Specifically, the @execute annotation (which is intended for trusted, user-authored comments) is also parsed in comments generated during auto-analysis (such as CFStrings in Mach-O binaries). This allows a crafted binary to present seemingly benign clickable text which, when clicked, executes attacker-controlled commands on the analyst’s machine.
A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function in `backend/routers/friends.py` does not implement proper authorization checks, enabling Insecure Direct Object Reference (IDOR) attacks. Specifically, the `/api/friends/requests/{friendship_id}` endpoint fails to verify whether the authenticated user is part of the friendship or the intended recipient of the request. This vulnerability can lead to unauthorized access, privacy violations, and potential social engineering attacks. The issue has been addressed in version 2.2.0.
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails to validate user-controlled URLs, allowing attackers to make arbitrary HTTP requests to internal services and cloud metadata endpoints. This vulnerability can lead to internal network access, cloud metadata access, information disclosure, port scanning, and potentially remote code execution.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.