Skip to main content

Healthcare security reports

Browse 6,595 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157381
Websites
130
Industries
113
Countries
52
Avg Score
Page 127 of 132|Showing 6301-6350 of 6595
B

Boston Scientific Corporation

bostonscientific.com

40
HealthcareUnited StatesenterpriseHIGH

Boston Scientific Corporation is a leading global healthcare company specializing in innovative medical devices and solutions aimed at improving patient outcomes. The website targets healthcare professionals, patients, caregivers, investors, and other stakeholders, offering comprehensive product information, educational resources, and corporate responsibility content. The company is well-established with a mature domain and strong brand presence. Technically, the website leverages Adobe Experience Manager as its CMS, integrates modern marketing and analytics tools such as Adobe Target and Google Tag Manager, and provides a responsive, accessible user experience. However, a critical security gap exists due to the absence of a valid SSL certificate and HTTPS support, which significantly impacts the site's security posture. Security headers and content security policies are implemented but their effectiveness is limited without HTTPS. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. Overall, the site demonstrates high business credibility and professionalism but requires urgent remediation of its SSL/TLS configuration to ensure user trust and data protection.

-
18
5
50
-
85
100
healthcaremedicaldevicescorporateeducationinvestorrelations+1 more
Adobe TargetGoogle Tag ManagerjQuery 3.7.1Coveo Search UI+2

Partner Domains:

relievant.com
subsidiarypending
intracept.com
subsidiarypending
2025-06-15T22:09:05.065Z
H

Health Cloud Initiative

winbase.nl

40
HealthcareNetherlandsmediumHIGH

Health Cloud Initiative (HCI) is a Dutch healthcare software provider specializing in comprehensive EHR solutions and digital healthcare platforms. The company serves a broad range of healthcare providers including mental health institutions, paramedical practices, general practitioners, pharmacies, dental care, and rehabilitation care. With over 4 million users and 40,000 healthcare professionals, HCI holds a significant market position in the Netherlands, offering an all-in-one platform that integrates EHR, eHealth apps, client environments, and consultancy services. The website reflects a professional and well-structured digital presence, targeting healthcare providers seeking efficient and user-friendly software solutions. Technically, the site is built on WordPress with Elementor and uses modern web technologies, though performance metrics are not explicitly available. Security-wise, the site has strong indicators such as ISO 27001 and NEN 7510 certifications and appropriate security headers; however, it critically lacks a valid SSL certificate and TLS support, which severely impacts its security posture. Privacy compliance is well addressed with accessible privacy and cookie policies, and GDPR compliance is evident. Overall, while the business and content quality are excellent, the lack of proper SSL/TLS implementation poses a significant risk that should be urgently addressed to protect user data and maintain trust.

-
-
-
50
-
50
100
healthcareehrsoftwarementalhealthparamedical+3 more
WordPressElementorjQueryNinja Forms+1

Partner Domains:

quli.nl
partnerpending
paranice.nl
partnerpending
2025-06-15T22:08:10.572Z
arbd.com favicon

Abramson, Brown and Dugan Law

arbd.com

19
HealthcareUnited StatessmallCRITICAL

Abramson, Brown and Dugan is a specialized law firm based in New Hampshire focusing on medical malpractice and personal injury cases. The firm holds a strong market position in the state, recognized for winning more malpractice settlements and verdicts than any other local firm. Their website provides comprehensive information about their services, recent settlements, attorney profiles, and client testimonials, targeting individuals seeking legal representation for serious injury and malpractice claims. The business model centers on plaintiff legal services with a focus on compassionate client engagement and free consultations. Technically, the website is built on WordPress using the Enfold theme and integrates common technologies such as jQuery, Google Tag Manager, Google Analytics, and Google reCAPTCHA for form security. While the site is mobile optimized and SEO friendly, performance metrics indicate slow loading times, and accessibility features are basic. The site lacks a valid SSL certificate, resulting in no HTTPS support, which is a significant security concern. DNS records are missing or not publicly visible, which is inconsistent with the active website presence. Security posture is weak due to the absence of HTTPS, missing DNSSEC, CAA, and HSTS configurations, and lack of security headers. No privacy, cookie, or terms of service policies are found, indicating compliance gaps with GDPR and other privacy regulations. The site uses Google reCAPTCHA to protect forms but lacks a formal security or incident response policy. Overall, the site demonstrates strong business credibility and content quality but requires urgent improvements in security and privacy compliance. Strategically, the firm should prioritize obtaining and configuring a valid SSL certificate, properly configuring DNS records, and publishing comprehensive privacy and cookie policies. Enhancing security headers and implementing vulnerability disclosure mechanisms would further improve trust and compliance. These steps will reduce risk, improve user trust, and align the firm with modern security and privacy standards.

-
-
-
50
-
50
-
lawfirmmedicalmalpracticepersonalinjurylegalservicesnewhampshire+3 more
ApachejQueryGoogle reCAPTCHA v2 and v3Google Tag Manager+6
2025-06-15T22:07:59.860Z
aplaceformom.com favicon

A Place for Mom

aplaceformom.com

40
HealthcareUnited StateslargeHIGH

A Place for Mom is a leading senior living referral service that connects families with assisted living, memory care, independent living, home care, nursing homes, and other senior care options. The company operates a large network of communities and home care providers, offering personalized support through expert advisors at no cost to families. Their market position is strong, supported by extensive consumer reviews, award recognitions, and a broad geographic presence across major US cities. Technically, the website is built on modern frameworks such as Next.js and React, leveraging AWS CloudFront for content delivery and integrating advanced analytics and marketing tools like Segment, Optimizely, and Drift. The site demonstrates good mobile optimization, accessibility, and SEO practices, providing a professional and user-friendly experience. However, the security posture is currently weak due to the absence of a valid SSL certificate and lack of HTTPS support, which is a critical vulnerability. While security headers are properly configured, the lack of TLS protocols and OCSP stapling reduces overall security. Privacy compliance is well addressed with comprehensive policies and consent mechanisms. Overall, the website presents a trustworthy and professional front for its business but requires urgent improvements in SSL/TLS implementation to ensure secure user interactions and maintain trust. Strategic recommendations include immediate SSL certificate installation, enabling modern TLS protocols, and enhancing DNS security measures.

95
18
-
50
-
85
100
seniorlivingassistedlivingmemorycarenursinghomeshomecare+3 more
Next.jsReactSegment AnalyticsOptimizely+3
2025-06-15T22:04:04.687Z
ambros-zalokar.at favicon

Mag. Boris Zalokar & Elke Blümel-Zalokar, MSc

ambros-zalokar.at

25
HealthcareAustriasmallHIGH

The website ambros-zalokar.at represents a small healthcare service provider specializing in psychological therapy, coaching, biofeedback, and corporate health management primarily serving clients in Austria. The business is positioned as a regional psychological practice with a focus on both individual and corporate clients, offering a broad range of mental health and workplace wellness services. The website content is well-structured, professionally presented, and provides clear contact information and service descriptions, targeting individuals and companies seeking psychological and health management support. Technically, the site is built on the IONOS MyWebsite CMS platform, leveraging Apache server technology and CDN services for content delivery. However, the site lacks HTTPS support due to an invalid or missing SSL certificate, which critically impacts security posture and user trust. Performance metrics are not provided, but the site is likely slow given the chunked transfer encoding and lack of optimization indicators. Mobile optimization is good, and basic SEO practices are in place, though accessibility features are minimal. From a security perspective, the absence of HTTPS and modern TLS protocols is a significant vulnerability. While some security headers are present, the lack of SSL/TLS encryption, HSTS, and incident response contact information exposes the site to risks. No privacy or cookie policies are published, indicating non-compliance with GDPR and related privacy regulations. No analytics or tracking scripts were detected, suggesting minimal user tracking. Overall, the website presents a credible business with professional content but suffers from critical security and privacy compliance gaps. Strategic improvements in SSL deployment, privacy policy publication, and security best practices are essential to enhance trust and protect user data.

35
-
-
50
-
85
-
psychologyhealthcarecoachingtherapybiofeedback+2 more
ApacheJavaScriptjQueryIONOS MyWebsite CMS+2
2025-06-15T22:03:46.223Z
L

L&R USA Inc.

lohmann-rauscher.com

39
HealthcareUnited StateslargeHIGH

Lohmann & Rauscher USA Inc. is a prominent international supplier specializing in medical devices and hygiene products, targeting healthcare professionals and patients. The company offers a broad portfolio including compression therapy, wound care, casting materials, and educational items. Their market position is strong, supported by recent acquisitions such as Unisurge International Ltd. and the teledermatology startup OnlineDoctor, indicating active growth and innovation. The website is professionally designed with comprehensive content and clear navigation, reflecting a mature digital presence. Technically, the site is built on TYPO3 CMS with modern JavaScript libraries and frameworks, but performance data is lacking and the site is currently not secured with HTTPS, which is a critical security gap. Security posture is weak due to the absence of a valid SSL certificate and lack of advanced security headers or policies. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism detected. Business credibility is high given the detailed contact information, structured data, and active corporate communications. Overall, the site requires urgent security improvements to protect user data and enhance trust.

15
25
17
85
-
85
85
healthcaremedicaldeviceswoundcarecompressiontherapycorporate+2 more
ApachejQueryBootstrapTYPO3 CMS+3

Partner Domains:

solarismed.com
partnerpending
lrmed.com
partnerpending
2025-06-15T22:03:26.602Z
Z

Zahnwerkstatt Selz

zahnselz.de

21
HealthcareGermanysmallCRITICAL

Zahnwerkstatt Selz is a small local dental workshop based in Germany, currently operating a website that is under construction. The site provides minimal information, primarily contact details including a phone number and an email address. The business appears to target local dental patients, offering dental care and workshop services. The website's market position is that of a small local dental practice with limited digital presence. Technically, the website is hosted on an Apache server with static HTML and CSS, lacking modern web technologies or CMS platforms. Performance and mobile optimization are poor, and the site lacks accessibility and SEO best practices. Critically, the website does not have a valid SSL/TLS certificate, serving content over HTTP only, which severely impacts security and trust. From a security perspective, the absence of HTTPS, security headers, and privacy policies indicates a low security posture. No vulnerabilities such as malware or phishing were detected, but the lack of basic security controls and compliance measures is a significant concern. The WHOIS data is consistent with a legitimate small business domain registration, with no suspicious patterns. Overall, the website presents a high risk due to lack of encryption and privacy compliance, minimal content, and poor technical implementation. Strategic improvements are necessary to enhance security, privacy, and user trust before the site can be considered professional or reliable.

15
-
-
50
-
85
20
underconstructiondentalhealthcarelocalbusiness
ApacheHTML5CSS3
2025-06-15T21:59:51.014Z
R

Romer Labs Division Holding GmbH

romerlabs.com

40
HealthcareAustriamediumHIGH

Romer Labs is a mature, globally recognized company specializing in innovative diagnostic solutions for food and feed safety, with a focus on mycotoxins, allergens, GMOs, and microbial contaminants. The company operates primarily in the healthcare sector, serving B2B clients such as laboratories and food industry professionals. It is a subsidiary of dsm-firmenich, reflecting strong corporate backing and market presence. The website is professionally designed, content-rich, and well-structured, supporting multiple languages and providing comprehensive resources including news, webinars, and product catalogs. Technically, the site is built on Magento CMS, hosted on AWS CloudFront, and integrates modern marketing and analytics tools such as Google Tag Manager, HubSpot forms, and Yoast SEO. While the site is mobile-optimized and SEO-friendly, performance metrics are not explicitly available. Security headers are implemented, but the lack of a valid SSL certificate and absence of TLS protocols represent critical vulnerabilities that significantly reduce the site's security posture. Privacy compliance is strong, with clear privacy and cookie policies and GDPR adherence. Contact information is transparent and easily accessible, including email, phone, and physical address. No WAF or blocking mechanisms are detected, and WHOIS data confirms domain legitimacy and maturity. Overall, the site is trustworthy and professional but requires urgent security improvements to protect user data and maintain trust.

-
-
5
50
-
75
100
foodsafetydiagnosticsmycotoxinsallergensgmo+4 more
MagentoJavaScriptjQueryGoogle Tag Manager+7
2025-06-15T21:59:47.573Z
A

Arjo

arjohuntleigh.com

40
HealthcareSwedenlargeHIGH

Arjo is a well-established global healthcare company specializing in medical devices and solutions aimed at improving mobility and care for patients with reduced mobility and age-related health challenges. The company operates in over 100 countries with a large workforce and offers a broad portfolio including patient handling equipment, medical beds, hygiene solutions, disinfection products, and prevention systems for pressure injuries and venous thromboembolism. The website reflects a mature digital presence with comprehensive content, clear navigation, and professional design tailored to healthcare providers and institutions. Technically, the website leverages modern web technologies including Episerver CMS, Azure hosting, and multiple analytics and marketing tools such as Google Analytics, Siteimprove, Hotjar, and Microsoft Application Insights. The site is hosted on Microsoft Azure with Cloudflare CDN, ensuring global availability and performance. However, performance metrics were not available, and accessibility is rated as basic, suggesting room for improvement. From a security perspective, the site implements several important HTTP security headers and a detailed Content Security Policy. Nevertheless, the SSL certificate is currently invalid or missing, which is a critical vulnerability that undermines user trust and data security. HSTS is configured but not fully enabled, and session resumption mechanisms are absent. No known vulnerabilities or malware were detected, and no WAF or blocking mechanisms interfere with site access. Overall, the website demonstrates strong business credibility and privacy compliance with clear policies and consent mechanisms. The main risk lies in the SSL certificate issue, which should be addressed promptly to maintain security posture and user confidence. Strategic recommendations include renewing the SSL certificate, enabling full HSTS, and enhancing accessibility and performance monitoring.

70
43
17
50
-
85
40
healthcaremedicaldevicespatienthandlingmedicalbedshygiene+6 more
JavaScriptWistia video embedsAzure Application InsightsSiteimprove Analytics+8
2025-06-15T21:58:28.695Z
vwr.com favicon

Avantor, Inc.

vwr.com

40
HealthcareUnited StatesenterpriseHIGH

VWR.com is the online presence of Avantor, Inc., a large enterprise specializing in providing life science products and service solutions. The website targets life science professionals and organizations globally, offering a broad range of scientific supplies and services. The business model is primarily B2B, with a strong market position as an established global supplier in the healthcare sector. The site uses localized subdomains to serve different countries, indicating a mature international presence. Technically, the website employs a variety of modern JavaScript libraries and tracking tools, including Google Analytics, Hotjar, and Cloudflare for CDN and security. However, the site lacks a valid SSL certificate and does not enable modern TLS protocols, which is a significant security concern. The content is professionally presented with good navigation and branding consistency, but mobile optimization and accessibility are basic. From a security perspective, while the site implements a comprehensive Content Security Policy and some security headers, the absence of HTTPS and modern TLS support severely impacts the security posture. No incident response or vulnerability disclosure information is provided, and no explicit contact details are available on the landing page, limiting transparency. Overall, the website is functional and professional but requires urgent improvements in SSL/TLS implementation and privacy compliance mechanisms to enhance trust and security. Strategic recommendations include installing a valid SSL certificate, enabling modern TLS protocols, implementing cookie consent mechanisms, and providing clear contact and security policy information.

55
18
5
85
-
85
100
lifesciencehealthcareb2benterprisescientificsupplies
JavaScriptGoogle AnalyticsCloudflareModernizr+2

Partner Domains:

avantorsciences.com
parentpending
2025-06-15T21:57:22.997Z
cbmed.org favicon

CBmed GmbH

cbmed.org

23
HealthcareAustriamediumCRITICAL

CBmed GmbH is a public-private partnership based in Graz, Austria, specializing in biomarker research to advance applied precision medicine and personalized healthcare. The organization collaborates globally with over 50 partners from academia and industry, focusing on innovative technologies such as ex vivo compound screening, microbiome research, and data science. Their business model centers on research and development services, supported by funded projects and a commitment to quality and innovation. The website reflects a mature, professional entity with consistent branding and comprehensive content tailored to healthcare professionals and collaborators. Technically, the website is built on WordPress with modern plugins like Yoast SEO and WPForms, hosted on an Apache server. While the site is mobile-optimized and SEO-friendly, performance metrics indicate slow loading times. Security posture is weak due to the absence of HTTPS, lack of security headers, and missing DNSSEC, exposing the site to potential risks. No explicit security or incident response policies are published, which could impact trust and compliance. Overall, the domain registration data aligns well with the business claims, showing a consistent and legitimate presence since 2014. Contact information is clearly provided, including multiple physical locations, email, phone, and a contact form. Privacy and cookie policies are present and GDPR compliant, with consent mechanisms in place. However, the critical lack of SSL/TLS encryption significantly lowers the security score and poses a risk to user data confidentiality. Strategically, CBmed should prioritize implementing HTTPS, enhancing security headers, and publishing security policies to improve trust and compliance. The website’s strong content and business credibility provide a solid foundation for growth and partnership expansion, but technical and security improvements are essential to safeguard operations and reputation.

15
18
5
50
-
70
-
healthcareprecisionmedicinebiomarkerresearchresearchtechnology
WordPress 6.6.2Yoast SEO pluginApache serverLivewire+4
2025-06-15T21:56:07.805Z
kh-herzjesu.at favicon

Herz Jesu Krankenhaus GmbH

kh-herzjesu.at

36
HealthcareAustriamediumHIGH

Herz Jesu Krankenhaus GmbH is a medium-sized, non-profit orthopaedic specialist hospital located in Vienna, Austria, operating under the parent company Vinzenz Kliniken Wien. The hospital offers specialized healthcare services in orthopaedics, rheumatology, osteology, remobilisation, and operates the largest pulmonological sleep laboratory in Vienna. The website targets patients, visitors, medical professionals, and job seekers, providing comprehensive information about services, events, and career opportunities. The hospital emphasizes professional, personal, and compassionate care with external quality certifications such as the 'Audit Beruf und Familie'. Technically, the website is built on TYPO3 CMS with Bootstrap and jQuery frameworks, delivering a responsive and well-structured user experience. However, the site suffers from slow loading times and lacks a valid SSL certificate, resulting in no HTTPS support, which is a critical security deficiency. The cookie consent mechanism and privacy policy are well implemented, reflecting good privacy compliance. Social media integration and external partnerships are clearly presented, enhancing the hospital's digital presence. From a security perspective, the absence of HTTPS and modern TLS protocols severely impacts the security posture, exposing users to potential risks. No advanced security headers or incident response information are found, indicating room for improvement in security maturity. The WHOIS data confirms the domain's legitimacy and consistency with the hospital's business claims. Overall, the website is professional and content-rich but requires urgent security enhancements, particularly SSL/TLS implementation, to protect user data and improve trust. Performance optimization and additional security best practices are recommended to elevate the site's technical and security standards.

30
-
5
50
-
85
100
healthcareorthopaedicshospitalaustriatypo3+3 more
TYPO3 CMSBootstrapjQueryFontAwesome
2025-06-15T21:55:14.385Z
cydeckt.com favicon

CardivAI GmbH

cydeckt.com

37
HealthcareN/asmallHIGH

CardivAI GmbH operates in the healthcare technology sector, specializing in generative AI-driven diagnostics for cardiovascular diseases. Their offerings include AI integrations, AWS cloud-based solutions architecture, and DevOps services tailored for mobile-first healthcare applications. The company positions itself as a niche provider leveraging advanced AI models such as Anthropic's Claude 4 and AWS infrastructure to deliver innovative healthcare diagnostics solutions. The website content and branding reflect a professional and consistent image targeting healthcare professionals and technology adopters in the medical diagnostics field. Technically, the website is hosted on AWS infrastructure using Amazon S3 and CloudFront, with modern frontend technologies including Bootstrap, Swiper, and JavaScript libraries for UI enhancements. Google Tag Manager and CookieYes scripts indicate moderate analytics and cookie consent management. However, the site lacks HTTPS support, which is a significant technical and security shortfall. Mobile optimization and SEO appear adequate, but performance metrics are unavailable. From a security perspective, the absence of a valid SSL/TLS certificate and HTTPS severely impacts the security posture, exposing users to potential data interception risks. No advanced security headers or protocols are implemented, and no incident response or vulnerability disclosure policies are evident. The use of AWS server-side encryption for content storage is a positive aspect, but overall security maturity is low. Privacy compliance is basic with cookie consent but lacks explicit GDPR compliance indicators. Overall, the website presents a credible business with professional content and clear contact information but requires urgent improvements in security, particularly enabling HTTPS and enhancing security headers. Strategic recommendations include implementing SSL/TLS, adopting security best practices, and formalizing privacy and incident response policies to improve trust and compliance.

15
-
5
50
-
80
100
healthcareaiawsclouddiagnostics+2 more
Amazon S3CloudFrontAWSGoogle Tag Manager+7
2025-06-15T21:55:01.326Z