clevelandclinic.org

B
Trust rating
Good · 85/100
Procurement snapshot
No critical findings. The 3 remaining items are configuration gaps, not architectural problems.
Strengths
TLS Configuration
DNS Configuration
DMARC / Email Security
MX Records & Mail Provider
Questions to ask
Confirm HSTS is enabled and its max-age setting
Sign in to see 1 more
Estimated remediation effort: 1–2 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change 1 scan · Last scanned February 15, 2026
Your rating Industry average
Score
100 75 50 25 0
B
clevelandclinic.org
85/100
Compliance & Certifications
Not yet verified
HIPAA
HIPAA
BAA not on file
Self-reported
Pro subscribers only
HI TRUST
HITRUST
Certificate not on file
3rd party
Pro subscribers only
SOC 2 TYPE II
SOC 2 Type II
Audit report not on file
3rd party · AICPA
Pro subscribers only
Incident History
None in 12 months
March 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
April 2023 – Feb 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
Security Posture
3 items need attention
7 passed
Increase how long HSTS stays remembered
HSTS Header
< 30 minutes

This briefly reopens an interception window for returning visitors. HSTS is already turned on for clevelandclinic.org, which is good — but it's only set to be remembered for 0 day(s), well under the 6-month minimum that's considered safe. A short duration means a returning visitor's browser "forgets" the HTTPS-only rule quickly, briefly reopening the same risk HSTS is meant to close.

PCI-DSS 4.0Req 6.4.1
Application security header configuration
How to fix this
1Update the existing header to the value below (same place you originally added it). You're using Cloudflare in front of this site — add it there, see https://developers.cloudflare.com/rules/transform/response-header-modification/create-dashboard/.
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
2Confirm it's live: search "http header checker" and enter clevelandclinic.org.
Report unlocked.
View all 7 passed checks
TLS Configuration
DNS Configuration
DMARC / Email Security
MX Records & Mail Provider
Known Breaches
CVE Exposure
Subprocessors & Tech Stack
Company Signals
Claim profile →
Operational risk
Low
11 yrs operating. Well-funded
Lynxradar · Composite signal
Last funding
$40B
Series F · Mar 2025 · SoftBank-led
Crunchbase ↗
Employees
~3,000
+40% YoY growth
LinkedIn ↗
Trust Resources
Claim profile →
Trust Center
trust.clevelandclinic.org ↗
Security page
clevelandclinic.org/security ↗
Privacy Policy
clevelandclinic.org/privacy ↗
DPA (Data Processing Agreement)
clevelandclinic.org/dpa ↗
Updated recently
Subprocessors List
clevelandclinic.org/policies/subprocessors ↗
Tech Stack Detected
Subprocessors
Cloudflare
Similar companies in Healthcare / Health Tech
Appears in
Claim profile →
SOC 2 Type II certified vendors
847 companies · Updated weekly by LynxRadar
Track
ISO 27001 certified SaaS
312 companies · Updated weekly by LynxRadar
Track
Top AI vendors by trust score
94 companies · LynxRadar ranking
Track
Enterprise-ready SaaS · Trust score A or above
203 companies · LynxRadar ranking
Track