ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

NYC Health + Hospitals data breach exposes records of 1.8 million people

New York City Health + Hospitals, the largest public healthcare system in the United States, disclosed a major cybersecurity breach affecting at least 1.8 million individuals after attackers gained access to internal systems for nearly three months and copied highly sensitive patient and identity data.


The health system said suspicious activity was detected on Feb. 2, prompting immediate steps to secure affected systems and launch an investigation with external cybersecurity specialists. Investigators later determined that an unauthorized actor accessed portions of the network between approximately Nov. 25, 2025, and Feb. 11, 2026, and extracted files containing personal, medical, financial, and biometric information.


The incident ranks among the largest healthcare data breaches disclosed so far in 2026 and raises significant concerns because the compromised data includes fingerprints and palm prints, which cannot be changed or replaced once exposed.


New York City Health + Hospitals, which serves more than one million New Yorkers annually, including many uninsured patients and Medicaid recipients, said the breach may have originated through a compromise involving an unnamed third-party vendor.


The organization said the exposed information varies by individual but may include health insurance policy information, Medicaid and Medicare identifiers, medical record numbers, diagnoses, medications, treatment plans, test results, medical imagery, billing and payment information, and claims data.


The compromised files may also contain Social Security numbers, driver’s license numbers, taxpayer identification numbers, passport details, financial account information, credit and debit card numbers, online account credentials, and precise geolocation data.


The inclusion of biometric information has intensified scrutiny of the breach because fingerprints and palm prints represent permanent identifiers that cannot be reset like passwords or payment cards. The health system did not specify whether the biometric records belonged to patients, employees, prospective hires, or multiple groups.


The investigation found that the attackers maintained access to affected systems for roughly 11 weeks. The timeline indicates the unauthorized activity continued for several days after suspicious behavior was first identified in early February.


New York City Health + Hospitals said the review of affected files remains ongoing and that the notification process required extensive analysis to determine which individuals and data types were involved.


In response to the breach, the health system said it deployed additional detection and security technologies, reset compromised credentials, strengthened monitoring rules designed to identify similar attack techniques, and updated remote access management controls intended to reduce the risk of future unauthorized access.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543