ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

NYC Health + Hospitals reports second data breach of 2026 compromising patients’ information

NYC Health + Hospitals disclosed a data security incident stemming from a cyberattack targeting its service provider, Solventum Health Information Systems, which compromised information maintained by the provider on behalf of the health system.

 

NYC Health + Hospitals is the largest public health care system in the United States, delivering a wide range of medical services through hospitals, outpatient facilities, and community-based programs across New York City. As part of its operations, the health system relied on Solventum Health Information Systems, a health care technology service provider that supported the management, processing, and maintenance of certain information on behalf of NYC Health + Hospitals.

 

In a data security incident notice posted on its website, NYC Health + Hospitals said that on March 29, threat actors gained unauthorised access to certain Solventum systems containing confidential information maintained on behalf of the public health provider. The healthcare insurance provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.

 

It also took steps to secure the affected systems including taking the affected accounts offline and notified relevant law enforcement authorities about the incident.

 

“The incident, which involved the unauthorised access to PHI by a Threat Actor, occurred on or around March 29,2026.  Solventum notified NYC Health + Hospitals of the disclosure on April 21, 2026,” the healthcare provider said.

 

The compromised data included patients’ names, addresses, dates of birth, medical record numbers, medical history, and diagnoses. The incident was reported to the U.S. Department of Health and Human Services where NYC Health + Hospitals said it has identified at least 58,778 individuals impacted by the incident.

 

 

In April, a threat actor claimed responsibility for the cyber attack on Solventum and listed the company as a victim on its data leak site. The cyber criminal said it had stolen confidential information, including Jira tickets, Confluence data, a Microsoft Entra (Azure AD) directory dump, and internal operational data.

 

Acknowledging reports of the cyberattack, Solventum confirmed in a data security incident notice that it experienced a significant data security incident affecting the personal and health information of thousands of individuals.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543