New York City Health and Hospitals Corporation
Incident posture
Linked entities
- Victim
- New York City Health and Hospitals Corporation
- Threat actors
- 0 actors
- Sources
- 6 sources
Timeline
Summary
Unauthorized user accessed NYC Health + Hospitals systems between Nov 25 2025 and Feb 11 2026, discovered Feb 2 2026, compromising patient data including health insurance, medical, biometric, billing, SSN, and geolocation; individuals notified March 24 2026.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Between November 2025 and February 2026, an unauthorized user maintained access to systems operated by New York City Health + Hospitals, the largest public health system in the United States, ultimately exposing sensitive personal, medical, and biometric data belonging to at least 1.8 million individuals. The healthcare provider first detected suspicious activity on its network on February 2, after which it secured the affected systems. An internal investigation subsequently determined that the unauthorized user had been able to access NYCHHC's systems between November 25 and February 11, copying files during that window. According to NYCHHC's own data breach notice, the intrusion was traced to a security breach at a third-party vendor, which the organization did not name. The system reported the incident to the U.S. Department of Health and Human Services, where the breach was logged as affecting approximately 1.8 million people, making it one of the largest healthcare-related data incidents disclosed that year. Notification letters to affected individuals were issued beginning March 24, with NYCHHC stating that the timing of its notification was not delayed as a result of any law enforcement investigation. The precise entry vector, identity of the threat actors, and whether the attackers were a known cybercrime group were not publicly identified, and no ransomware group had claimed the incident at the time of reporting.
The data exposed varied by individual but included health insurance plan and policy information, medical information such as diagnoses, medications, tests, and imagery, as well as billing, claims, and payment information. Additional compromised information included government-issued identity documents such as Social Security numbers, passports, and driver's licenses. Notably, biometric information including fingerprints and palm prints was also stolen, which security observers noted was particularly sensitive because such identifiers cannot be replaced over the course of an individual's life. NYCHHC did not initially explain why it stored biometric data, though prospective NYCHHC employees are generally required to enroll their fingerprints for criminal records checks, and it was not yet known if patients' biometrics were taken in addition to staff data. The breach notice also indicated that "precise geolocation data" was taken, suggesting that user-uploaded photos of identity documents may have contained metadata revealing the exact location where the document was captured. Because the breach was linked to a third-party vendor, the full scope of systems and downstream data flows affected remained incompletely described in public statements.
In response to the discovery, NYCHHC secured its network on February 2 and proceeded to investigate the scope of the intrusion. The organization publicly touted several steps it took to prevent future attacks, including the deployment of new detection and protection technologies. The healthcare system also reported the breach to federal regulators, complying with the HIPAA-mandated reporting requirement for breaches affecting 500 or more individuals. On June 4, Senate Health, Education, Labor and Pensions (HELP) Committee Chairman Senator Bill Cassidy, M.D., R-La., sent a letter to NYCHHC CEO Mitchell Katz, M.D., and to the administration of New York Mayor Zohran Mamdani, seeking detailed information about the incident. The letter requested specifics on the security protocols employed, whether the system was adopting best cyber practices from other critical industries, when federal authorities were notified, how the breach was investigated, and what remedial measures had been taken or were planned. Cassidy also asked the organization to outline any additional reporting it intended to provide to affected individuals beyond what HIPAA requires. The Senator's office set a June 18 deadline for a response from NYCHHC officials. The New York City hospital system's public website was briefly offline on May 18 as the breach disclosures drew media attention, and a NYCHHC spokesperson did not immediately respond to inquiries from reporters regarding the timeline of detection, possible communications from the attackers, or whether any payment demand had been received.
The wider regulatory environment around the breach included ongoing federal attention to healthcare cybersecurity. Cassidy and Senate colleagues Maggie Hassan (D-NH), John Cornyn (R-TX), and Mark Warner (D-VA) had reintroduced the Health Care Cybersecurity and Resilience Act in December, a bill intended to strengthen protections for Americans' health data, which advanced out of the Senate HELP committee in February. In 2025, the U.S. Department of Health and Human Services' breach portal recorded 435 healthcare data breaches affecting 500 or more individuals, although Cassidy's letter referenced 628 reported breaches, illustrating differences in counting methodology. The NYCHHC incident, while significant, was not the largest healthcare breach of the period; Conduent Business Services had earlier reported a breach impacting 62 million individuals, and Nacogdoches Memorial Hospital in Texas was listed on the HHS tracker as affecting 2.5 million. Separately, NYCHHC was connected to another earlier data security incident involving the National Association on Drug Abuse Problems (NADAP), a Care Management Agency Partner that provides coordination services under the Lead Health Home program. That NADAP incident, discovered in January, affected over 5,000 NYCHHC patients and occurred on or around November 26, 2025, though NYCHHC stated that the NYCHHC and NADAP incidents appeared unrelated. The FBI's 2025 cybercrime report noted that healthcare remained a top target for ransomware actors, who typically copy sensitive data, scramble victim systems, and threaten publication unless paid, with 460 ransomware attacks and 182 data breaches, totaling 642 cyber events across the sector.
Sources
Sources available to members: 6 sources.