New York City Health + Hospitals said it is notifying patients after two separate third-party hacking incidents exposed sensitive health and personal data. In the more recent case, disclosed in a March 24 notice, an unnamed vendor suffered a security breach that may have compromised medical, insurance, biometric, financial, and identity information tied to an undisclosed number of patients. The health system said attackers may have retained access to the vendor’s systems for nearly three months before the intrusion was detected.
In a separate notice issued earlier, NYC Health + Hospitals said 5,086 patients were affected by a hacking incident at the National Association on Drug Abuse Programs (NADAP), a care management agency partner. The hospital system said the two breaches were unrelated, while the NADAP incident reportedly affected about 90,000 individuals across multiple clients, underscoring the continuing risk that healthcare providers face from compromises at outside partners and service providers.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
When disclosing the vendor-related incident, NYC Health + Hospitals stated that the unnamed vendor breach and the earlier NADAP breach were separate, unrelated incidents. This clarified attribution and scope across the two third-party compromises.
In a March 24, 2026 notice, NYC Health + Hospitals disclosed a separate third-party security incident involving an unnamed vendor. The organization said attackers had access for nearly three months before detection and that sensitive medical, insurance, biometric, financial, and personal information may have been exposed.
A hacking incident at care management partner National Association on Drug Abuse Programs (NADAP) exposed data affecting NYC Health + Hospitals patients. The breach reportedly impacted about 90,000 individuals across multiple NADAP clients, including 5,086 NYC Health + Hospitals patients.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.