NYC Health + Hospitals disclosed that attackers accessed its network for nearly three months and copied sensitive files affecting about 1.8 million people. The intrusion reportedly began around November 25, 2025 and continued until February 11, 2026, with suspicious activity first detected on February 2. The organization said the breach appears to have originated through a compromised third-party vendor and later reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights.
Stolen information included personal and medical records, insurance and billing details, payment data, government-issued identifiers, precise geolocation data, and biometric data such as fingerprints and palm prints, raising particular concern because biometric identifiers cannot be reissued once exposed. NYC Health + Hospitals said it engaged external cybersecurity specialists, reset affected credentials, added security technologies, strengthened monitoring and detection rules, updated remote access controls, and is offering two years of Kroll identity theft protection and credit monitoring to affected patients and employees.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
By the time of the May 2026 disclosures, NYC Health + Hospitals had reported to the U.S. Department of Health and Human Services Office for Civil Rights that about 1.8 million individuals were affected. The organization also said it implemented added security controls, reset credentials, strengthened monitoring and remote access policies, and offered two years of Kroll identity theft and credit monitoring services.
On 2026-03-24, NYC Health + Hospitals announced the cyber incident and data breach. The organization said it had engaged external cybersecurity specialists and was reviewing affected files.
On 2026-03-11, NYC Health + Hospitals disclosed a separate third-party-related hacking incident involving care management partner National Association on Drug Abuse Programs. The notice said 5,086 patients were affected, making it a distinct incident from the later 1.8 million-person breach.
NYC Health + Hospitals said the attackers' access to its network lasted until about 2026-02-11. During the intrusion, sensitive personal, medical, financial, government ID, geolocation, and biometric data was copied.
The organization identified suspicious activity on its systems on 2026-02-02 and said it subsequently secured its network. The intrusion nevertheless continued until about 2026-02-11, according to the breach timeline disclosed later.
NYC Health + Hospitals said unauthorized access to its network began around 2025-11-25, apparently via a compromised third-party vendor. Attackers remained in the environment for months and copied files from internal systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourceteiss.co.uk
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.