Sen. Bill Cassidy, chair of the U.S. Senate health committee, has demanded answers from New York City officials about a 2025 cyberattack on New York City Health + Hospitals that affected 1.8 million individuals. In a June 4 letter to CEO Mitchell Katz and Mayor Zohran Mamdani, Cassidy asked when the breach was discovered, what cyber and physical security controls were in place, and what remediation steps have been taken or are planned.
New York City Health + Hospitals previously said the intrusion appeared to originate from a security breach at an unnamed third-party vendor. Exposed data reportedly included insurance information, medical records, billing claims, Social Security numbers, payment card numbers, and biometric data including fingerprints and palm prints. The incident has drawn congressional attention because the organization is the nation’s largest municipal public health system, serving more than 1 million patients annually across roughly 70 care locations in New York City.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
New York City Health + Hospitals disclosed that a 2025 cyberattack affected 1.8 million individuals. The compromised data reportedly included insurance information, medical information, billing claims, Social Security numbers, payment card numbers, and biometric data such as fingerprints and palm prints.
On 2026-06-04, Sen. Bill Cassidy sent a letter to NYC Health CEO Mitchell Katz and Mayor Zohran Mamdani seeking details about the breach, security controls, discovery timing, and remediation steps. The inquiry reflected congressional scrutiny of the incident and broader concern about cyber threats to healthcare.
On 2026-03-24, NYC Health said the attackers appeared to have gained access through a security breach at an unnamed third-party vendor. This statement provided the first cited explanation in the references for the intrusion path.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcehelp.senate.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.