NYC Health + Hospitals Reports Data Breach

It appears that the unauthorized actor may have gained access to NYC Health + Hospitals systems due to a security breach at a third-party vendor.

By HFT Staff


On February 2, 2026, NYC Health + Hospitals discovered suspicious activity affecting certain systems in its computer network and immediately secured its network, began an investigation and engaged external cybersecurity professionals for support. The investigation determined that an unauthorized actor accessed certain NYC Health + Hospitals’ systems between approximately November 25, 2025, and February 11, 2026, and copied certain files from those systems.  

NYC Health + Hospitals’ review to identify the individuals and specific data elements involved remains ongoing. Although the investigation is ongoing, it appears that the unauthorized actor may have gained access to NYC Health + Hospitals systems due to a security breach at a third-party vendor. This notification was not delayed as a result of a law enforcement investigation. 

Based on the review to date, the information involved varies by individual, the affected information may include one or more of the following, though not every data element was involved for every affected individual: 

  • Health insurance information (such as plans/policies, insurance companies, member/group ID numbers and Medicaid-Medicare-government payor ID numbers); 
  • Medical information (such as medical record numbers, disability codes, diagnoses, medications, test results, images, or treatment plans); 
  • Biometric information (including fingerprints and palm prints); 
  • Billing, claims, and payment information; or 
  • Other personal information such as Social Security numbers, driver’s license numbers or other government-issued identification numbers, taxpayer identification numbers or IRS-issued identity protection numbers, precise geolocation data, credit or debit card numbers, financial account information or credentials or online account credentials. 

Upon discovering the incident, NYC Health + Hospitals immediately launched a thorough investigation with the support of a leading cybersecurity firm. NYC Health + Hospitals also engaged a leading data analytics firm to analyze the contents of the data that may have been accessed without authorization. The investigation is ongoing. 

To protect against future security incidents, NYC Health + Hospitals has taken a number of steps, including deploying additional detection and protective technologies across its network. It reset credentials for all compromised accounts, implemented enhanced detection rules targeting the specific tools and techniques suspected to be used by the unauthorized individual and updated its remote access management policies to prevent similar unauthorized entry points in the future. 



March 26, 2026


Topic Area: Information Technology , Security


Recent Posts

Cleanliness Is a Measurable Outcome

By restoring the distinction between cleaning and cleanliness, managers and staffs can better protect patients from environmental pathogens.


Workplace Safety and the Role of Access Control

Workplace violence and other issues threaten patients, staff and operations, so managers need to rethink security measures and technology.


Henry Ford Hospital Celebrates Construction Milestone for Expansion Project

Crews from BTD, a joint venture created by Barton Malow, Turner Construction and Dixon Construction, are on track to complete the hospital in 2029.


How EVS Leaders Can Support Staff for Better Cleaning

Environmental services is one of the most important departments in healthcare facilities, but it can be a difficult one to manage.


Addressing Infection Prevention Staffing Gaps in Ambulatory and Procedural Care

Traditional models that are based on inpatient bed counts fail to account for the unique demands of ambulatory and procedural settings.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.