NYC Health + Hospitals Reports Data Breach

It appears that the unauthorized actor may have gained access to NYC Health + Hospitals systems due to a security breach at a third-party vendor.

By HFT Staff


On February 2, 2026, NYC Health + Hospitals discovered suspicious activity affecting certain systems in its computer network and immediately secured its network, began an investigation and engaged external cybersecurity professionals for support. The investigation determined that an unauthorized actor accessed certain NYC Health + Hospitals’ systems between approximately November 25, 2025, and February 11, 2026, and copied certain files from those systems.  

NYC Health + Hospitals’ review to identify the individuals and specific data elements involved remains ongoing. Although the investigation is ongoing, it appears that the unauthorized actor may have gained access to NYC Health + Hospitals systems due to a security breach at a third-party vendor. This notification was not delayed as a result of a law enforcement investigation. 

Based on the review to date, the information involved varies by individual, the affected information may include one or more of the following, though not every data element was involved for every affected individual: 

  • Health insurance information (such as plans/policies, insurance companies, member/group ID numbers and Medicaid-Medicare-government payor ID numbers); 
  • Medical information (such as medical record numbers, disability codes, diagnoses, medications, test results, images, or treatment plans); 
  • Biometric information (including fingerprints and palm prints); 
  • Billing, claims, and payment information; or 
  • Other personal information such as Social Security numbers, driver’s license numbers or other government-issued identification numbers, taxpayer identification numbers or IRS-issued identity protection numbers, precise geolocation data, credit or debit card numbers, financial account information or credentials or online account credentials. 

Upon discovering the incident, NYC Health + Hospitals immediately launched a thorough investigation with the support of a leading cybersecurity firm. NYC Health + Hospitals also engaged a leading data analytics firm to analyze the contents of the data that may have been accessed without authorization. The investigation is ongoing. 

To protect against future security incidents, NYC Health + Hospitals has taken a number of steps, including deploying additional detection and protective technologies across its network. It reset credentials for all compromised accounts, implemented enhanced detection rules targeting the specific tools and techniques suspected to be used by the unauthorized individual and updated its remote access management policies to prevent similar unauthorized entry points in the future. 



March 26, 2026


Topic Area: Information Technology , Security


Recent Posts

Infrastructure Issues: Assisting Mobility-Challenged Visitors

Parking constraints, mobility needs and patient experience priorities are elevating arrival pathways as a strategic planning issue.


Willis-Knighton Medical Center Upgrades Chilled Water Plant

The medical center sought upgrades through Trane to add capacity, control comfort, increase redundancy and reduce energy costs.


NYC Health + Hospitals Reports Data Breach

It appears that the unauthorized actor may have gained access to NYC Health + Hospitals systems due to a security breach at a third-party vendor.


Redefining What Mental Health Facilities Look Like

A new Mental Health and Addictions Center uses design and architecture to challenge the stigma and create a more open model of care.


Managing High-Volume Laundry Operations 

Tips and tricks one director has learned in three decades of managing a large, high-volume laundry operation.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.