NYC Health + Hospitals network data incident

Unauthorized access to NYC Health + Hospitals systems from approximately November 25, 2025 through February 11, 2026, discovered on February 2. Files copied from affected systems containing varying personal, health, biometric, financial, and account information.

Last modified

Summary

  • Environment: Date NYC Health + Hospitals discovered suspicious activity affecting network systems.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to NYC Health + Hospitals systems from approximately November 25, 2025 through February 11, 2026, discovered on February 2. [2]

Impact

Files copied from affected systems containing varying personal, health, biometric, financial, and account information. [1][2]

Documented data types include:

  • Account credentials — Online account credentials; fields varied by individual. [2]
  • Driver’s license numbers — Driver’s license and other government-issued identification numbers; fields varied by individual. [2]
  • Payment card information — Credit or debit card numbers; fields varied by individual. [2]
  • Healthcare billing and claims information — Billing, claims, and payment information; fields varied by individual. [2]
  • Financial account information — Financial account information or credentials; fields varied by individual. [2]
  • Health insurance information — Health plans or policies, insurers, member or group IDs, and government-payor IDs; fields varied by individual. [2]
  • Biometric identifiers — Fingerprint and palm-print information; fields varied by individual. [2]
  • Social Security numbers — Social Security numbers; fields varied by individual. [2]
  • Clinical information — Medical record numbers, disability codes, diagnoses, medications, test results, images, or treatment plans; fields varied by individual. [2]
  • Precise geolocation data — Precise geolocation data; fields varied by individual. [2]

A cited record reports 1,800,000 individuals (Individuals listed in the HHS OCR incident report; regulator-reported and not independently verified; as of 2026-03-24). [1][2]

NYC Health + Hospitals said the unauthorized actor copied certain files from the affected systems. [2]

Timeline

  1. Activity began

    Approximate beginning of the unauthorized-access window stated in the first-party notice.

    [2]
  2. Discovery

    Date NYC Health + Hospitals discovered suspicious activity affecting network systems.

    [2]
  3. Documented activity ended

    Approximate end of the unauthorized-access window stated in the first-party notice.

    [2]
  4. Public disclosure

    Date of the public HIPAA substitute notice.

    [2]
  5. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The no-cost monitoring offer covered anyone who had been an NYC Health + Hospitals workforce member or patient at any time since 2020. NYC Health + Hospitals offered 24 months of no-cost Kroll identity-theft prevention, mitigation, and credit-monitoring services to the stated eligibility population. NYC Health + Hospitals deployed additional detection and protection, reset compromised-account credentials, added incident-specific detection rules, and updated remote-access policies. The ongoing investigation indicated that the actor may have gained access because of a security incident at an unnamed third-party vendor. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]