Summary
- Environment: Date NYC Health + Hospitals discovered suspicious activity affecting network systems.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Unauthorized access to NYC Health + Hospitals systems from approximately November 25, 2025 through February 11, 2026, discovered on February 2. [2]
Impact
Files copied from affected systems containing varying personal, health, biometric, financial, and account information. [1][2]
Documented data types include:
- Account credentials — Online account credentials; fields varied by individual. [2]
- Driver’s license numbers — Driver’s license and other government-issued identification numbers; fields varied by individual. [2]
- Payment card information — Credit or debit card numbers; fields varied by individual. [2]
- Healthcare billing and claims information — Billing, claims, and payment information; fields varied by individual. [2]
- Financial account information — Financial account information or credentials; fields varied by individual. [2]
- Health insurance information — Health plans or policies, insurers, member or group IDs, and government-payor IDs; fields varied by individual. [2]
- Biometric identifiers — Fingerprint and palm-print information; fields varied by individual. [2]
- Social Security numbers — Social Security numbers; fields varied by individual. [2]
- Clinical information — Medical record numbers, disability codes, diagnoses, medications, test results, images, or treatment plans; fields varied by individual. [2]
- Precise geolocation data — Precise geolocation data; fields varied by individual. [2]
A cited record reports 1,800,000 individuals (Individuals listed in the HHS OCR incident report; regulator-reported and not independently verified; as of 2026-03-24). [1][2]
NYC Health + Hospitals said the unauthorized actor copied certain files from the affected systems. [2]
Timeline
Activity began
Approximate beginning of the unauthorized-access window stated in the first-party notice.
[2]Discovery
Date NYC Health + Hospitals discovered suspicious activity affecting network systems.
[2]Documented activity ended
Approximate end of the unauthorized-access window stated in the first-party notice.
[2]Public disclosure
Date of the public HIPAA substitute notice.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
The no-cost monitoring offer covered anyone who had been an NYC Health + Hospitals workforce member or patient at any time since 2020. NYC Health + Hospitals offered 24 months of no-cost Kroll identity-theft prevention, mitigation, and credit-monitoring services to the stated eligibility population. NYC Health + Hospitals deployed additional detection and protection, reset compromised-account credentials, added incident-specific detection rules, and updated remote-access policies. The ongoing investigation indicated that the actor may have gained access because of a security incident at an unnamed third-party vendor. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]
