NYC Health + Hospitals Breach Exposed 1.8 Million Records
Coverage from Morningstar, TechCrunch, and others
Articles
27
Active Days
72
The Topic

A series of breaches and privacy incidents is exposing highly sensitive information through healthcare providers, business associates, public-sector vendors, and poorly handled records. The most significant incidents involve NYC Health + Hospitals, including a major intrusion affecting about 1.8 million people and a separate vendor breach affecting 58,778 patients, while broader reporting shows hacking remains the dominant source of large healthcare breaches. The incidents demonstrate how third-party access, weak monitoring, social engineering, and inadequate records handling can expose medical, identity, biometric, and other difficult-to-replace data.
First Article: 05/18/26
Latest Article: 07/28/26
Summary
- NYC Health + Hospitals reported a breach affecting at least 1.8 million people after attackers accessed systems from November 2025 through February 2026 via an unnamed third-party vendor.
- The exposed NYC data reportedly included medical records, insurance and billing details, government identification documents, fingerprints, palm prints, and potentially precise geolocation data.
- A separate Solventum incident exposed information belonging to 58,778 NYC Health + Hospitals patients, with data reportedly posted on the dark web.
- HHS reporting for March 2026 recorded 44 healthcare breaches affecting more than 1.5 million people; 40 involved hacking or IT-related events.
- The incidents show persistent exposure created by business associates, development and testing environments, employee accounts, and other third-party access paths.
- A Singapore Land Authority vendor incident potentially exposed NRIC numbers and addresses in a dataset intended for testing, while a Pennsylvania borough case involved discarded payroll records.
History
This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.
