NYC Health + Hospitals—the largest public hospital system in the United States—disclosed that hackers rode a third-party vendor compromise into its environment and copied files for at least 1.8 million people.
Detection came on February 2, 2026. Forensics later put unauthorized access between roughly November 25, 2025 and February 11, 2026. The system reported the incident to HHS on March 24, 2026, making it one of the largest healthcare breaches of the year.
What happened
According to NYC H+H’s notice of data breach, an unauthorized actor accessed certain systems and copied files after a vendor pathway failed. This is the classic 2026 healthcare pattern: the hospital’s own perimeter is not the weak link—the supplier with legitimate access is.
TechCrunch and Malwarebytes reported that the stolen mix includes medical records, insurance and billing data, government IDs, geolocation metadata from identity-document uploads, and biometric fingerprints and palm prints often collected for employee background checks.
What data was exposed
- Diagnoses, medications, test results, and medical imagery
- Insurance, policy, billing, and claims information
- Social Security numbers, passports, and driver’s licenses (where present)
- Precise geolocation metadata tied to ID uploads
- Fingerprint and palm-print biometrics
Field lists vary by person. Read any letter you receive—do not assume every category applies to you.
Why biometrics cannot be “reset”
Passwords can be changed overnight. Payment cards can be cancelled. Raw fingerprints cannot. Once copied, biometric templates become a durable identity asset for attackers and a permanent liability for anyone who relied on those prints for background checks or facility access. That permanence is why this incident draws more attention than a routine PHI spill of the same headcount.
Who is at risk
Patients and employees across the NYC Health + Hospitals network. Expect medical-identity fraud (bogus claims on EOBs), tax fraud if SSNs appear on your notice, and phishing that name-drops clinics you actually used.
This vendor biometrics event is separate from the March 2026 Solventum HIS business-associate breach that affected a smaller NYC H+H patient subset (~59,000).
Context in the 2026 healthcare breach wave
Public hospital systems sit on dense identity graphs: patients, employees, contractors, and vendors all touch the same clinical and HR stores. When a vendor with file access is compromised, the blast radius is measured in millions, not thousands—and the clock often runs for months before detection. NYC H+H’s November-to-February window fits that pattern.
Regulators and patients will keep asking the same questions: which vendor, what contracts required encryption or logging, and how quickly individuals were told once HHS was notified in March. Those answers matter as much as the 1.8 million headline.
Action items
- Read any NYC H+H letter carefully and enroll in offered monitoring before deadlines.
- Freeze credit with Equifax, Experian, and TransUnion if SSNs or government IDs were listed.
- Monitor Explanation of Benefits and patient portals for services you did not receive.
- Treat “hospital biometric re-enrollment” or “badge reset” emails as hostile until verified by phone through a known number.
- Employees whose prints were collected for background checks should ask HR which vendor held the templates and what remediation is offered.
Canonical record
Full catalog entry: NYC Health + Hospitals vendor biometrics breach. Primary sources: NYC H+H notice, TechCrunch, Malwarebytes.