← Blog

Solventum Breach: 59K NYC Hospital Patients Hit

Share on X

March 29, 2026: Solventum Health Information Systems suffered a data security incident that exposed protected health information for roughly 59,000 patients of NYC Health + Hospitals, the largest public health system in the United States. Solventum discovered the intrusion on March 30 and notified the hospital system on April 21. On April 19, the threat actor posted stolen patient data to the dark web.

What happened

Solventum operates behind the scenes at hospitals — health-information technology and analytics that never show up on a patient wristband. Most people who ended up in this breach likely never heard the company name until a letter or news alert arrived.

The unauthorized access occurred on or around March 29, 2026. Solventum engaged forensic experts and said its core production systems and live hospital connections kept running; the hit was against data the business associate held, not a shutdown of clinical operations.

NYC Health + Hospitals posted a patient notification and stood up a response line. If you treated at Bellevue, Harlem, Kings County, Elmhurst, or any other NYC H+H facility, the breach path is the same vendor layer — not a break-in at the bedside registration desk.

What data was exposed

According to Solventum and NYC Health + Hospitals disclosures, affected information varies by person but may include:

  • First and last names
  • Addresses
  • Dates of birth
  • Medical record numbers
  • Medical histories
  • Diagnoses

This is clinical identity data — enough to fuel insurance fraud, targeted phishing, or blackmail in sensitive cases. It is not the same category as a stolen credit card you can reissue overnight.

Who is at risk

Patients whose records flowed through Solventum systems tied to NYC Health + Hospitals during the affected window. Because Solventum does not bill patients directly, many victims learn about the incident from the hospital or a third-party notice, not from a line item on a statement.

Action items

  1. Call the dedicated line at 1-855-830-9403 (9 a.m.–9 p.m. ET, Mon–Fri) or visit response.idx.us/solventum to confirm whether your record was involved.
  2. Review Explanation of Benefits and clinic bills for services you did not receive.
  3. Be skeptical of texts or emails citing a specific diagnosis or MRN — attackers who bought dark-web dumps use those details to sound legitimate.
  4. Report suspected medical identity theft to your insurer and IdentityTheft.gov.

Canonical record: Solventum 2026 breach on BreachHistory.