2026 Solventum HIS — March BA breach; ~59k NYC Health + Hospitals patients (PHI on dark web Apr 19)
Data compromised
PHI including names, addresses, dates of birth, medical record numbers, medical histories, and diagnoses; threat actor posted accessed patient information to the dark web on April 19, 2026
Technical writeup
Solventum Health Information Systems (Solventum HIS), a medical-technology business associate serving hospitals, disclosed a data security incident on or around March 29, 2026, discovered March 30, 2026. NYC Health + Hospitals reported that Solventum notified it on April 21, 2026 that PHI of certain NYC Health + Hospitals patients was affected; circulating July 2026 reporting cited nearly 59,000 patients in the NYC subset. Solventum's investigation indicated accessed PHI could include names, addresses, dates of birth, medical record numbers, medical histories, and diagnoses. On April 19, 2026 the threat actor posted accessed patient information to the dark web, according to Solventum and NYC Health + Hospitals notices summarized by ClassAction.org. Solventum stated its core production systems and hospital connections were not disrupted. This March 2026 Solventum BA incident is distinct from NYC Health + Hospitals' separate November 2025–February 2026 vendor-network breach affecting 1.8M+ individuals (`new-york-city-health-hospitals-vendor-biometrics2026`).
Root cause
Unauthorized access to Solventum Health Information Systems systems by a threat actor (March 29, 2026); business-associate breach affecting NYC Health + Hospitals patients per company and hospital notices