New York public well being supplier NYC Well being and Hospitals says a months-long data breach that allowed hackers to steal private knowledge, medical information, and fingerprints scans impacts a minimum of 1.8 million folks.
NYCHHC is the biggest public well being system in the USA and gives healthcare to over a million New Yorkers, nearly all of whom are uninsured or obtain state healthcare advantages, comparable to Medicaid.
The healthcare system reported the quantity to the U.S. Division of Well being and Human Providers, making it one of many largest healthcare-related knowledge breaches of the 12 months to this point. Healthcare organizations have been repeatedly focused by financially motivated cybercriminals in recent times in efforts to steal their huge banks of extremely delicate sufferers’ private, medical, and billing data.
In an information breach discover on its web site, NYCHHC mentioned that it detected a cyberattack on February 2 and secured its community. The hackers had entry to its community from November 2025 till February 2026, throughout which the hackers copied information from its programs.
The healthcare system mentioned hackers broke as a consequence of a breach at a third-party vendor, which it didn’t title.
NYCHHC mentioned that the uncovered knowledge varies by particular person, and consists of sufferers’ medical insurance plan and coverage data, medical data (comparable to diagnoses, medicines, checks, and imagery), billing, claims, and cost data. Different government-issued id paperwork, comparable to Social Safety numbers, passports, and driver’s licenses, had been additionally compromised.
The breach discover additionally says “exact geolocation knowledge” was taken within the breach, suggesting that the user-uploaded images of their id paperwork could have additionally contained the precise location of the place the doc was captured.
The breach is especially delicate as a result of hackers stole biometric data, together with fingerprints and palm prints, which affected people have for all times and can’t exchange. NYCHHC didn’t present a proof for storing biometric knowledge. Potential NYCHHC workers are usually required to enroll their fingerprints for legal information checks. It’s not but recognized if sufferers’ biometrics had been additionally taken.
NYCHHC’s web site was briefly offline as of Monday morning. A spokesperson for NYCHHC didn’t instantly reply to an electronic mail from TechCrunch with questions concerning the cyberattack. TechCrunch requested, amongst different issues, why it took the group months to detect the breach, and if it has obtained any communication from the hackers, comparable to a requirement for cost.
It’s not clear if NYCHHC can obtain electronic mail on the time of the web site outage.
The incident seems to be unrelated to the information breach at Nationwide Affiliation on Drug Abuse Issues (NADAP) earlier this year, during which over 5,000 NYCHHC sufferers had data taken within the cyberattack.
Within the FBI’s newest annual report on cybercrime protecting 2025, healthcare remained a high goal for ransomware attackers — criminals who break into databases, steal a duplicate of the information whereas scrambling the sufferer’s servers, and threaten to publish the stolen knowledge if the sufferer doesn’t pay the hackers. A ransomware assault on UnitedHealth-owned well being tech big Change Healthcare allowed Russian-linked hackers to steal the medical and billing information of more than 190 million Americans, believed to be the biggest theft of U.S. medical knowledge in historical past.
Once you buy via hyperlinks in our articles, we may earn a small commission. This doesn’t have an effect on our editorial independence.

