NYC Health + Hospitals Loses Fingerprints of 1.8 Million in Vendor Attack

Hackers accessed NYC Health + Hospitals systems for over two months via a third-party vendor, stealing medical records, SSNs and fingerprints from 1.8 million people. The biometric data cannot be replaced, creating permanent risk for vulnerable patients. The incident highlights persistent gaps in vendor oversight across healthcare.
NYC Health + Hospitals Loses Fingerprints of 1.8 Million in Vendor Attack
Written by Ava Callegari

New York City Health + Hospitals has revealed one of the most troubling healthcare breaches in recent memory. Hackers stole personal records, medical histories and fingerprints from at least 1.8 million people. The compromised data cannot be replaced for those affected.

The public health system, which serves more than a million New Yorkers annually, many uninsured or on Medicaid, detected suspicious activity on February 2, 2026. It secured its network right away. Yet the intruders had already operated inside its systems for more than two months.

Access began around November 25, 2025 and continued until February 11, 2026. During that window the unauthorized actor copied files containing a wide array of sensitive details. Names. Social Security numbers. Diagnoses. Medications. Insurance identifiers. And biometrics.

According to the official notice posted by NYC Health + Hospitals, the stolen information varies by individual but may include health insurance details, medical records such as treatment plans and test results, billing data, government identification numbers, precise geolocation information and crucially biometric records including fingerprints and palm prints. (NYC Health + Hospitals Notice of Data Breach)

TechCrunch first highlighted the scale on May 18, reporting the breach as one of the largest healthcare incidents of the year. The publication noted that fingerprints and palm prints, once taken, stay compromised for life. No reset exists. (TechCrunch)

The Next Web added further color the same day. It pointed out that the health system did not explain why it held biometric data in the first place. Most observers suspect the prints belonged to employees required to submit them for background checks. Whether patient fingerprints were taken remains unclear. Yet the notice lists biometrics among possible compromised categories. (The Next Web)

Entry came through a third-party vendor. NYC Health + Hospitals has not named the supplier. Investigators believe the attackers first broke into the vendor’s environment and then used trusted connections to reach the hospital network. This pattern repeats across the sector. Change Healthcare’s 2024 breach, which exposed records of over 190 million Americans, followed a similar route.

But this case carries extra weight. NYC Health + Hospitals operates 11 acute care hospitals, five nursing facilities and more than 70 clinics across all five boroughs. Its patients often come from low-income, immigrant or medically underserved communities. They possess fewer resources to fight identity theft or monitor accounts over decades.

Biometric compromise changes the risk equation. Credit cards get replaced. Passwords get updated. Fingerprints do not. Criminals could use them for account takeovers, impersonation or even physical access attempts in systems that rely on fingerprint readers. Precise geolocation data taken alongside photos of identity documents adds another layer. It reveals exactly where and when documents were scanned.

The health system responded by hiring external cybersecurity experts and a data analytics firm. It reset credentials, added detection tools and tightened remote access rules. Out of caution it offers 24 months of free credit monitoring and identity protection through Kroll to anyone who has been a patient or employee since 2020. A toll-free line at (844) 403-4518 stays open through at least June.

Notification arrived weeks after containment. The official notice appeared March 24, more than seven weeks after discovery. No law enforcement request delayed it. A spokesperson did not answer questions about detection time, ransom demands or specific remediation steps when contacted by reporters.

This incident stands apart from a smaller breach earlier in 2026. That one involved a subcontractor working with the National Association on Drug Abuse Problems and touched roughly 5,000 NYC Health + Hospitals patients. Officials say the two events share no connection.

Healthcare remains a prime target. The FBI’s 2025 cybercrime report listed the sector high on ransomware actors’ lists. Criminals steal data, encrypt systems and demand payment to avoid leaks. Medical records sell well on underground markets because they support insurance fraud, prescription scams and convincing phishing that impersonates doctors.

Costs run high too. Industry figures put the average healthcare breach expense above $7 million in 2025. Detection often takes months. Here the gap exceeded 70 days before alarms sounded. Public systems like NYC Health + Hospitals frequently work with tighter budgets and legacy technology. Advances in artificial intelligence for threat hunting have yet to close those windows for everyone.

Patients face practical steps now. Review statements. Check credit reports. Consider fraud alerts or security freezes. Change passwords if online credentials were involved. The offered Kroll service provides one layer of help, but vigilance must last years because biometric data offers permanent value to thieves.

Lawyers have already begun investigating potential suits on behalf of affected individuals. Class actions could focus on the storage of irreplaceable biometrics and the delayed discovery through a vendor relationship.

The breach throws fresh light on third-party risk. Healthcare organizations share data with billing platforms, record vendors, analytics firms and background check services. Each link creates an entry point. Many boards still treat vendor reviews as a checkbox exercise rather than a continuous discipline.

NYC Health + Hospitals says its investigation continues. It promises updates if new facts emerge. For the 1.8 million people whose fingerprints now sit in unknown hands, those updates cannot arrive soon enough. The fingerprints will not change. The exposure will not expire.

Regulators at the Department of Health and Human Services have received the filing. The agency’s breach portal will track follow-up. Yet enforcement actions move slowly. In the meantime the people who rely on the city’s safety-net hospitals must shoulder lifelong uncertainty about how their most personal physical identifiers might be used against them.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us