NYC Health + Hospitals (NYCHHC), the largest US public-hospital system, has begun notifying at least 1.8 million people that their personal and medical data was stolen in a cyberattack disclosed on 18 May 2026. The exfiltrated material includes biometric scans (fingerprints among them), which is unusual: most large US healthcare breaches involve administrative and clinical data but not biometric identifiers, and biometrics cannot be re-issued the way an account number can.
The system says the intrusion began through an unnamed third-party vendor in November 2025 and went undetected until 2 February 2026, when NYCHHC detected and contained the activity. The three-month dwell time is consistent with the broader 2026 pattern of identity-via-vendor compromises in healthcare. NYCHHC has not attributed the attack publicly.
Two issues merit attention. First, the breach comes as the HHS Office for Civil Rights is understood to be finalising tighter requirements around third-party risk management in healthcare, and a 1.8-million-record vendor-route incident at the country's largest public system will be a difficult test case for the existing regime. Second, the biometric exposure raises a question for digital-health design: how authentication and remediation should be handled for patients whose fingerprint templates are held by an attacker.
Sources
Sources: NYC Health + Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people (TechCrunch, 18 May 2026); NYC Health + Hospitals says hackers stole fingerprints, medical data of 1.8M patients (Cybernews); Biometrics, diagnoses, and bank details exposed in major healthcare breach (Malwarebytes).