NYC Health+Hospitals breach exposes fingerprints and medical data of 1.8 million
Hackers spent over two months inside New York City’s largest public health system, walking away with medical records, Social Security numbers, and biometric data including fingerprints and palm prints belonging to at least 1.8 million people.
NYC Health + Hospitals (NYCHHC) disclosed the breach after reporting the figure to the U.S. Department of Health and Human Services. It is one of the largest healthcare data breaches of 2026 so far, and by far the most sensitive, because biometric data cannot be replaced.
A stolen password can be changed. A compromised credit card can be canceled. A fingerprint is forever. The people whose biometric data was taken will carry that exposure for the rest of their lives, and no amount of credit monitoring will fix it.
How it happened
NYCHHC detected suspicious activity on February 2, 2026. By then, the attackers had been inside the network since roughly November 25, 2025. Over two months of unchecked access. The hackers copied files containing an extraordinary range of data: health insurance details, medical records with diagnoses and medications, billing and payment data, Social Security numbers, passport numbers, driver’s license numbers, and the biometric data.
The breach notice also mentions “precise geolocation data” was taken. This likely means photos uploaded as identity documents contained embedded location metadata showing exactly where and when they were captured.
The entry point was a third-party vendor. NYCHHC declined to name the vendor. This is the same pattern that powered the Change Healthcare attack, which exposed over 190 million Americans’ medical data. Attackers don’t hit the target head-on anymore. They go through the supplier.
Why the biometrics matter
NYCHHC did not explain why it was storing fingerprint and palm print data. The most probable reason is employee onboarding: prospective staff at NYC public hospitals must submit fingerprints for criminal background checks. It remains unclear whether patients’ biometric data was also compromised.
That question matters enormously. The population served by NYCHHC is disproportionately low-income, immigrant, and medically underserved. These are people who face high barriers to responding to identity theft and fraud. Unlike patients of private health systems who may have identity protection benefits through employers, many NYCHHC patients will have to rely on whatever the organization provides.
The vendor problem persists
Third-party vendor breaches have become one of the most persistent vulnerabilities in healthcare. Hospitals depend on outside vendors for billing, claims processing, scheduling, electronic health records, staffing, analytics, and remote access. When a vendor credential is compromised, attackers move into the hospital’s environment without ever touching the hospital’s own perimeter.
The NYCHHC breach follows the same template as the Canvas LMS breach and the Change Healthcare ransomware attack. The target hardens its own walls. The attacker walks through the side door that the vendor left open.
The timeline raises questions
Two months of undetected access in a system holding biometric data, medical records, and Social Security numbers for millions of people. NYCHHC says it secured its network on February 2. The website was briefly offline on Monday. The organization has not responded to press inquiries about why detection took so long, or whether it has received communication from the attackers.
Sources: TechCrunch, TNW, SecurityWeek, BiometricUpdate