Most breach notifications offer credit monitoring because most breached fields can be replaced. A card is reissued. A password is rotated. A Social Security number cannot be changed easily, which is why its exposure is treated as serious. A fingerprint cannot be changed at all.
NYC Health + Hospitals, the largest public health system in the United States, has reported a network intrusion affecting roughly 1.8 million individuals, with access running from November 2025 into February 2026. Among the data described as taken were biometric records including fingerprints and palm prints.
A Field With No Remediation Path
Biometric templates are collected in health systems for reasons that are entirely sensible — patient identification, controlled-substance dispensing, staff access to restricted areas. The collection is justified. The retention is where the risk accumulates.
There is no equivalent of a reissue for these fields. The standard remedies a notification letter can offer do not apply, and the exposure does not decay: a template taken in 2026 still describes the same person in 2046. Any organisation that has decided biometrics are worth collecting has also, implicitly, decided they are worth defending permanently.
The three-month access window is the second thing worth noting. It is long enough for deliberate work and short enough that the logging needed to reconstruct it usually still exists — which is why the fields taken are known with this much specificity.
Compiled from public reporting, listed below. We have not reviewed the affected records and are not describing the intrusion route, which has not been established publicly. Corrections: corrections@forensicpost.com.