Desk live·
ForensicPost
Breaches/Healthcare/File 26-0324

NYC Health + Hospitals Intrusion Touched 1.8 Million People Over Three Months

The intrusion at NYC Health + Hospitals ran from November 2025 into February 2026 and touched about 1.8 million people. What separates it from the year’s larger breaches is the field list: it included biometric records.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetNYC Health + Hospitals
ActorUnattributed
D. Kennedy10 min readConfidence: high2 sources reviewed

Most breach notifications offer credit monitoring because most breached fields can be replaced. A card is reissued. A password is rotated. A Social Security number cannot be changed easily, which is why its exposure is treated as serious. A fingerprint cannot be changed at all.

NYC Health + Hospitals, the largest public health system in the United States, has reported a network intrusion affecting roughly 1.8 million individuals, with access running from November 2025 into February 2026. Among the data described as taken were biometric records including fingerprints and palm prints.

A Field With No Remediation Path

Biometric templates are collected in health systems for reasons that are entirely sensible — patient identification, controlled-substance dispensing, staff access to restricted areas. The collection is justified. The retention is where the risk accumulates.

There is no equivalent of a reissue for these fields. The standard remedies a notification letter can offer do not apply, and the exposure does not decay: a template taken in 2026 still describes the same person in 2046. Any organisation that has decided biometrics are worth collecting has also, implicitly, decided they are worth defending permanently.

The three-month access window is the second thing worth noting. It is long enough for deliberate work and short enough that the logging needed to reconstruct it usually still exists — which is why the fields taken are known with this much specificity.

How we reported this

Compiled from public reporting, listed below. We have not reviewed the affected records and are not describing the intrusion route, which has not been established publicly. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
  2. Data breach tracker 2026 — latest incidents and statisticsBitsight
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary