NYC Health + Hospitals, the largest public health system in the United States, has disclosed a data breach that exposed personal, medical, financial, and biometric information, including fingerprints and palm prints. The system reported the incident to the U.S. Department of Health and Human Services as affecting at least 1.8 million people, making it one of the largest healthcare-related breaches disclosed so far this year.
According to the system’s notice of data breach, attackers had access to its network between November 2025 and February 2, 2026, when NYC Health + Hospitals detected the intrusion and secured its systems. Public notification followed on May 18. The organization has attributed the incident to a breach at a third-party vendor, which it has not named.
The categories of exposed data are unusually broad. The breach notice lists health insurance and policy details, medical records covering diagnoses, medications, tests, and imaging, billing and payment information, and government-issued identity documents such as Social Security numbers, passports, and driver’s licenses. It also lists biometric data in the form of fingerprints and palm prints, along with precise geolocation data.
The exposure of biometric identifiers is the element that distinguishes this breach from a conventional health-records incident. Unlike a password or an account number, a fingerprint or palm print cannot be reissued once compromised, which means the affected individuals carry the exposure permanently. The same concern has been raised in other public-sector incidents, including a data breach in Long Beach that exposed Social Security numbers and biometric data, and a leak of biometric police records in India.
NYC Health + Hospitals operates 11 acute-care hospitals along with community health centers and other facilities across New York City, which gives the breached records a wide reach across the city’s population. The organization has not publicly identified a ransomware group in connection with the incident, and has not detailed why fingerprint and palm-print data was held in the affected systems.
The disclosure adds biometric data to the list of sensitive information at risk in healthcare cyberattacks, where identity documents and medical histories are already routinely targeted, and where the records often pass through third-party vendors outside a provider’s direct control.
Sources: NYC Health + Hospitals, TechCrunch
–
By the ID Tech Editorial Team








Follow Us