All Breaches
November 25, 2025 Verified Sensitive Record Healthcare

NYC Health + Hospitals 2025 Data Breach

The NYC Health + Hospitals 2025 data breach involved an unauthorized third party entering the network of the largest public health system in the United States on November 25, 2025 and maintaining access until February 11, 2026. The organization identified suspicious activity on February 2. Its investigation confirmed that files containing personal and protected health information were exfiltrated from the network.

The current breach record maintained by the US Department of Health and Human Services Office for Civil Rights covers 1,800,000 current and former patients and employees. pwnCount and totalRecords use that federal value. The incident affected identity, medical, insurance, billing, biometric, financial, location, and online-account information; contents varied by person and LeakData imports no personal records.

How Was the Data Theft Confirmed?

NYC Health + Hospitals announced on March 24, 2026 that personal and protected health information was exposed in a security incident. A forensic investigation determined that the unauthorized third party remained in the network for roughly eleven weeks and exfiltrated files. This statement classifies the event as organization-confirmed acquisition rather than only possible viewing.

HHS OCR lists the event as a Hacking/IT Incident, the information location as Network Server, and the entity type as Healthcare Provider. HIPAA Journal compared the organization's disclosure with the federal entry, corroborating the access range, exfiltration, affected groups, and broad data classes. Sources do not attribute the attack to a named ransomware group.

What Was the Access and Notification Timeline?

The threat actor first accessed the network on November 25, 2025. The organization detected suspicious activity and secured systems on February 2, 2026, but the investigation found access continued until February 11. breachDate is November 25, the beginning of the verified window; the discovery or notification date is not substituted for it.

The organization made its public announcement in March 2026 while continuing to review affected files. The HHS row carries a March 24 submission date and shows 1.8 million people. NYC Health + Hospitals said initial access may have followed a security breach at an unnamed third-party vendor; neither the vendor nor technical method is named in this original record without confirmation.

What Medical and Insurance Information Was Affected?

Medical information included medical record numbers, disability codes, diagnoses, medications, test results, images, and treatment plans. These fields contain detailed, enduring information about a person's health. Because the organization did not say every clinical field appeared in every file, the classes describe possible individual scope.

Health-insurance plan and policy information, insurer names, member and group identifiers, and Medicaid, Medicare, or other government-payor identifiers may have been involved. Billing and claims information was also in scope. These fields can support fraudulent healthcare claims, medical identity theft, and targeted insurance scams.

What Identity, Biometric, and Location Data Was Involved?

Personal fields included names, Social security numbers, driver's-license or other government identity numbers, and taxpayer identification numbers. IRS-issued Identity Protection PINs and precise geolocation data were also in scope. Credit or debit card numbers and financial-account information or credentials were involved as well, increasing risks involving tax, public-benefit, and new-account fraud.

Biometric information such as fingerprints and palm prints and online-account credentials were present in files. Passwords can be changed, but biometric characteristics are permanent, creating longer-lasting consequences. The broad list does not mean every person had every field. LeakData does not invent file volumes or subgroup totals and does not assign biometric, location, or financial fields to every victim.

Why Is the Separate NADAP Breach Excluded?

A separate incident involving care-coordination partner NADAP also affected NYC Health + Hospitals patients around the same period. That event involved roughly 5,086 people in November 2025 and exposed names, birth dates, addresses, Medicaid numbers, Social security numbers, and clinical information related to home-based care.

The NADAP event had a different organization, discovery date, and notification scope, so it is not added to the 1.8 million-person network breach. This LeakData record represents only the event beginning in the NYC Health + Hospitals network on November 25 and resulting in file exfiltration. That separation avoids possible double-counting and merging distinct incidents.

What Should Affected People Do?

NYC Health + Hospitals offered 24 months of complimentary credit monitoring and identity-theft protection to people who were patients or workforce members from 2020 through February 2, 2026. Notice recipients should monitor credit reports, tax and public-benefit accounts, cards, and bank activity and consider a security freeze if a Social Security number was involved.

Unfamiliar services and claims in medical or insurance statements should be reported. People whose biometric or online-account information was involved should be cautious about unexpected verification requests and make passwords unique. importedRecordCount is zero; LeakData does not store or publish identity, health, biometric, location, financial, or account data.

1.8 Million
Affected Accounts
20
Data Types
Critical
Severity
Yes
Verification

Exposed Data Types

20
Names
Medical record numbers
Disability codes
Diagnoses
Medications
Test results
Medical images
Treatment plans
Health insurance information
Billing and claims information
Fingerprints
Palm prints
Social security numbers
Government-issued ids
Taxpayer identification numbers
Irs identity protection pins
Precise geolocation
Credit and debit card numbers
Financial account information and credentials
Online account credentials

Additional Information

Added DateJuly 27, 2026
Breach DateNovember 25, 2025
Domainnychealthandhospitals.org
SourceUnauthorized network access and confirmed exfiltration of files containing PII and PHI
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information