Summary

A data breach at NYC Health + Hospitals Corporation — the largest public health system in the United States — has compromised personal and protected health information belonging to approximately 1.8 million current and former patients and employees. The breach, which originated in late March, was traced to a security incident involving one of the organization’s third-party vendors.

Investigators found that attackers maintained access to the network for 11 weeks before detection. NYC Health + Hospitals serves more than 1 million New Yorkers and operates across the city’s five boroughs. The Department of Health and Human Services Office for Civil Rights breach portal confirmed the scope of the compromise, making it one of the largest healthcare data breaches of 2026.

The extended dwell time and the volume of records exposed — spanning both patient health information and employee data — raise serious concerns about the organization’s network monitoring capabilities and vendor security oversight.

Source

HIPAA Journal · Kaseya

Commentary

Eleven weeks of undetected network access in a system holding 1.8 million health records is a catastrophic failure of detection and response. Healthcare organizations continue to be prime targets precisely because the data they hold — medical histories, Social Security numbers, insurance information — is among the most valuable for identity theft and fraud.

The third-party vendor origin of this breach adds to a growing pattern: organizations can invest heavily in their own security, but a single weak link in their vendor ecosystem can undo all of it. With the Verizon DBIR just this week reporting that third-party breaches are surging, healthcare systems need to treat vendor security assessments as ongoing operations, not annual checkbox exercises. The 1.8 million affected individuals now face years of potential identity theft risk from data that can never be “unbreached.”

By Allan