NYC Health + Hospitals Loses 1.8M People's Data, Including Fingerprints - Because Nothing Says 'Trust Us' Like Storing Biometrics
NYC Health + Hospitals reveals a breach exposing 1.8M people's data, including fingerprints - because nothing says 'secure' like losing your biometrics.
New York's public health provider NYC Health + Hospitals (NYCHHC) has announced that a months-long data breach - which allowed hackers to swipe personal details, medical records, and even fingerprint scans - affects at least 1.8 million people. Because what's a little identity theft between friends, right?
The largest public health system in the United States, serving over a million New Yorkers (mostly uninsured or on Medicaid), reported the number to the U.S. Department of Health and Human Services, making it one of the biggest healthcare data breaches of the year so far. Healthcare organizations have become a favorite snack for financially motivated cybercriminals, who love nothing more than feasting on vast banks of highly sensitive patient data.
According to a notice on its website, NYCHHC detected the cyberattack on February 2 and secured its network - but the hackers had been merrily accessing the network from November 2025 until February 2026, copying files all the while. The breach was traced to a third-party vendor, which remains unnamed, presumably to protect the guilty.
The exposed data varies by individual and includes health insurance plan and policy info, medical records (diagnoses, medications, tests, imagery), billing, claims, and payment details. Also compromised: government-issued IDs like Social Security numbers, passports, and driver's licenses. And because the universe has a twisted sense of humor, 'precise geolocation data' was also taken, meaning those selfies of your ID might have come with GPS coordinates.
But the pièce de résistance: hackers stole biometric information, including fingerprints and palm prints. These are yours for life and can't be replaced - unlike, say, a credit card. NYCHHC didn't explain why it stores biometrics, but prospective employees typically have to enroll fingerprints for background checks. Whether patients' prints were also taken remains a mystery.
As of Monday morning, NYCHHC's website was briefly offline, and a spokesperson didn't respond to TechCrunch's questions - like why it took months to detect the breach, or if the hackers sent a ransom note. It's unclear if the organization can even receive email during the outage.
This incident appears unrelated to the earlier NADAP breach that affected over 5,000 NYCHHC patients. The FBI's 2025 cybercrime report shows healthcare remains a top target for ransomware attackers. Remember the Change Healthcare fiasco? Russian-linked hackers stole data on over 190 million Americans - the largest medical data heist in U.S. history. So, at least NYCHHC is in good company - if by 'good' you mean 'terrifyingly bad'.
The Good Times
News in your inbox.
One sardonic roundup, delivered on your schedule. Free. Unsubscribe whenever your tolerance for wit runs out.
Already subscribed but we never reach your inbox? Check your spam folder and hit 'Not spam' (or 'Remove from spam') to bust us out of junk-mail purgatory. You'll be helping everyone else too.
Don't open any of our emails for a month and you'll be automatically removed from the mailing list.
Rewrite Article
Select parts to regenerate with a fresh AI pass. Translations will be updated automatically.
Generate AI Image
Creates a sardonic version of the article image using OpenAI.