Supply chain β›“ Supply Chain

NYC Health + Hospitals Notifying Patients of Two Separate Third-Party Vendor Hacks

πŸ“… 2026-03-26
Primary Source β†—

Incident Details

New York City Health + Hospitals β€” the largest public health system in the US, serving approximately 1.4 million patients annually β€” notified patients of data exposure from two separate third-party vendor hacks. Attackers had access to the vendors’ systems for nearly a year before detection. NYC H+H provides care to New York City’s most vulnerable populations including uninsured and underinsured patients. The dual vendor breaches illustrate the systemic supply chain risk at large public health systems that rely on numerous third-party vendors for specialized services. HHS OCR was notified. The nearly year-long dwell times suggest sophisticated threat actors who specifically target healthcare vendor access for long-term data collection rather than immediate ransomware deployment.

Technical Details

Initial Attack Vector
Two separate third-party vendors providing services to NYC Health + Hospitals (New York City's public hospital system) suffered data breaches, exposing patient data
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2026-03-26 Breach occurred
  2. 2026-03-26 Publicly disclosed