Table of Contents
New York City-based NYC Health + Hospitals disclosed a NYC Health Hospitals incident at business associate Solventum Health Information Systems, affecting 58,778 patients. The disclosure marks the health system’s third data security incident revealed in 2026 alone, underscoring an ongoing pattern of cybersecurity challenges tied to third-party partners.
How the NYC Health Hospitals Data Breach Occurred
The incident involved unauthorized access to protected health information by a threat actor and occurred on or around March 29, 2026, according to a June 11 notice from NYC Health + Hospitals. The medtech company notified the health system of the disclosure April 21, creating a notable gap between the breach itself and formal notification.
What Information Was Accessed
The accessed information includes patients’ first and last names, addresses, dates of birth, medical record numbers, medical history and diagnoses. This combination of identifying and clinical details represents a significant exposure risk for the affected patients within this NYC Health Hospitals incident.
Data Posted to the Dark Web Before Notification
On April 19, before notifying NYC Health + Hospitals, the threat actor posted the accessed patient information to the dark web. This timeline detail is particularly concerning, as it means sensitive patient data was already circulating publicly before the health system or affected patients had any awareness of the NYC Health Hospitals incident.
Solventum’s Response to the Incident
Solventum said it has reset compromised employee accounts, rotated passwords, tightened permissions on sensitive information, and increased employee training on “vishing” and other social engineering tactics in response to the incident. These remediation steps suggest the breach may have originated through a social engineering attack targeting Solventum employees.
Regulatory Notifications Following the NYC Health Hospitals Data Breach
NYC Health + Hospitals has notified OCR, which posted the notice in July, and the attorneys general of New York, Connecticut and Puerto Rico. This multi-jurisdictional notification reflects the geographic spread of affected patients tied to this NYC Health Hospitals incident.
The Third Breach of 2026
This is the third data security incident NYC Health + Hospitals has disclosed in 2026, following a network breach affecting 1.8 million patients and employees and a separate breach at care management partner NADAP affecting 5,086 patients. The pattern suggests the health system’s third-party vendor relationships have become a recurring point of vulnerability throughout the year.
What This Means for NYC Health + Hospitals Patients
With three separate incidents disclosed in a single year, and this latest NYC Health Hospitals incident involving data already posted to the dark web, affected patients face a compounded risk of identity theft or fraud stemming from the combination of demographic and clinical information exposed. Patients should watch for direct notification detailing available protections, such as credit monitoring services, if offered.
What Comes Next
Becker’s reached out to NYC Health + Hospitals and Solventum for comment and will update the story if either responds. As the health system continues managing fallout from multiple 2026 breaches, its handling of vendor risk management and third-party data security practices is likely to draw continued scrutiny from regulators, patients, and industry observers alike.
Why Third-Party Vendor Risk Remains a Persistent Challenge
This latest NYC Health Hospitals data breach reflects a broader industry pattern in which business associates and technology vendors, rather than the health system itself, are increasingly the point of compromise in major healthcare data incidents. Health systems often have limited direct visibility into how thoroughly a vendor like Solventum secures its own systems, making vendor risk assessments and contractual security requirements an area of growing importance for hospital compliance teams. As NYC Health + Hospitals works through its third breach disclosure of the year, the recurring involvement of external partners may prompt the health system to reevaluate how it vets and monitors the security practices of the vendors handling its patients’ protected health information going forward.
For more healthcare industry updates, insights and news, visit DistilINFO. Click here to subscribe to stay informed.
