BREACH2026-06-06T14:00:46.16698+00:005 min read

Hackers Stole 1.8 Million People's Fingerprints From a Hospital. You Can't Change Your Fingerprints.

NYC Health + Hospitals confirmed hackers accessed the biometric data, medical records, SSNs, and bank details of 1.8 million patients. Unlike a password, your fingerprints are permanent.

Hackers Stole 1.8 Million People's Fingerprints From a Hospital. You Can't Change Your Fingerprints.

This Breach Is Different

You've heard this before. Hospital hacked. Patient data stolen. Change your passwords. Monitor your credit.

But this one is different — and the reason is sitting at the end of your hands.

In March 2026, NYC Health + Hospitals disclosed that hackers had breached their systems through a third-party vendor, maintaining access from November 2025 through February 2026 — over three months. By the time anyone noticed, the attackers had stolen data on at least 1.8 million people.

The data included everything you'd expect: names, Social Security numbers, dates of birth, addresses, diagnoses, medications, insurance details, bank account numbers, passports.

And then the thing that makes this breach unfixable: fingerprints and palm prints.


Why Biometric Data Changes Everything

When hackers steal your password, you change it. When they steal your credit card number, you cancel the card. When they steal your SSN, you freeze your credit.

When they steal your fingerprints — you can't do anything. You have one set. They're on your hands right now. They'll be there until you die.

Biometric data — fingerprints, face scans, iris patterns, palm prints — is the final frontier of identity. It's increasingly used to:

  • Unlock your phone
  • Clear airport security
  • Authenticate banking apps
  • Access government services
  • Clock in at work

Once that data is in a criminal's hands, it's there permanently. The attack surface grows as more systems adopt biometrics. A fingerprint stolen today could be used to impersonate you in systems that don't exist yet.


How the Breach Happened

NYC Health + Hospitals — the largest public health system in the United States, serving predominantly low-income and uninsured patients — was breached not directly, but through a third-party vendor.

This is now the dominant attack vector in healthcare. Hospitals and health systems rely on dozens of software vendors, billing processors, and service providers. Each one is a potential door.

The breach was reported to the U.S. Department of Health and Human Services on March 24, 2026. It was publicly disclosed May 18, 2026 — nearly six months after the attack began.


What Was Stolen

| Category | Data Exposed | |---|---| | Identity | Full name, DOB, SSN, address | | Medical | Diagnoses, medications, treatment history | | Biometric | Fingerprints, palm prints | | Financial | Bank account numbers | | Government | Passport numbers |

For the 1.8 million affected, this is a complete identity profile — everything needed to impersonate someone across financial, medical, and government systems.


What You Should Do If You Use NYC Public Healthcare

1. Assume your data is compromised If you've used NYC Health + Hospitals services in the past few years, treat your data as exposed.

2. Freeze your credit immediately Contact all three bureaus — Equifax, Experian, TransUnion — and place a freeze. Free, takes 10 minutes, blocks new account openings.

3. Enable biometric revocation where possible Some systems allow you to re-enroll biometrics. If a service you use was relying on a fingerprint database linked to this breach, contact them.

4. Watch for medical identity theft Stolen medical data is used to fraudulently bill insurance, obtain prescriptions, and create false medical records. Request your medical records summary and look for anything unfamiliar.

5. Place a fraud alert A fraud alert requires lenders to verify your identity before issuing credit. More powerful than a credit freeze for certain attack types.


The Bigger Problem

This breach didn't happen at a luxury hospital serving wealthy patients with leverage to sue. It happened at a system serving the most vulnerable people in New York — those with the least resources to respond to identity theft.

Healthcare is now the most attacked sector in the United States. In 2025, healthcare breaches cost the industry an average of $9.77 million per incident — the highest of any sector. The patients bear the real cost.

Until healthcare vendors face consequences proportional to the harm they cause, this will keep happening.


Stay invisible. Follow HackDecoded.

Sources

WHAT TO DO RIGHT NOW
  1. 01Go to haveibeenpwned.com and check your email address right now
  2. 02Change your password on the breached service — use a unique password you do not use anywhere else
  3. 03Enable two-factor authentication (2FA) on that account if available
  4. 04Monitor your bank statements and credit report for unusual activity over the next 90 days
RECOMMENDED PROTECTIONAFFILIATE

AuraAll-in-one identity theft and scam protection with real-time alerts

Get Aura
Check Have I Been Pwned →
// FAQ

Common Questions About Breach

What should I do immediately after a data breach?

Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.

How long do companies have to notify me after a data breach?

In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.

Should I freeze my credit after a data breach?

Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.

// RELATED

More in breach

153 Million Driver's Licenses Are Being Sold on the Dark Web Right Now
2026-09-08T08:03:13.929805+00:00 · 5 min read
Hasbro Kept Quiet for 5 Months While Hackers Had Workers' SSNs and Bank Info
2026-09-05T08:04:13.891376+00:00 · 5 min read
Your Hospital Records Could Go Public: Ransomware Gang Hit 27 US Facilities
2026-09-03T08:04:32.922878+00:00 · 5 min read

Stay invisible. Follow @hack_decoded