Data breach at NYC Health + Hospitals partner exposes info of 5,086 patients

Advertisement

A data security incident at a care management partner of NYC Health + Hospitals resulted in the unauthorized access of protected health information for 5,086 patients.

The incident involved NADAP, a care management agency partner that provides care coordination services to individuals receiving services under NYC Health + Hospitals’ Lead Health Home program. The breach occurred on or around Nov. 26, 2025, and was discovered by NADAP on Jan. 10, 2026, according to a March 11 news release from the healthcare organization. 

NYC Health + Hospitals said it was notified of the incident Jan. 27.

Information accessed during the incident included patients’ names, dates of birth, addresses, Medicaid numbers and clinical information related to their health home care provided by NADAP, as well as Social Security numbers.

After discovering the unauthorized activity, NADAP isolated the affected systems and took them offline. The organization also engaged third-party experts to investigate the incident and strengthen system security, and notified law enforcement, the release said.

NYC Health + Hospitals also reported the incident to the Office for Civil Rights, the federal agency responsible for oversight of unauthorized disclosures of protected health information.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement