NYC Health + Hospitals faces Senate scrutiny after cyber incident

Advertisement

Sen. Bill Cassidy, MD, chairman of the Senate Health, Education, Labor and Pensions Committee, is seeking information from New York City officials about a February cybersecurity incident that affected NYC Health + Hospitals and potentially exposed sensitive patient data.

In a June 4 letter to NYC Health + Hospitals President and CEO Mitchell Katz, MD, Sen. Bill Cassidy, MD, R-La., requested information about the health system’s cybersecurity practices, its response to the breach and efforts to safeguard patient data. He asked for responses by June 18.

The inquiry centers on security protocols, federal agency notifications, communication with affected individuals and plans to bolster cyber defenses. Dr. Cassidy noted that unauthorized access persisted for three months and exposed information belonging to more than 1 million patients, underscoring the growing threat cyberattacks pose to healthcare organizations. He is also seeking information about how New York Mayor Zohran Mamdani’s administration, which oversees NYC Health + Hospitals, is addressing cybersecurity risks.

In the letter, Dr. Cassidy cited healthcare cybersecurity as a major risk to the industry, noting that 628 healthcare data breaches were reported in 2025. He said such incidents can disrupt care, compromise patient information and increase fraud risks. Among the questions posed, he asked when NYC Health + Hospitals first discovered the breach, when and which federal agencies were notified, how officials are determining whether additional information was accessed, and how potentially affected patients and organizations are being informed.

He also requested details on corrective actions taken or planned to strengthen security and whether the health system intends to provide affected individuals with support beyond HIPAA notification requirements.

Dr. Cassidy has made healthcare cybersecurity a focus as chairman of the HELP Committee. His office said he has investigated cyber incidents involving Hims & Hers, Instructure, OPEXUS and UnitedHealth Group, and the committee previously passed the Health Care Cybersecurity and Resilience Act.

“The safety of NYC Health + Hospitals’ patients and employees is paramount,” a spokesperson for NYC Health + Hospitals said in an emailed statement to Becker’s. “We took appropriate actions, including alerting our staff, notifying the public and informing appropriate authorities. We have also offered all those affected tools to ensure their credit can be monitored and protected.”

NYC Health + Hospitals said in a March 24 notice that it detected suspicious activity Feb. 2 and determined an unauthorized individual accessed parts of its network between Nov. 25, 2025, and Feb. 11, 2026, copying certain files. The organization said it has not yet determined the full scope of the breach and continues to review impacted data and individuals.

The potentially exposed information varies by individual but may include health insurance information, medical records, biometric data, billing information, Social Security numbers, driver’s license numbers, financial account information and online account credentials.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement