NYC Health and Hospitals Data Breach Exposes 11TB of Stolen Data by LeakNet
LeakNet asserts it has obtained an 11TB dataset from NYC Health + Hospitals containing sensitive medical, financial, and biometric records linked to over 12 million individuals.
Overview of the Leak
LeakNet asserts it has obtained an 11TB dataset from NYC Health + Hospitals containing sensitive medical, financial, and biometric records linked to over 12 million individuals. The claim remains unverified by the health system, regulatory bodies, or independent investigators. The group released a preview on July 27 featuring screenshots of databases, medical spreadsheets, internal communications, and a directory listing of the alleged stolen archive. LeakNet warned of a subsequent full disclosure of the data.
Details of the Stolen Data
Analysis of the Preview
Analysis of the provided images reveals patient names, addresses, phone numbers, Social Security numbers, dates of birth, and medical details, including mental health diagnoses, HIV records, cancer appointments, and fingerprint documents bearing NYC Health + Hospitals branding. The publication has omitted direct patient identifiers.
Uncertainty in the 12 Million Figure
The 12 million figure lacks definitive proof, as database rows may represent appointments, diagnoses, or repeated entries rather than unique individuals. LeakNet alleged NYC Health + Hospitals leadership was aware of the scale of the breach by February 2. A screenshot shows an internal service-desk notice from that date indicating Windows users encountered data-breach alerts. Another image displays an extortion message claiming 12 million victims and 11TB of exposed data. However, these materials do not confirm CEO Mitchell Katz’s knowledge of the 12 million estimate.
Response from NYC Health + Hospitals
The health system previously reported 1.8 million affected individuals to the US Department of Health and Human Services, a figure not addressed in the leaked materials. NYC Health + Hospitals disclosed the breach on March 24 after detecting unauthorized network activity beginning November 25, 2025, and ending February 11, 2026. The investigation revealed an unauthorized party accessed systems and copied files. The compromised data varied per individual and could include medical records, insurance information, biometric data, billing details, Social Security numbers, government IDs, financial data, and online credentials. The health system attributed the incident to a breach at an unnamed third-party vendor.
Senator’s Inquiry and Ongoing Investigations
Ongoing reviews of the stolen files continue, with updates expected if new information emerges. In June 2026, Senator Bill Cassidy of the Senate HELP Committee requested details from Katz regarding the breach’s detection timeline, federal agency notifications, methods for identifying additional exposed data, and potential beyond-HIPAA reporting. The inquiry, noted in the New York Post, did not accuse the organization of concealing the 12 million-person breach but referenced publicly available information.
Current Status and Next Steps
LeakNet’s full claims remain unverified, with the confirmed affected count standing at 1.8 million. The group’s assertions about the 11TB archive and executive knowledge require independent validation. NYC Health + Hospitals has not publicly responded to the July 27 LeakNet post. Affected individuals and former employees can access the health system’s official incident website or response line to determine eligibility for two years of identity-protection services.
