NYC Health + Hospitals Data Breach
NYC Health + Hospitals Portable Device Loss Exposes 2,174 Patients
What happened in the NYC Health + Hospitals data breach?
The NYC Health + Hospitals data breach was reported on December 2, 2022 and affected 2,174 individuals. The breach type was Loss involving Other Portable Electronic Device. This breach occurred in New York. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
NYC Health + Hospitals Breach Details
NYC Health + Hospitals Data Breach Report
Incident Overview
On December 2, 2022, NYC Health + Hospitals, one of the largest public healthcare systems in the United States, reported a data breach affecting 2,174 individuals. The breach resulted from the loss of a portable electronic device containing protected health information (PHI). This incident represents a significant security event for the organization, which serves millions of patients across New York City's five boroughs. The loss of portable devices remains one of the most common vectors for healthcare data breaches, as these devices are inherently mobile and vulnerable to theft or misplacement.
Discovery and Response Timeline
NYC Health + Hospitals discovered the loss of the portable electronic device and subsequently initiated an investigation to determine the scope and nature of the data exposure. Upon discovery, the organization followed HIPAA breach notification requirements by conducting a thorough risk assessment to evaluate whether the breach posed a significant risk of harm to affected individuals. The organization notified affected patients of the breach on or around the submission date of December 2, 2022, in compliance with the HIPAA Breach Notification Rule, which requires notification without unreasonable delay and no later than 60 calendar days after discovery of a breach. The investigation process included attempts to locate the device, assessment of whether the data was actually accessed or merely at risk of access, and evaluation of any security measures that may have protected the information.
Specific Details of the Breach
The breach involved the loss of a portable electronic device, which typically includes laptops, tablets, USB drives, external hard drives, or mobile devices used by healthcare personnel for clinical documentation, patient communication, or administrative purposes. Portable devices represent a particular vulnerability in healthcare settings because they frequently leave secure facilities, travel with staff members, and may not have the same level of physical security as stationary network infrastructure. The loss occurred at an unspecified location classified as "Other Portable Electronic Device," indicating the device was not recovered and its current location remains unknown. Without confirmation of device recovery or data access, the organization must assume the worst-case scenario for notification purposes—that the information may have been accessed by unauthorized parties. The device may or may not have contained encryption or other technical safeguards; the breach notification does not specify whether the device had password protection, full-disk encryption, or remote wipe capabilities that might have mitigated the exposure.
Organizational Context
NYC Health + Hospitals (NYC H+H) is a public benefit corporation and the largest municipal healthcare system in the United States, operating 11 acute care hospitals, four skilled nursing facilities, and numerous outpatient clinics and diagnostic centers throughout New York City. The system serves approximately 1.4 million patients annually, including a significant proportion of uninsured and underinsured individuals. As a public healthcare system, NYC H+H operates under unique governance structures and serves as a safety-net provider for the city's most vulnerable populations. The organization's scale and complexity—with thousands of employees across multiple facilities and boroughs—creates significant challenges for data security and device management. The loss of a portable device within such a large, distributed organization underscores the difficulty of maintaining comprehensive inventory control and security protocols across numerous locations and personnel.
Patient Impact and Affected Population
The breach affected 2,174 individuals whose protected health information was stored on the lost portable device. While the specific data elements exposed are not detailed in the breach submission, portable devices in healthcare settings typically contain some combination of patient names, medical record numbers, dates of birth, addresses, phone numbers, insurance information, and clinical notes or treatment details. The affected population likely includes patients who received care at one or more NYC H+H facilities during the period when the device was in use. Notification letters were sent to affected individuals informing them of the breach, the types of information potentially exposed, the steps the organization was taking to investigate, and recommended actions for protecting themselves against potential misuse of their information. The organization likely offered complimentary credit monitoring or identity theft protection services for a specified period, as is standard practice in healthcare breaches involving personal identifiers.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), covered entities and business associates must notify affected individuals of breaches of unsecured PHI. A breach is defined as the unauthorized acquisition, access, use, or disclosure of PHI that compromises the security or privacy of the information. The loss of a device containing PHI is presumed to be a breach unless the organization can demonstrate through a risk assessment that there is a low probability that the PHI has been compromised. The risk assessment must consider factors including the nature and extent of the PHI involved, who accessed or may have accessed the PHI, whether the PHI was actually acquired or accessed, and the extent to which the risk has been mitigated. Portable device losses represent a persistent challenge in healthcare security; according to industry reports, lost or stolen laptops, tablets, and mobile devices account for a significant percentage of healthcare data breaches annually. The absence of a business associate in this breach indicates the device and data were directly under the control of NYC H+H rather than a third-party vendor, placing full responsibility for the breach response on the organization itself. This incident reflects broader industry trends regarding the tension between clinical mobility (the need for healthcare workers to access patient information at point-of-care) and data security (the need to protect sensitive information from loss and unauthorized access).
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the NYC Health + Hospitals Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications
Review healthcare bills and explanation of benefits (EOBs) statements carefully for unauthorized services or claims; contact your insurance provider and healthcare providers immediately if you identify suspicious activity
Change passwords for any online healthcare portals, insurance accounts, and financial accounts, using strong, unique passwords; enable multi-factor authentication where available
Consider enrolling in the complimentary credit monitoring and identity theft protection services offered by NYC Health + Hospitals for the duration of the coverage period; these services typically include credit monitoring, fraud alerts, and identity theft insurance
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More New York Breaches
Search all breaches reported in New York
Technical Notes
NYC Health + Hospitals Has 3 Reported Breaches
This organization has been involved in multiple reported data breaches.
- 2025-06-06—5,728 affected(Hacking/IT Incident)
- 2023-12-22—1,500 affected(Unauthorized Access/Disclosure)