<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[(malwarebytes.com) Massive Healthcare Data Breach at NYC Health + Hospitals Exposes Sensitive Patient and Employee Data via Third-Party Vendor]]></title><description><![CDATA[<p>(malwarebytes.com) Massive Healthcare Data Breach at NYC Health + Hospitals Exposes Sensitive Patient and Employee Data via Third-Party Vendor</p><p>NYC Health + Hospitals breach exposes 1.8M records, including biometric data, via third-party vendor compromise (Nov 2025–Feb 2026).</p><p>In brief - A supply-chain attack on NYC H+H via an unnamed vendor led to the exposure of PII, medical records, and biometric data for 1.8M individuals. The incident underscores third-party risks in healthcare and the long-term impact of biometric data theft.</p><p>Technically - Attackers exploited a vendor vulnerability to gain persistence in NYC H+H’s network, exfiltrating PII, medical/insurance records, and biometric data (fingerprints/palm prints). The breach aligns with FBI-reported ransomware trends targeting healthcare. Mitigation requires vendor risk management, MFA, encryption, and continuous monitoring of sensitive data.</p><p>Source: <a href="https://www.malwarebytes.com/blog/news/2026/05/biometrics-diagnoses-and-bank-details-exposed-in-major-healthcare-breach" rel="nofollow noopener"><span>https://www.</span><span>malwarebytes.com/blog/news/202</span><span>6/05/biometrics-diagnoses-and-bank-details-exposed-in-major-healthcare-breach</span></a></p><p><a href="https://swecyb.com/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/8e1f6abf-df7a-43fa-a486-aa3da50ce701/malwarebytes.com-massive-healthcare-data-breach-at-nyc-health-hospitals-exposes-sensitive-patient-and-employee-data-via-third-party-vendor</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 12:11:17 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/8e1f6abf-df7a-43fa-a486-aa3da50ce701.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 19 May 2026 16:57:57 GMT</pubDate><ttl>60</ttl></channel></rss>