Cyber intruders spent more than three months inside the networks of NYC Health + Hospitals, the largest public health system in the United States, copying medical records, fingerprint scans, and personal data from over 1.8 million people before anyone noticed. Now the chairman of the Senate Health, Education, Labor and Pensions Committee wants to know how that happened, and why Mayor Zohran Mamdani's administration has not provided answers.
Sen. Bill Cassidy of Louisiana fired off a letter to NYC Health + Hospitals CEO Mitchell Katz demanding a briefing on the breach, which the New York Post first reported. The intrusion ran from at least November 2025 through February 2026. Cassidy set a June 18 deadline for the hospital system to respond.
The breach raises hard questions about the security of sensitive health data in a system that serves some of New York City's most vulnerable residents, and about the competence of the Mamdani administration charged with protecting them.
Cassidy's missive lays out five specific areas of inquiry. He wants to know what security protocols the hospital system used, whether it adopted best cyber practices from other critical industries, when it notified the federal government, how it investigated the breach, and what steps it has taken to help individuals whose data was stolen.
In the letter, Cassidy wrote:
"At a time when hostile actors are increasingly using sophisticated tactics leveraging artificial intelligence, it is essential for the health care sector to take meaningful steps to safeguard patient and consumer information."
He added that the incident "highlights the risk cybersecurity incidents pose to patients." The fact that hackers roamed the system for roughly ninety days without detection makes those risks concrete rather than theoretical.
Mamdani, whose early tenure as mayor has drawn sustained criticism on multiple fronts, reappointed Katz to lead the hospital system. Neither Mamdani nor Katz has been quoted publicly addressing the scope of the failure.
NYC Health + Hospitals issued a data-breach notice acknowledging the incident. The system said it reset credentials for all compromised accounts, implemented enhanced detection rules targeting the tools and techniques the intruder was suspected of using, and updated its remote access management policies to prevent similar entry points in the future.
A spokesperson told the Post that the safety of patients and employees "is paramount."
"We took appropriate actions, including alerting our staff, noticing the public, and informing appropriate authorities. We have also offered all those affected tools to ensure that their credit can be monitored and protected."
That statement raises as many questions as it answers. The system says it "noticed the public" and "informed appropriate authorities," but neither the timing of those notifications nor the identity of the authorities contacted has been disclosed. Cassidy's letter asks specifically when the federal government was told. The gap between the breach's February 2026 endpoint and the current demand for answers suggests the notification timeline may not have been swift.
Credit monitoring is a standard post-breach offering. But for 1.8 million people whose medical records and fingerprint scans may now be in hostile hands, a free credit report is cold comfort. Biometric data, unlike a credit card number, cannot be reissued.
The cybersecurity debacle is not the first time Cassidy has turned his committee's attention toward Mamdani's New York City. The senator has previously launched oversight inquiries into Mamdani related to antisemitism and a New York City Health Department working group. Those inquiries addressed what the committee described as conduct that endangered Jewish New Yorkers and used taxpayer dollars to advance a political agenda.
Mamdani has faced public protests outside Gracie Mansion from a broad coalition of New Yorkers who object to his leadership. The cybersecurity breach adds a new dimension to the criticism: not ideology, but basic operational competence.
Running the nation's largest municipal health system is not a vanity project. It requires serious infrastructure, serious oversight, and serious people managing both. When intruders can camp inside your networks for a full quarter of the year without triggering an alarm, something has gone wrong at a fundamental level.
Critics of Mamdani's broader governing approach have pointed to a pattern of ambitious rhetoric paired with weak execution. His tax plan drew sharp pushback from business figures who warned it would accelerate the flight of wealth from the city. His housing proposals have been questioned as well.
The senator's interest in healthcare cybersecurity is not new. Cassidy, a trained gastroenterologist, has pushed for the Health Care Cybersecurity and Resilience Act, legislation designed to strengthen cyber infrastructure across America's healthcare sector. He has also scrutinized high-profile breaches at Hims & Hers and UnitedHealth Group.
The NYC Health + Hospitals breach fits a disturbing national pattern. Healthcare systems hold some of the most sensitive personal information in existence, diagnoses, prescriptions, Social Security numbers, biometric identifiers, and too many of them treat cybersecurity as an afterthought.
But the NYC case stands out for its duration. Three months is not a momentary lapse. It suggests either that monitoring systems were inadequate, that warning signs were missed, or that the hospital system lacked the capacity to detect sophisticated intrusion techniques. Cassidy's letter pointedly asks whether the system has adopted best practices from other critical industries. The implication is clear: it may not have.
Mamdani's administration has drawn national scrutiny over its ideological priorities. Whether those priorities have come at the expense of the unglamorous but essential work of protecting patient data is a question the June 18 deadline may begin to answer.
The people most affected by this breach are not politicians or policy analysts. They are patients, many of them low-income New Yorkers who rely on the public hospital system because they have no other option. They handed over their most private information in exchange for medical care, trusting that the city would keep it safe.
That trust was broken. And so far, the city's response has amounted to a boilerplate press release, a promise of credit monitoring, and silence from the mayor's office.
Cassidy is right to press for specifics. When did the city discover the breach? When did it tell Washington? What took so long? And what, concretely, has changed to prevent the next intrusion from lasting another ninety days, or longer?
The hospital system's own breach notice lists remedial steps that sound responsible in a press release but beg for verification. Resetting compromised credentials is a minimum, not a solution. Updating remote access policies after hackers have already exploited them is closing the door after the data walked out.
Mamdani's record of relying on government programs with long histories of failure makes skepticism warranted. Grand plans mean nothing if the basic machinery of city government cannot protect its own systems from intruders who had the run of the place for an entire season.
Cassidy has given the hospital system until June 18 to provide answers. Whether Katz and the Mamdani administration meet that deadline, and whether their answers satisfy a Senate chairman who has already demonstrated willingness to escalate oversight, will say a great deal about how seriously New York City takes the security of its residents' most private information.
The breach itself was bad enough. A three-month dwell time for intruders inside a system holding data on 1.8 million people is a serious failure by any standard. But the response matters just as much. Transparency, speed, and accountability are the minimum that patients deserve.
When 1.8 million people's medical records and fingerprints are floating in the hands of unknown hackers, the public deserves more than a press release and a free credit report. It deserves leaders who treat protecting their data as seriously as they treat their own political ambitions.