Tech

Federal Officials Flag Cybersecurity Risks at NYC Hospital Networks

A Department of Health and Human Services advisory names three New York City healthcare systems as having critical vulnerabilities in their medical device infrastructure.

By Leo Wang · June 11, 2026 · 4 min read

Federal Officials Flag Cybersecurity Risks at NYC Hospital Networks

NEW YORK — The Department of Health and Human Services this week issued a cybersecurity advisory naming three New York City healthcare systems as among a group of institutions with critical unpatched vulnerabilities in their medical device networks — a designation that puts them at elevated risk of ransomware attacks that could disrupt patient care, expose sensitive health records, and in worst-case scenarios affect the operation of networked life-support and monitoring equipment. The advisory does not identify the institutions by name in its public version, but two people familiar with the matter confirmed that all three are large hospital networks operating across multiple boroughs.

The advisory, issued by HHS's Health Sector Cybersecurity Coordination Center, or HC3, describes a pattern of vulnerabilities in legacy medical devices — including imaging machines, infusion pumps, and patient monitoring systems — that run on outdated operating systems and communicate over insufficiently segmented networks. These devices, which were not designed with cybersecurity in mind, can serve as entry points for attackers who gain footholds in hospital networks and then move laterally to administrative and clinical systems. HC3 said the pattern is consistent with tactics used in recent ransomware attacks on hospitals in Chicago and Atlanta.

NYC Health + Hospitals, the city's public hospital system, issued a statement saying it was aware of the advisory and was reviewing its network architecture in coordination with HHS and the city's Office of Technology and Innovation. The statement did not confirm whether NYC Health + Hospitals was among the named institutions, but said the organization had "accelerated its medical device security remediation program" following a 2025 review that identified 4,200 networked devices running end-of-life operating systems. The organization said it has a plan to replace or isolate those devices by the end of 2027.

Cybersecurity experts said the advisory reflects a known and longstanding challenge in healthcare. "Hospitals have hundreds or thousands of devices on their networks that were bought in the 2000s or 2010s and are running Windows XP or earlier embedded operating systems," said Priya Nair, a health sector cybersecurity researcher at the NYU Tandon School of Engineering. "You can't just patch them or update them the way you would a laptop, because they're FDA-regulated devices. Replacing them takes years and costs tens of millions of dollars. In the meantime, they're sitting on the network."

The timing of the advisory is notable. It follows a ransomware attack in May on a regional hospital network in New Jersey that disrupted electronic health record systems for 11 days, forced the diversion of ambulances from three emergency departments, and resulted in the exposure of personal health data for approximately 280,000 patients. That attack, which has been attributed by federal investigators to a cybercriminal group with ties to Eastern Europe, used a technique involving a compromised medical imaging device as an initial entry vector — precisely the vulnerability pattern HC3's advisory describes.

State legislators and the city's own technology oversight bodies have responded with calls for action. State Sen. Diana Okonkwo, who chairs the health committee, said she would hold hearings in July on medical device cybersecurity in New York hospitals. City Councilmember Josh Featherstone, who oversees the city's information technology subcommittee, requested a briefing from NYC Health + Hospitals and pressed the administration to accelerate remediation timelines. Several advocacy organizations representing patients and healthcare workers have also called for mandatory minimum cybersecurity standards for facilities receiving city contracts or Medicaid reimbursement.

The broader implications extend beyond immediate security concerns. A successful ransomware attack on a major New York City hospital network would not only threaten patient data but could strain emergency care capacity in a city that already runs several of its trauma centers at or near full utilization. Health officials have noted that the surge in healthcare visits during pandemic years permanently elevated baseline demand at many hospitals, meaning the margin for operational disruption is narrower than it was a decade ago. How quickly the named institutions can close the identified vulnerabilities — and whether they can do so before attackers exploit them — is the central question federal and city officials are now pressing them to answer.