Oahe Data

Digital Footprint Audit

NewYork-Presbyterian Hospital
Date: 2026-04-09 Entity Type: Healthcare Audit Type: Public Index Reconnaissance

Contents

Purpose

This audit maps the publicly indexed digital footprint of NewYork-Presbyterian Hospital across federal agency databases (CMS, HHS, OIG, EPA), state regulatory systems (NY DOH, NY AG), certificate transparency logs, the Wayback Machine, court records, and the entity's own web properties.

What can anyone with a search engine learn about your organization in 30 minutes?

For a major academic medical center, the digital footprint extends far beyond the institutional website. Federal regulators, state agencies, bond markets, nonprofit tax databases, certificate transparency infrastructure, and third-party data aggregators each contribute to a composite picture that any researcher, competitor, litigant, or threat actor can assemble from public sources alone.

Methodology

The following public data sources were queried:

No unauthorized access was performed or attempted. All findings come from publicly indexed sources.

Governance & Sensitive Documents

Queries used:

"NewYork-Presbyterian" filetype:pdf "confidential" OR "internal" OR "not for distribution"
"NewYork-Presbyterian" filetype:pdf "agreement" OR "contract" OR "memorandum" OR "MOU"
"NewYork-Presbyterian" filetype:pdf "proprietary" OR "draft" OR "privileged"
#DocumentHosted OnRiskNotes
1Confidentiality, Privacy and Information Security Agreementnyp.vsyslive.comMediumEmployee confidentiality agreement on third-party vendor platform (VSys Live).
2GME Recruitment Packet (SAMPLE)psychiatry.weill.cornell.eduLowGraduate medical education document referencing confidential access policies.
3Medical Staff Bylawsmedicine.weill.cornell.eduLowFull bylaws including credentialing processes and committee structures.
4Code of Conduct (June 2024)nyp.orgLowIntentionally public governance document.
5NYP Hospital Refinancing SEQR Determinationdasny.orgLowState environmental review for $400M bond refinancing.

Assessment: LOW

Summary: Most documents are intentionally public governance materials or regulatory filings. The confidentiality agreement on vsyslive.com reveals categories of information NYP considers proprietary, but no leaked contracts, MOUs, or privileged materials were found.

Personnel & PII Exposure

Queries used:

"NewYork-Presbyterian" filetype:csv OR filetype:xlsx "employee" OR "directory" OR "roster" OR "staff"
"NewYork-Presbyterian" filetype:pdf "staff list" OR "phone directory" OR "org chart"
#DocumentHosted OnRiskNotes
1NYC Call Center MASTER Contact LISTnysna.orgMedium-HighStaff names, emails, and phone numbers across multiple NYP facilities. Hosted on union website.
2PPS Workforce Lead Contact Listhealth.ny.govMediumState-hosted document with NYP staff names, titles, phone numbers, and emails.
3LMH Physician Directorynyp.orgLowIntentionally public physician directory.
4NYP Employee Directory (ZoomInfo)zoominfo.comMediumThird-party data aggregator with scraped employee directory.
5NYP Staff Directory (LeadIQ)leadiq.comMediumSales intelligence platform aggregating NYP employee contacts.
6NYP Staff Directory (ContactOut)contactout.comMediumAnother third-party platform reselling NYP employee information.

Assessment: MEDIUM-HIGH

Summary: The NYSNA "MASTER Contact LIST" aggregates staff names, direct phone numbers, and email addresses across multiple NYP facilities on a domain NYP does not control. Multiple data aggregators (ZoomInfo, LeadIQ, ContactOut) are actively scraping and reselling NYP employee information.

Financial Documents

Queries used:

"NewYork-Presbyterian" filetype:pdf "budget" OR "revenue" OR "salary" OR "compensation"
"NewYork-Presbyterian" filetype:pdf "audit" OR "financial statement" OR "990" OR "annual report"
#DocumentHosted OnRiskNotes
12024-2025 GME Salary & Benefits Summarysurgery.weill.cornell.eduLowDetailed salary schedules for all PGY levels. Intentionally shared.
2PPS Finance Committee Guidelinesnyp.orgMediumNames VP of Revenue Cycle, details budget/funds flow processes.
3Consolidated Financial Statements (EMMA/MSRB)emma.msrb.orgLowBond disclosure financials. Regulatory requirement.
4Revenue Bonds Series 2023A (DASNY)dasny.orgLowBond offering with Moody's Aa2 rating. Public record.

Assessment: LOW

Summary: Financial exposure is extensive in volume but low in risk. Nearly all documents are intentionally published or regulatory obligations.

HIPAA & Regulatory Enforcement

Queries used:

"NewYork-Presbyterian" HIPAA violation OR breach OR penalty
"NewYork-Presbyterian" site:hhs.gov
"NewYork-Presbyterian" "consent decree" OR "settlement" OR "enforcement"
#RecordSourceAmountNotes
1HHS OCR — ePHI Data Breach Settlementhhs.gov$4.8M (combined)2014. ~6,800 patient records exposed on search engines. NYP paid $3.3M. Largest HIPAA settlement at the time.
2HHS OCR — Unauthorized Patient Filminghhs.gov$2.2M2016. ABC News "NY Med" crew filmed dying patient without consent. 2-year corrective action monitoring.
3NY AG — Pixel Tracking Settlementag.ny.gov$300K2023. Tracking pixels from Meta, Google, TikTok transmitted PHI of 54,396 individuals (2016-2022).

Assessment: HIGH

Summary: Three separate federal/state HIPAA enforcement actions spanning a decade, totaling approximately $7.3M in fines. The full resolution agreements and corrective action plans are publicly available on hhs.gov.

Wayback Machine Archive

Domains queried: nyp.org, www.nyp.org, healthmatters.nyp.org, cadc.nyp.org

MetricValue
Total unique pages archived~150,000+
Total unique PDFs archived312
Earliest snapshot1999-01-17
Most recent snapshot2026-02-27
Hosting platform detectedOracle WebCenter Sites (FatWire CMS)

Notable Archived Documents

#DocumentTypeNotes
1HIPAA Stroke Registry FormsPDFClinical/compliance document
2Privacy and Confidentiality Policy P205PDFFull internal privacy policy
3Photographing/Recording Policy C137PDFInternal policy on recording patients and staff
4SelectHealth Provider Manual (2006)PDFInsurance operations document
5Incident and Reporting PolicyPDFACN health home incident reporting procedures
6Employee Portal (archived)HTMLBenefits, pension statements, FICA refunds page
7Vendor Policy SeriesPDFMultiple numbered policies (C140, D160, I210, etc.)

Assessment: MEDIUM-HIGH

Summary: NYP has a massive 27-year Wayback Machine footprint with 150,000+ archived pages. The archive contains internal policy documents with numbered codes, provider manuals, clinical operations documents, and an archived employee portal.

Certificate Transparency

Domain analyzed: nyp.org

PropertyValue
Total certificates found~130
Certificate issuer(s)DigiCert (enterprise), Google Trust Services (public www via Cloudflare)
Wildcard certs?No — every subdomain gets an explicit named certificate
Renewal patternAnnual (DigiCert), 90-day automated (Cloudflare for www)

Subdomains Discovered (115+ unique, selected highlights)

CategoryCountExamples
Public-Facing11www, doctors, news, careers, mobile, healthmatters
Patient Portals3myhealth, nypcares, webportal
Campus Profiles12profiles, allenprofiles, cadcprofiles, cancerprofiles, neuroprofiles
Regional Directories9brooklyndoctors, hudsonvalleydoctors, queensdoctors, medgroup* variants
Intranet Systems5infonet, infonetmobile, infonethudson, infonetqueens, exfonet
Executive/Internal4execportal, finance, dashboard, protocols
Medical Credentialing6mdstaffcolumbia, mdstaffcornell, mdstaffmsow, mdstaffnypmg
Research5redcap, redcaptest, cerebro, cerebrotest, rogosinredcap
Security/Identity8infosecure, api.infosec, sslvpn, oneid-test, imprivatatest
VPN/Remote Access9sslvpn, pra, pra2, pragateway, praweb, pratest
Contact Center5cceadmin, ccefinesse, ccemaintapp, ccereports
DevOps6sonarqube, buildnyp.sdo, daggerboard, pitechpoc, hera.uat.sdo
Alternate Domains15+nyhq.org, innovatenyp.org, epictogetherny.org, nypchildrens.net

Assessment: MEDIUM

Summary: NYP's certificate strategy is enterprise-grade (DigiCert, no wildcards, proper rotation). However, CT logs expose the full breadth of internal infrastructure — intranet portals, research databases, security tools, VPN endpoints, and dev/test environments.

Infrastructure & Technical Surface

Domain analyzed: nyp.org

RecordValueSignificance
A143.104.236.115, 156.111.236.115Self-hosted: NYP own /16 IP block + Columbia University network
MXmxa-00227301.gslb.pphosted.comProofpoint enterprise email security gateway
NSns1.nyp.org, ns2.nyp.org + cornell.edu secondariesSelf-hosted DNS with Weill Cornell backup
TXTSPF, MS (x3), Google (x3), Atlassian, DocuSign (x2), VMware, Duo, OneTrust (x2), Zoom, Cisco, HPE16+ SaaS vendor domain verifications
PropertyValue
Hosting platformSelf-hosted (ARIN-registered /16 block) + Acquia/Drupal for public site
Domain type.org
Email providerProofpoint gateway → Microsoft 365 backend
CDN/ProxyCloudflare (www only); F5 BIG-IP (bare domain)
Subdomains discovered2,166+
Security headersFull suite (HSTS, X-Frame-Options, CSP, X-Content-Type-Options)
EHR PlatformEpic

Technology Stack Revealed via DNS/CT Logs

VendorCategory
EpicElectronic Health Records
Palo Alto PanoramaNetwork Security
Cisco Expressway/CCEUnified Communications & Contact Center
Aruba ClearPassNetwork Access Control
ImprivataIdentity & Access Management
ProofpointEmail Security
SonarQubeCode Quality
DaggerboardSBOM/Vulnerability Tracking
REDCapResearch Data Capture
EverbridgeEmergency Mass Notification
VoceraClinical Voice Communication
ADPPayroll/HR
Salesforce Marketing CloudEmail Marketing

Assessment: HIGH

Summary: NYP operates one of the most extensive institutional web infrastructures observed — 2,166+ unique subdomains, its own ARIN-registered /16 IP block, and deep network integration with Columbia and Cornell. The scale, including 374 dev/test subdomains visible in CT logs, provides a detailed reconnaissance map of the technology stack.

Funding & Contract Records

Key Financial Profile (IRS 990 / ProPublica)

FieldValue
Legal NameThe New York and Presbyterian Hospital
EIN13-3957095
Total Revenue (2024)$10.7B
Total Expenses (2024)$10.1B
Total Assets$21.9B
Employees36,103
CEO Compensation (Corwin, 2024)$26.3M

Federal Funding Records

#RecordAmountAgencyNotes
1HRSA Ryan White HIV/AIDS$2.7MHRSACoordinated services grant
2SAMHSA Mental Health$1.2MSAMHSASubstance abuse/mental health
3FEMA COVID-19 Reimbursement$60MFEMAH1 2025 pandemic response costs
4Youth Opportunity Hub (CJII)$10.3MManhattan DA4-year grant for Washington Heights
5HRSA 340B Drug PricingProgram benefitHRSA340B ID: 25027; discounted drug purchasing

Subsidiary Entities (13+ identified)

#EntityEINRelationship
1The New York and Presbyterian Hospital13-3957095Core operating entity
2NY Presbyterian Hospitals Healthcare System Inc13-3792361Parent/system entity
3New York Presbyterian Fund Inc13-3160356Foundation ($138.5M annual grants, $3.7B assets)
4New York Presbyterian Foundation Inc13-4153668Foundation entity
5NewYork Presbyterian Queens11-1839362Subsidiary hospital
6New York Presbyterian Brooklyn Methodist11-1631796Subsidiary hospital

Assessment: MEDIUM-HIGH

Summary: NYP's financial profile is fully reconstructable from public sources: $10.7B revenue, $21.9B assets, and a 13+ entity corporate structure each filing separate IRS 990s.

#Case/MatterTypeAmount/StatusNotes
1DOJ v. NYP — AntitrustFederal CivilActive (March 2026)Sherman Act Section 1: "all-or-nothing" insurer contracts
2Hadden Sexual Abuse SettlementState Mass Tort$750M (May 2025)Combined total exceeds $1B. Institutional knowledge since 1995.
3Brooklyn Methodist — Healthcare FraudFederal (FCA)$17.3MUnlawful kickbacks at chemotherapy infusion center
4Hudson Valley — Kickback SettlementFederal (AKS)$6.8MKickbacks to oncology practice for referrals (2011-2019)
5Queens — Healthcare FraudFederal (FCA)$2.5MMedically unnecessary services billed to federal programs
6Improper Billing SettlementFederal (FCA)$800KRadiology practices improperly billed Medicare/Medicaid/TRICARE
7Nurse Staffing ViolationsLabor Arbitration~$675K + 141 vacation days614 safe-staffing violations (Jan 2023-May 2024). NYP appealing.
8Meta Pixel Tracking Class ActionFederal Class ActionPendingPatient data shared via tracking pixels from Meta, Google, TikTok

Assessment: MEDIUM-HIGH

Summary: Enforcement actions span antitrust, anti-kickback, false claims, HIPAA privacy, and labor law. The breadth across multiple subsidiaries and time periods elevates this beyond routine litigation. The active DOJ antitrust suit is the most significant current matter.

Disaster & Environmental

#DeclarationDateNotes
1FEMA-4085-DR (Hurricane Sandy)2012-10-30NYP maintained operations; received transfer patients from evacuated hospitals
2FEMA-4480-DR (COVID-19)2020-03-20Among hardest-hit systems during initial NYC surge
3FEMA-4615-DR (Hurricane Ida remnants)2021-09-05Record rainfall/flooding near NYP/Columbia campus
4FEMA-1391-DR (September 11)2001-09-11Primary receiving hospital for 9/11 casualties

Assessment: LOW

Summary: NYP operates in a high-disaster-frequency jurisdiction. However, its institutional record demonstrates strong emergency resilience — maintaining operations during Sandy when peers evacuated, and serving as a frontline COVID-19 system.

Media & Public Narrative

#StoryDatePublicationKey Points
1DOJ Antitrust Lawsuit2026-03DOJ"All-or-nothing" insurer contracts
240K City Workers May Lose Coverage2026-04THE CITYNYP-EmblemHealth rate dispute; NYP charges 77% more
3UHC Drops NYP from Medicare Advantage2025CBS NYJan 2026 effective; access disruption for seniors
4Hadden $750M Settlement2025-05Columbia SpectatorTotal payouts exceed $1B
52% Workforce Layoffs (~1,000)2025-05Healthcare Dive4 days after Hadden settlement
6U.S. News #5 Nationally, #1 in NY2025U.S. News22nd consecutive year on Honor Roll
7$1.2B Cancer Center ("The Beacon")2025Crain's16-story facility, completion 2028

Leadership (as of April 2026)

NameRole
Dr. Brian G. DonleyPresident & CEO (since Jan 22, 2026)
Dr. Deepa KumaraiahEVP & COO (since Jan 22, 2026)
Michael P. BreslinGroup SVP, CFO & Treasurer
Mary Beth ClausGroup SVP, Chief Legal Officer
Adebayo O. OgunlesiBoard Co-Chair (also Chairman, Global Infrastructure Partners)
Jerry SpeyerBoard Co-Chair (also Chairman, Tishman Speyer)

Assessment: MEDIUM-HIGH

Summary: NYP is undergoing a CEO transition while facing the most adversarial regulatory environment in its history. The DOJ antitrust suit, insurer disputes, and $1B+ settlements dominate the narrative, even as the institution maintains #5 national ranking and executes $1.2B+ in capital expansion.

Risk Summary

CategoryAssessment
Governance & Sensitive DocumentsLOW
Personnel & PII ExposureMEDIUM-HIGH
Financial DocumentsLOW
HIPAA & Regulatory EnforcementHIGH
Wayback Machine ArchiveMEDIUM-HIGH
Certificate TransparencyMEDIUM
Infrastructure & Technical SurfaceHIGH
Funding & Contract RecordsMEDIUM-HIGH
Legal & Regulatory RecordsMEDIUM-HIGH
Disaster & EnvironmentalLOW
Media & Public NarrativeMEDIUM-HIGH
Overall Footprint Assessment: EXTENSIVE

NewYork-Presbyterian Hospital has one of the largest digital footprints of any healthcare institution in the United States, commensurate with its $10.7B annual revenue and 36,000+ employees. The footprint extends across 2,166+ subdomains, 150,000+ archived web pages, 13+ subsidiary entities each with separate federal filings, a decade of HIPAA enforcement history, and active DOJ antitrust litigation.

Recommendations

Immediate Actions

1. Address the NYSNA staff contact list. Request removal of the "MASTER Contact LIST" from nysna.org or work with the union to redact direct contact information. This document aggregates staff names, phones, and emails across multiple facilities on a domain NYP does not control.

2. De-index authentication endpoints. Seven or more login pages (iNYP intranet, MobileIron MDM, InfoSec API, PingFederate SSO) are indexed by search engines. Implement robots.txt disallow rules and X-Robots-Tag: noindex headers for all authentication-only subdomains.

3. Audit certificate transparency exposure. The 374 dev/test subdomains visible in CT logs reveal internal naming conventions and development infrastructure. Consider using private CAs for internal-only systems that do not require public trust.

4. Monitor third-party data aggregators. ZoomInfo, LeadIQ, and ContactOut are actively scraping and reselling NYP employee information. Evaluate contractual and legal options for data removal.

Ongoing Monitoring

1. Wayback Machine monitoring. With 150,000+ archived pages, removed content remains perpetually accessible. Implement periodic audits of what the archive reveals about internal policies and infrastructure.

2. Federal enforcement tracking. Given enforcement actions across antitrust, anti-kickback, false claims, and HIPAA domains, implement systematic monitoring of DOJ, OIG, OCR, and NY AG announcements.

3. CT log monitoring. Subscribe to certificate transparency log notifications for nyp.org to detect unauthorized certificate issuance or unexpected subdomain creation.

Strategic Considerations

1. The infrastructure footprint is a map. The combination of 2,166+ subdomains, DNS TXT records revealing 16+ SaaS vendors, and CT logs exposing specific products means a threat actor can construct a detailed technology inventory without touching the network.

2. Subsidiary fragmentation creates audit complexity. With 13+ entities each maintaining separate federal filings, IRS 990s, and state registrations, the total compliance surface is significantly larger than what any single-entity search reveals.

3. The public narrative is bifurcated. NYP simultaneously holds elite clinical rankings while facing unprecedented legal and pricing scrutiny. Any engagement should account for both the institutional prestige and the regulatory headwinds.

What This Means

Competitive intelligence exposure means your rivals, litigants, and potential partners can reconstruct more about your operations than any single disclosure was intended to reveal. The digital footprint of a $10.7 billion academic medical center is the cumulative result of every federal filing, regulatory enforcement action, certificate issuance, archived web page, and third-party data aggregation — assembling into a composite picture that no single department authorized or intended.