Protect.Computer
NEWS

SickKids Hospital Data Breach Exposes Staff and Applicant Info

· 0 min read · Data hijack Identity theft
SickKids Hospital Data Breach Exposes Staff and Applicant Info

Toronto’s Hospital for Sick Children (SickKids) has disclosed a data breach affecting the personal information of current and former employees, Boomerang clinic staff, SickKids Foundation employees, and job applicants. The incident stemmed from a vulnerability in a third-party software application used for the hospital’s external Careers website, which was taken offline temporarily while the issue was addressed. SickKids says it brought in external cybersecurity experts to investigate, and the scope of exposed data is still being determined.

Importantly, clinical systems and patient records were not touched — the breach was limited to HR and recruitment data. The hospital is notifying individuals confirmed to be affected and is offering 24 months of complimentary credit monitoring and identity protection services. This is the third publicly disclosed security incident at SickKids in four years, following a 2022 LockBit ransomware attack and a 2023 breach tied to the MOVEit zero-day.

Sources

Related reading