SickKids data breach exposes employee and job applicant info
-
The Hospital for Sick Children (SickKids) in Toronto has confirmed a data breach that exposed the personal information of certain current and former employees, as well as job applicants. The incident originated from a vulnerability in third-party software, not from a direct attack on the hospital’s own infrastructure. Critically, clinical systems and patient records were not affected, so patient care and data integrity remain intact.
The compromised information varies by individual but may include names, contact details, and other employment-related data. The hospital has not disclosed the specific third-party software or the nature of the flaw, but has stated that the issue was contained and remediation efforts are underway.
- Affected parties: current and former employees, plus job applicants.
- Systems impacted: administrative HR-related files only.
- Excluded: all clinical systems and patient health records.
Those impacted are being notified directly, and SickKids is offering support to help mitigate potential risks, such as identity theft or fraud. The hospital is also cooperating with relevant authorities and reviewing its security protocols in response.
Source: Unknown
With patient records untouched but HR data exposed, how is your organization handling third-party software risk in non-clinical or administrative systems?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login