Skip to content
Tech News
← Back to articles

SickKids data breach exposes employee and job applicant info

read original more articles
Why This Matters

The SickKids data breach highlights the ongoing risks associated with third-party software vulnerabilities, emphasizing the importance of cybersecurity vigilance for healthcare institutions. While patient data remained secure, the exposure of employee and applicant information underscores the need for robust third-party risk management to protect sensitive personal data and maintain trust in healthcare systems.

Key Takeaways

The Hospital for Sick Children (SickKids) has disclosed that the personal information of some current and former employees, as well as job applicants, was exposed in a "cybersecurity incident." The hospital says the breach stemmed from a flaw in third-party software.

Clinical systems and patient records were untouched, according to the Toronto pediatric hospital, but its public-facing Careers website was temporarily pulled offline.

Careers site restored, incident scope under review

SickKids disclosed the incident this week, saying it resulted in unauthorized access to employee data.

The hospital attributes the breach to a vulnerability in a third-party software application that it says is used by SickKids and other organizations, according to a media statement.

The framing appears to suggest that there's a wider campaign against users of the same product, although the hospital has not named the vendor, the application, or the CVE involved.

The external Careers website was temporarily affected and has "since been safely restored," per the statement.

Clinical systems and patient information were not affected, and patient care continued as usual, SickKids says.

After learning of the incident, the hospital launched an investigation with the help of outside cybersecurity experts.

The findings indicate that personal information belonging to current and former SickKids, Boomerang (a SickKids-owned pediatric clinic), and SickKids Foundation employees, as well as SickKids job applicants, may have been exposed.

... continue reading