SickKids employee data stolen in incident tied to software vendor

Canada's largest pediatric hospital says a third-party software incident exposed employee data but no clinical or patient information.

MedRisk Staff
By
2 Min Read

Toronto’s Hospital for Sick Children, Canada’s largest pediatric health center, says a recent cyber incident exposed personal information belonging to current and former employees.

The hospital, known as SickKids, posted a notice on Thursday saying investigators believe the data theft is tied to a third-party software application. The attack briefly knocked out the careers website and triggered a broader review of what was taken.

Potentially affected groups include current and former employees, job applicants, and staff of related organizations such as the SickKids Foundation. The hospital did not specify which employee data was involved but said no clinical systems or patient information were touched. People who may be impacted have been notified and offered two years of credit monitoring.

SickKids has been here before. In December 2022, the LockBit ransomware group shut down hospital systems ahead of the holidays, forcing weeks of recovery that disrupted pharmacy, diagnostic imaging, and timekeeping operations. LockBit later apologized, released a free decryptor, and said it fired the affiliate responsible.

The incident lands in a busy week for healthcare breach disclosures, alongside Baylor Genetics and EHR vendor CareCloud. For children’s hospitals, even a contained employee-data incident draws extra scrutiny because any disruption to pediatric care capacity gets immediate public attention. Health systems should treat third-party applications as an extension of their attack surface and verify what those vendors can see and store.

Share This Article