The Hospital for Sick Children (SickKids) in Toronto has confirmed a data breach involving personal information belonging to current and former employees, with staff at affiliated organizations and job applicants also potentially affected.
SickKids said the incident was linked to a vulnerability in a third-party software application used by the hospital and other organizations. The vulnerability resulted in unauthorized access to personal information and temporarily affected the hospital’s external Careers website, which has since been restored.
Clinical systems and patient information were not affected, according to the hospital, and patient care continued normally.
SickKids disclosed the incident on Aug. 20 in an official cybersecurity incident notice. The hospital has not identified the third-party software provider, the affected application, or a vulnerability identifier associated with the incident.
Exposure extends beyond hospital employees
SickKids launched an investigation with external cybersecurity experts after discovering the incident. That investigation determined that personal information belonging to some current and former SickKids employees was accessed.
The hospital also identified potentially affected information belonging to current and former employees of Boomerang, a SickKids-owned pediatric clinic, and SickKids Foundation. People who applied for jobs at SickKids may also have had personal information exposed.
SickKids has not disclosed the number of affected individuals or specified which categories of personal information were involved. Its review of the compromised information remains ongoing.
Individuals confirmed to have been affected will be notified directly. SickKids said it has already alerted all potentially impacted individuals as a precaution and offered them 24 months of complimentary credit monitoring and identity protection services.
Unnamed third-party software sits at center of breach
The hospital’s attribution of the breach to a third-party software vulnerability leaves several questions unanswered. SickKids has not disclosed how the vulnerability was exploited, when unauthorized access occurred, or whether attackers stole information beyond the data currently under review.
SickKids specifically noted that the affected software is also used by other organizations. That raises the possibility that the vulnerability could have implications beyond the hospital, although no broader exploitation campaign has been confirmed.
No threat actor has been publicly attributed to the breach.
Patient systems escaped the latest incident
The breach follows previous cybersecurity incidents involving SickKids, including a ransomware attack in December 2022 that disrupted clinical and corporate systems.
That attack forced the hospital to declare a Code Grey while teams restored affected infrastructure. SickKids later said approximately 80% of its priority systems had been restored by early January 2023, allowing the hospital to lift the Code Grey. Its electronic medical record was not affected, although systems supporting areas such as diagnostic imaging, pharmacy operations and staff functions experienced disruptions.
SickKids was also affected indirectly by the 2023 BORN Ontario cybersecurity incident, which resulted from exploitation of a vulnerability in MOVEit Transfer used by the provincial perinatal and child registry. SickKids was among the healthcare providers that shared information with BORN Ontario.
The latest breach is different in scope. SickKids says its clinical systems and patient information remained unaffected, with the identified exposure instead involving workforce and recruitment-related information.












