Hong Kong Hospital Authority leak exposes data of 56,000 patients via contractor
Hong Kong's Hospital Authority disclosed that personal and surgical data of more than 56,000 patients from the Kowloon East Cluster had leaked onto a third-party platform; police later arrested a contractor's system developer accused of downloading the records during maintenance work.
- Victim
- Hospital Authority (Hong Kong)
- users
- 56.0K
On 4 April 2026, Hong Kong's Hospital Authority (HA), which runs the territory's public hospitals, disclosed that personal data of more than 56,000 patients had leaked. Its routine monitoring had detected, at around 2am on 3 April, suspected unauthorised access and leakage of patient data that had appeared on a third-party platform. The HA reported the case to the police and to the Office of the Privacy Commissioner for Personal Data.
The leaked records related to patients of the Kowloon East Cluster and included names, gender, Hong Kong identity card numbers, hospital file numbers and details of surgical procedures. The HA said its internal network was operating securely and normally, set up a dedicated hotline and began notifying affected patients through its HA Go app, by letter and by phone. Data on more than 1,000 staff members was also reported to be involved.
A contractor, not a cyberattack
The HA said its review found no evidence of a cyberattack on its systems. A system developer employed by an outsourced maintenance contractor allegedly downloaded data onto a personal computer while working on an operating theatre system, in breach of contractual rules requiring formal approval before any data access. HA director Dr Tony Ha said the affected system was separate from the Clinical Management System used for patient care records. The HA suspended the contractor's access and tightened monitoring.
On 8 April, police arrested a 30-year-old man working for the contractor on suspicion of "access to computer with criminal or dishonest intent."
Why it matters
Lawmakers questioned whether the true number of affected people was higher and criticised oversight of outsourced IT contractors, with one legislator saying the data had been downloaded thousands of times after being posted online. The case shows how maintenance staff at third-party suppliers can become the weakest point in protecting highly sensitive health and identity data, even when the core network is not breached.
Timeline
The Hospital Authority's monitoring detects suspected unauthorised access and leakage of patient data on a third-party platform at around 2am; police and the privacy commissioner are notified.
The government announces that data of more than 56,000 Kowloon East Cluster patients has leaked and sets up a hotline for affected patients.
Police arrest a 30-year-old employee of a systems maintenance contractor on suspicion of accessing a computer with criminal or dishonest intent.
Sources
- news.gov.hkhttps://www.news.gov.hk/eng/2026/04/20260404/20260404_152124_997.html
- thestandard.com.hkhttps://www.thestandard.com.hk/news/article/328514/Over-56000-patients-data-leaked-in-Hospital-Authority-breach
- dimsumdaily.hkhttps://www.dimsumdaily.hk/hospital-authority-tightens-security-after-data-leak-affecting-56000-patients/
- databreaches.nethttps://databreaches.net/2026/04/08/hk-man-arrested-over-stolen-patient-personal-data/