SickKids employee data breach (third-party software flaw)
Toronto's Hospital for Sick Children (SickKids) disclosed that a vulnerability in a third-party software application exposed personal information of current and former employees and job applicants, while clinical systems and patient data were unaffected.
- Victim
- The Hospital for Sick Children (SickKids)
On 20 August 2026, The Hospital for Sick Children (SickKids) β a leading pediatric hospital and research center in Toronto β disclosed that a cybersecurity incident had resulted in unauthorized access to the personal information of some of its current and former employees. The hospital attributed the breach to a vulnerability in a third-party software application used by SickKids and other organizations; neither the application nor its vendor was named.
Crucially, SickKids said clinical systems and patient information were not affected and that patient care continued as usual. The incident temporarily affected the hospital's external Careers website, which was subsequently taken down for remediation and safely restored.
What happened
Working with external cybersecurity experts, SickKids determined that personal information of current and former employees β including staff of Boomerang Health (a SickKids-owned pediatric clinic) and the SickKids Foundation β as well as job applicants, may have been affected. The hospital did not disclose the specific categories of data accessed or the number of people involved, saying that individuals confirmed to be affected would be notified directly.
Potentially impacted individuals were alerted and offered 24 months of complimentary credit monitoring and identity-protection services. The breach came less than four years after a separate, higher-profile 2022 ransomware incident at the hospital, though the two events are unrelated.
Impact
- Personal information of current and former employees and job applicants, across SickKids, Boomerang Health and the SickKids Foundation, may have been exposed.
- Clinical systems and patient data were not affected; patient care continued normally.
- The external Careers website was temporarily disrupted; affected individuals were offered 24 months of credit and identity monitoring.
Why it matters
The SickKids breach highlights how third-party software vulnerabilities can expose sensitive data even when a hospital's own clinical systems remain secure. Recruitment and HR platforms hold identity documents and personal details for staff and applicants β a data set attractive to fraudsters and often managed outside a hospital's core security perimeter. The incident reinforces the need for healthcare organizations to inventory and assess the security of every third-party application touching employee and applicant data, not just clinical systems.
Timeline
SickKids publicly discloses a cybersecurity incident affecting personal information of current and former employees.
Reporting details that a third-party software vulnerability was exploited and that the external Careers website was temporarily affected and then restored.
Sources
- sickkids.cahttps://www.sickkids.ca/en/news/archive/2026/SickKids-employee-information-impacted-by-cybersecurity-incident
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/
- theregister.comhttps://www.theregister.com/cyber-crime/2026/08/21/sickkids-childrens-hospital-bandages-up-careers-website-after-intruder-breaks-in/5291098
- cybernews.comhttps://cybernews.com/news/sickkids-breach-exposes-employee-and-applicant-data/