SickKids Says Third-Party Software Flaw Exposed Employee and Applicant Data

Toronto's largest paediatric hospital confirms a breach affecting HR records. Patient files were not touched.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A hospital building exterior with a data breach notification banner, showing HR and personnel records locked behind security barriers while patient files remain
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Toronto's Hospital for Sick Children (SickKids) disclosed a cybersecurity incident that exposed personal information belonging to some current and former employees and job applicants.
  • The hospital says clinical systems and patient records were not affected.
  • The breach stems from a flaw in third-party software used by the hospital, not a direct attack on its own network.
  • SickKids is notifying affected individuals and has offered credit monitoring where appropriate.

SickKids has told staff and past job applicants that their personal details were caught up in a data breach. The cause: a security flaw in software supplied by an outside vendor. Patient records were not touched, which is the line families need to hear first.

The people caught up in this are current employees, former employees, and job applicants. All are being contacted directly.

What information was taken?

The exposed data relates to human resources and recruitment records, the kind a hospital holds when you work there or apply for a role. That typically means names, contact details, and identifiers used during hiring and payroll. SickKids hasn't published a field-by-field list; it says it's contacting affected people individually with specifics and offering credit monitoring where the data warrants it. Clinical data sits on separate systems that weren't involved.

How did the hackers get in?

The breach came through a third-party software product SickKids uses, first reported by BleepingComputer. A flaw in that vendor's system gave outsiders access to a slice of HR data. SickKids hasn't named the vendor. The hospital says the flaw has since been patched and that its own investigation, with outside forensic help, is ongoing.

This pattern keeps appearing. As we noted in our 10 August report on LexisNexis pulling three services offline after a vendor server break-in, a compromise at one supplier ripples immediately to every downstream customer. Hospitals, banks, and government bodies all inherit the problem when a shared tool fails.

Should staff and applicants be worried?

The practical risk is identity fraud and targeted phishing: fake emails or texts that use real details to sound convincing. If your name, email, and the fact that you applied to SickKids are in circulation, a scammer can craft a message that looks legitimate. A few steps help.

Read SickKids' letter carefully and take up any credit monitoring offered. Be sceptical of unexpected contact referencing your employment or application, even when details look right. Turn on two-factor authentication (a second code sent to your phone) on email and banking accounts.

Current staff should watch for internal-looking emails asking them to log in to "update" HR details. That's a classic follow-up move after breaches of this kind.

What happens next?

SickKids reported the incident to Ontario's Information and Privacy Commissioner, which oversees health-sector privacy under the Personal Health Information Protection Act. Even with no patient data involved, hospitals must notify the regulator when identifiable personal information is exposed.

The hospital hasn't disclosed how many people were affected. That figure typically takes weeks to firm up as forensic teams finish reviewing which records were actually accessed. Once the vendor is named or the scope confirmed, a further notice should follow.

The detail worth watching here isn't the breach itself, it's the unnamed vendor. The Scottish Government workers' data loss we covered on 14 August showed how a single contractor can carry data from dozens of agencies simultaneously. Until SickKids identifies the supplier, there's no way to know how many other organisations share the same exposure.

© 2026 Threat Vectr