SickKids Says Third-Party Software Flaw Exposed Employee and Applicant Data

Toronto's largest paediatric hospital confirms a breach affecting HR records. Patient files were not touched.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial 16:9 image of a large Japanese urban data centre at dusk, exterior shot, rows of cooling units and server ventilation grilles lit by am
Share

Key points

  • Toronto's Hospital for Sick Children (SickKids) disclosed a cybersecurity incident that exposed personal information belonging to some current and former employees and job applicants.
  • The hospital says clinical systems and patient records were not affected.
  • The breach stems from a flaw in third-party software used by the hospital, not a direct attack on its own network.
  • SickKids is notifying affected individuals and has offered credit monitoring where appropriate.

SickKids, the paediatric hospital in Toronto, has told staff and past job applicants that their personal details were caught up in a data breach. The cause was a security flaw in software supplied by an outside vendor, not the hospital's own clinical systems.

Patient records, appointments, and care files were not touched. That is the important line for families using the hospital.

The people affected are current employees, former employees, and people who applied for jobs at SickKids. The hospital is writing to them directly.

What information was taken?

SickKids has said the exposed data relates to human resources and recruitment records, the kind of information a hospital holds when you work there or apply for a role. That typically includes names, contact details, and, for staff and applicants, identifiers used during hiring and payroll.

The hospital has not published a full field-by-field list. It says it is contacting affected people individually with specifics, and offering credit monitoring where the data warrants it.

Clinical data, meaning patient charts, test results, and treatment histories, sits on separate systems that were not involved.

How did the hackers get in?

The breach came through a third-party software product the hospital uses, first reported by BleepingComputer. A flaw in that vendor's system, rather than in SickKids' own network, gave outsiders access to a slice of HR data.

This is an increasingly common pattern. Hospitals, banks, and government bodies rely on outside suppliers for payroll, recruitment portals, file transfer tools, and cloud storage. When one of those suppliers is breached, every customer downstream inherits the problem.

SickKids has not named the vendor publicly. The hospital says the vendor has since patched the flaw and that its own investigation, with outside forensic help, is ongoing.

Should staff and applicants be worried?

The practical risk is identity fraud and targeted phishing, meaning fake emails or texts that use real details about you to sound convincing. If your name, email, and the fact you applied to SickKids are floating around, a scammer can craft a message that looks legitimate.

A few plain steps help:

  • Read the letter from SickKids carefully and take up any credit monitoring offered.
  • Be sceptical of unexpected emails or calls that reference your SickKids employment or application, even if details look correct.
  • Turn on two-factor authentication (a second code sent to your phone) on your email and banking accounts if you have not already.

Current staff should watch for internal-looking emails asking them to log in to "update" HR details. Those are a classic follow-up to breaches of this kind.

What happens next?

SickKids says it reported the incident to Ontario's Information and Privacy Commissioner, which oversees health-sector privacy in the province under the Personal Health Information Protection Act. Even though no patient data was involved, hospitals are expected to notify the regulator about breaches touching identifiable personal information.

The hospital has not said how many people were affected. That figure often takes weeks to firm up as forensic teams finish reviewing which records the attackers actually accessed.

Expect a further notice once the vendor is named or the scope is confirmed.

© 2026 Threat Vectr