SickKids Hospital Reports New Data Theft Incident Linked to Third-Party Software
The Hospital for Sick Children (SickKids) in Toronto has disclosed a new data theft incident involving employee and applicant information, potentially stemming from a third-party software compromise.

Canada's largest pediatric health center, the Hospital for Sick Children (SickKids), has announced a recent cybersecurity incident that resulted in the theft of personal information belonging to current and former employees, as well as job applicants. This disclosure follows a significant ransomware attack in 2022 that disrupted some of the hospital's critical systems.
The latest breach briefly took down SickKids' careers website, prompting an immediate investigation. While the hospital has not specified the exact date of the attack, investigators believe the perpetrators gained access through a third-party software application. The stolen data is understood to include information related to current and former employees, job applicants, and employees of associated organizations, such as the SickKids Foundation. The exact nature of the exposed employee data has not been detailed.
Fortunately, SickKids has stated that the incident did not affect any clinical systems or patient information, mitigating the risk of compromised patient care data. Affected individuals have been notified and offered two years of complimentary credit monitoring services as a protective measure.
This incident marks a concerning recurrence of cyber threats for SickKids, which was previously targeted by ransomware hackers in late 2022. That attack significantly impacted pharmacy systems, diagnostic imaging results, and internal staff timekeeping systems, requiring weeks to fully recover. The group responsible for the 2022 attack later apologized and claimed to have dismissed the affiliate responsible.
The latest breach at SickKids occurs amidst a wave of cybersecurity incidents affecting healthcare organizations. This week alone has seen disclosures from Baylor Genetics, which experienced a leak of medical testing and health insurance information in June, and CareCloud, where a March incident impacted approximately 3.7 million individuals.
The reliance on third-party software continues to be a critical vulnerability for organizations across all sectors. A compromise in a single vendor's system can cascade into widespread data breaches, affecting numerous clients. The investigation into the specific third-party application involved at SickKids is ongoing.
SickKids has not provided further comment beyond its initial statement, emphasizing that the investigation is active. The hospital's commitment to offering credit monitoring services aims to help mitigate the potential fallout for affected employees and applicants.
This event underscores the persistent and evolving threat landscape facing healthcare institutions, highlighting the need for robust security practices, diligent vendor risk management, and rapid response capabilities to protect sensitive employee and patient data.