The Hospital for Sick Children (SickKids) is investigating a cybersecurity incident involving a vulnerability in third-party software that may have exposed personal information belonging to employees and job applicants.
SickKids disclosed the incident on August 20 after the security issue temporarily disrupted its external Careers website. According to the hospital, the affected application is supplied by a third party and is also used by other organizations. SickKids has not identified the software or its developer. The Careers website has since returned to normal operation.
Importantly, the incident did not affect SickKids’ clinical systems or patient information. The hospital also said there was no disruption to patient care.
After discovering the incident, SickKids brought in external cybersecurity specialists to investigate what happened and determine whether personal information had been compromised. The ongoing review found that information associated with several groups may have been affected.
Those potentially impacted include current and former SickKids employees, personnel from SickKids Foundation and Boomerang Health, a pediatric healthcare organization owned by SickKids, as well as people who previously applied for jobs at the hospital.
The full extent of the exposure has not yet been established. SickKids has not revealed how many individuals may be involved or specified the types of personal information potentially accessed. The hospital has also not publicly provided the date on which the unauthorized activity occurred.
People whose information may have been affected have been contacted and offered two years of complimentary credit monitoring and identity protection. SickKids said it will separately notify individuals if its investigation confirms that their personal information was compromised.
The involvement of a third-party application makes the source of the incident particularly significant. SickKids confirmed that other organizations use the same software, but there is currently no confirmed information showing that those organizations were breached as part of the same incident.
SickKids said it continues to review the incident while strengthening measures intended to protect the personal information entrusted to the organization.
