GKRootWire
AI Google Adds 'Preferred Source' Button to Help Publishers Fight AI Traffic LossesGadgets Linkdaze Launches a Smart Calendar Aimed at Running Your Whole HouseholdSecurity Popular Rust Crate arrayref Hijacked to Spread Infostealer MalwareCloud & Sysadmin GitHub Details Cause of August 17 Outage, Outlines Reliability FixesDev Tools Show HN: 'Huzzah' Proposes a Fresh Take on AI-Assisted CodingCloud & Sysadmin The Weird Science of Cooling Data Centers With UrineAI Google Adds 'Preferred Source' Button to Help Publishers Fight AI Traffic LossesGadgets Linkdaze Launches a Smart Calendar Aimed at Running Your Whole HouseholdSecurity Popular Rust Crate arrayref Hijacked to Spread Infostealer MalwareCloud & Sysadmin GitHub Details Cause of August 17 Outage, Outlines Reliability FixesDev Tools Show HN: 'Huzzah' Proposes a Fresh Take on AI-Assisted CodingCloud & Sysadmin The Weird Science of Cooling Data Centers With Urine
Security

SickKids Hospital Discloses Data Breach Tied to Third-Party Software Flaw

A vulnerability in outside software exposed personal data of employees and job applicants at Toronto's Hospital for Sick Children, though patient records remained untouched.

The Hospital for Sick Children in Toronto, known as SickKids, has confirmed a cybersecurity incident that compromised personal information belonging to current and former staff members as well as people who applied for jobs there. The hospital says the breach originated from a security flaw in third-party software rather than its own internal systems.

Importantly, SickKids emphasized that clinical systems and patient medical records were not accessed or affected by the incident, limiting the scope of harm to employment-related data. The hospital has not yet detailed exactly what categories of personal information were exposed, such as Social Security numbers, addresses, or salary details.

SickKids is notifying affected individuals and working with cybersecurity experts to investigate the incident further.

Why it matters: This breach is another reminder that healthcare organizations' attack surface extends well beyond patient records into HR and vendor systems, which often receive less security scrutiny despite holding sensitive personal data. Third-party software vulnerabilities remain a persistent weak link, meaning hospitals must extend vetting and monitoring to every vendor touching employee or applicant data, not just clinical platforms.

Sources: BleepingComputer