GKRootWire
Cloud & Sysadmin Microsoft Confirms Preview Update Wipes Out Desktop SettingsAI Nvidia to Acquire Hugging Face for $12.9 BillionDev Tools A Deep Dive Into Intrusive Linked ListsGadgets DJI's Romo 2 Robovac Adds Local-Only Mode After Privacy ScareAI Nvidia Reportedly Moves to Acquire Hugging FaceAI Anthropic Launches Claude Tools for AI Shopping AgentsCloud & Sysadmin Microsoft Confirms Preview Update Wipes Out Desktop SettingsAI Nvidia to Acquire Hugging Face for $12.9 BillionDev Tools A Deep Dive Into Intrusive Linked ListsGadgets DJI's Romo 2 Robovac Adds Local-Only Mode After Privacy ScareAI Nvidia Reportedly Moves to Acquire Hugging FaceAI Anthropic Launches Claude Tools for AI Shopping Agents
Security

SickKids Hospital Discloses Data Breach Tied to Third-Party Software Flaw

A vulnerability in outside software exposed personal data of employees and job applicants at Toronto's Hospital for Sick Children, though patient records remained untouched.

The Hospital for Sick Children in Toronto, known as SickKids, has confirmed a cybersecurity incident that compromised personal information belonging to current and former staff members as well as people who applied for jobs there. The hospital says the breach originated from a security flaw in third-party software rather than its own internal systems.

Importantly, SickKids emphasized that clinical systems and patient medical records were not accessed or affected by the incident, limiting the scope of harm to employment-related data. The hospital has not yet detailed exactly what categories of personal information were exposed, such as Social Security numbers, addresses, or salary details.

SickKids is notifying affected individuals and working with cybersecurity experts to investigate the incident further.

Why it matters: This breach is another reminder that healthcare organizations' attack surface extends well beyond patient records into HR and vendor systems, which often receive less security scrutiny despite holding sensitive personal data. Third-party software vulnerabilities remain a persistent weak link, meaning hospitals must extend vetting and monitoring to every vendor touching employee or applicant data, not just clinical platforms.

Sources: BleepingComputer