Toronto's Hospital for Sick Children (SickKids) has disclosed a cybersecurity incident that exposed the personal information of current and former employees, job applicants, and workers at affiliated organizations. The breach, discovered on July 9, 2026, was publicly disclosed on August 20, 2026 after an investigation confirmed unauthorized access to an HR and payroll system.
Patient clinical data was not affected. Patient care has continued normally throughout.
What Happened
An unauthorized party accessed a system supporting SickKids' external careers website and certain HR and payroll functions. The breach was caused by a vulnerability in a third-party software application used by SickKids and other unnamed organizations. The vendor has not been publicly identified.
SickKids engaged external cybersecurity experts immediately upon discovering the incident and temporarily took the careers website offline. The site has since been restored.
Who Is Affected
The breach affected individuals whose data was processed through the impacted system. SickKids has identified the primary exposure window as individuals employed between December 12, 2016 and August 31, 2018. In addition to SickKids staff, the breach also involves data related to:
- Current and former employees
- Job applicants who applied through the careers website
- Workers at SickKids Foundation
- Workers at Boomerang Health, a Vaughan-based pediatric clinic operated by the hospital
The exact number of affected individuals has not been disclosed — the investigation is ongoing and a final count is expected as the review continues.
What Data Was Exposed
SickKids described the impacted information as sensitive personal information consistent with HR and payroll system data. The hospital has not yet publicly itemized specific data field categories (such as Social Insurance Numbers, banking details, or home addresses), noting that outreach to confirmed individuals is underway and the investigation remains active.
SickKids' Response
The hospital has taken several steps since discovering the incident:
- External cybersecurity experts were engaged immediately
- The careers website was temporarily taken offline and has since been restored
- Direct notification letters are being sent to individuals confirmed to be impacted
- Out of an abundance of caution, broader notifications are going to all potentially affected individuals
- 24 months of complimentary credit monitoring and identity protection services are being offered to those notified
- The incident has been reported to relevant authorities
SickKids emphasized: "Clinical systems and patient information were not affected and patient care has continued as usual."
Third-Party Risk in Healthcare
This incident follows a familiar pattern in healthcare data breaches: an institution's own security posture is bypassed not through a direct attack, but through a vulnerability in a third-party vendor's software. The vendor in this case remains unnamed, but the breach affected SickKids and reportedly other organizations using the same application.
Healthcare institutions are prime targets due to the volume and sensitivity of data they process — not just patient records, but HR, payroll, and recruitment data that carry equally high personal risk when exposed. Third-party supply chain risk remains one of the most persistent blind spots in healthcare security programs.
What Affected Individuals Should Do
If you are or were employed at SickKids, SickKids Foundation, or Boomerang Health, or applied for a position through the careers website between December 2016 and August 2018, watch for notification letters from the hospital.
Steps to take:
- Enroll in the offered credit monitoring when notified — 24 months of coverage is being provided
- Place a fraud alert with Equifax and TransUnion Canada
- Monitor financial accounts for unusual activity
- Be alert for phishing — breached data is often used for targeted social engineering
Timeline
| Date | Event |
|---|---|
| December 12, 2016 | Start of HR/payroll data exposure window |
| August 31, 2018 | End of primary exposure window |
| July 9, 2026 | Breach identified by SickKids |
| August 20, 2026 | Public disclosure and notification letters sent |
| August 21, 2026 | Investigation described as ongoing |
Sources: CP24, CTV News, BleepingComputer. Investigation is ongoing and additional details are expected as SickKids completes its review.