SickKids data breach exposes cybersecurity risk for employee information

A third-party software flaw compromised staff records at SickKids, raising urgent questions for HR leaders across Canada

SickKids data breach exposes cybersecurity risk for employee information

The Hospital for Sick Children in Toronto (SickKids) has disclosed a cybersecurity incident that compromised the personal information of current and former employees — a breach that exposes a growing and underappreciated vulnerability facing human resources (HR) departments at organizations across Canada.

The incident, announced by SickKids on Thursday, involved unauthorized access to employee records through a flaw in a third-party software application. Critically, the breach was not the result of a direct attack on SickKids' own infrastructure. Instead, it exploited a vulnerability in an external platform the hospital shared with other organizations — a pattern that is becoming increasingly familiar to HR leaders managing complex vendor ecosystems.

Clinical systems weren’t affected, and patient care continued without disruption, according to SickKids in a news release. The hospital's external Careers website was temporarily taken offline but has since been restored. SickKids has not disclosed how many individuals were affected, stating only that its review of the impacted information is ongoing.

Third-party risk at the core of data breach

The SickKids incident is an example of what cybersecurity professionals describe as a supply chain vulnerability — where an attacker gains access to sensitive data not by breaching an organization’s own defenses, but by targeting a third-party technology provider with access to that organization’s data.

For HR leaders, this distinction matters. Payroll platforms, applicant tracking systems, benefits administrators, and workforce management tools routinely hold sensitive employee data, including social insurance numbers, banking details, and home addresses. When those vendors become a point of failure, the employer bears reputational and legal consequences regardless of where the technical breach originated.

SickKids confirmed that the personal information of current and former employees from three affiliated entities may have been exposed: the hospital itself, Boomerang, and the SickKids Foundation. Job applicants whose information was held in the Careers system were also potentially compromised. The hospital engaged external cybersecurity experts to support its investigation and said affected individuals will be notified directly as the review progresses.

What employers owe affected employees

Once a breach is identified, Canadian employers face clear obligations. SickKids moved quickly to alert all potentially affected individuals as a precaution – not waiting for its investigation to conclude – and offered 24 months of complimentary credit monitoring and identity protection services. That response reflects both best practice and the reputational stakes involved for a prominent public institution.

Under Canada's federal privacy legislation — the Personal Information Protection and Electronic Documents Act (PIPEDA) — organizations that experience a breach of security safeguards involving personal information must notify the Office of the Privacy Commissioner of Canada and affected individuals when there is a real risk of significant harm. Provincially regulated organizations may face additional requirements depending on jurisdiction.

A cybersecurity risk pattern

This incident isn’t the first time SickKids has faced a data security reckoning. In 2007, the hospital was ordered to encrypt all electronic patient files after a laptop containing health information on approximately 2,900 people was stolen from a vehicle belonging to a doctor at the institution, according to the Toronto Star. That earlier incident involved patient data while this latest breach targets employee records, but both reflect the enduring challenge of protecting sensitive personal information across a large, complex healthcare organization.

In 2022, the hospital suffered a ransomware attack that closed down the payroll system for several weeks, according to CTV News.

That history matters for HR leaders assessing their own organizations’ posture. Security incidents are rarely isolated events. They tend to reveal systemic gaps in data governance, vendor management, and employee information lifecycle practices – gaps that often pre-date the breach by years.

Former employees, in particular, represent a blind spot for many HR teams. Once a person leaves an organization, data retention and deletion are rarely reviewed with the same rigour applied to active staff. The SickKids breach affected former employees alongside current ones – a reminder that data minimization is an HR responsibility, not purely an IT concern.

SickKids said it remains committed to strengthening its cybersecurity measures to protect personal employee information.

LATEST NEWS