SickKids employee information impacted by cybersecurity incident
Summary:
The incident resulted in unauthorized access to personal information of some of our current and former employees. We remain committed to maintaining strong protections and continuously enhancing our cybersecurity measures to help protect the information entrusted to us.
The Hospital for Sick Children (SickKids) was recently targeted in a cybersecurity incident that resulted in unauthorized access to personal information of some of our current and former employees. The incident temporarily affected the external Careers website, which has since been safely restored, and is linked to a vulnerability in a third-party software application used by SickKids and other organizations. Clinical systems and patient information were not affected and patient care has continued as usual.
After learning about the incident, SickKids launched an investigation and engaged external cybersecurity experts to help support our investigation and response efforts. Through our investigation, we have determined that personal information of some current and former SickKids, Boomerang and SickKids Foundation employees as well as SickKids job applicants, may have been affected.
Our review of the impacted information is ongoing. Individuals determined to have been impacted will be notified directly, though, out of an abundance of caution, all potentially impacted individuals have been alerted and offered 24 months of complimentary credit monitoring and identity protection services.
Safeguarding the privacy and security of personal information is a responsibility SickKids takes seriously. We remain committed to maintaining strong protections and continuously enhancing our cybersecurity measures to help protect the information entrusted to us.