Hong Kong Hospital Authority: Probe launched after Hospital Authority data breach involving 56,000 patients

Hong Kong Hospital Authority: Probe launched after Hospital Authority data breach involving 56,000 patients

Hong Kong Hospital Authority Suffers Major Data Breach Affecting 56,000 Patients

Hong Kong’s Hospital Authority reported a significant data breach on Friday, exposing the personal and medical information of over 56,000 patients. The incident, detected early that morning through routine monitoring, involved unauthorized access to sensitive data, which was subsequently leaked on a third-party platform.

The compromised information includes patients’ names, Hong Kong identity card numbers, genders, dates of birth, hospital visit records, and detailed medical histories. The Office of the Privacy Commissioner for Personal Data (PCPD) confirmed receiving the report and launched an investigation into the breach.

Authorities have not yet identified the source of the leak but are coordinating with law enforcement to assess the scope and impact. The Hospital Authority has not disclosed whether the breach stemmed from an internal or external cyberattack. While no evidence of immediate financial fraud has been reported, affected patients have been advised to monitor their accounts for suspicious activity.

Source: https://www.scmp.com/news/hong-kong/law-and-crime/article/3349020/probe-launched-after-hospital-authority-data-breach-involving-560000-patients

Hospital Authority cybersecurity rating report: https://www.rankiteo.com/company/hospital-authority

"id": "HOS1775284192",
"linkid": "hospital-authority",
"type": "Breach",
"date": "4/2026",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'customers_affected': '56,000',
                        'industry': 'Healthcare',
                        'location': 'Hong Kong',
                        'name': 'Hong Kong Hospital Authority',
                        'type': 'Healthcare Provider'}],
 'customer_advisories': 'Affected patients advised to monitor their accounts '
                        'for suspicious activity',
 'data_breach': {'data_exfiltration': 'Leaked on a third-party platform',
                 'number_of_records_exposed': '56,000',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Names',
                                              'Hong Kong identity card numbers',
                                              'Genders',
                                              'Dates of birth',
                                              'Hospital visit records',
                                              'Medical histories']},
 'date_detected': '2023-11-10T00:00:00Z',
 'date_publicly_disclosed': '2023-11-10T00:00:00Z',
 'description': 'Hong Kong’s Hospital Authority reported a significant data '
                'breach on Friday, exposing the personal and medical '
                'information of over 56,000 patients. The incident involved '
                'unauthorized access to sensitive data, which was subsequently '
                'leaked on a third-party platform.',
 'impact': {'brand_reputation_impact': 'Potential impact due to data breach',
            'data_compromised': 'Personal and medical information of over '
                                '56,000 patients',
            'identity_theft_risk': 'High'},
 'investigation_status': 'Ongoing',
 'references': [{'date_accessed': '2023-11-10T00:00:00Z',
                 'source': 'Hong Kong Hospital Authority'}],
 'regulatory_compliance': {'regulatory_notifications': 'Reported to the Office '
                                                       'of the Privacy '
                                                       'Commissioner for '
                                                       'Personal Data (PCPD)'},
 'response': {'communication_strategy': 'Advisories issued to affected '
                                        'patients',
              'enhanced_monitoring': 'Routine monitoring detected the breach',
              'law_enforcement_notified': 'Yes'},
 'title': 'Hong Kong Hospital Authority Suffers Major Data Breach Affecting '
          '56,000 Patients',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.