Hong Kong Hospital Authority Suspends Contractor Data Access After Major Leak
The Hong Kong Hospital Authority has suspended all contractors' access to patient data following a significant security breach that compromised the personal information of over 56,000 patients at United Christian Hospital. The leaked data included sensitive details such as names, identity card numbers, dates of birth, and surgical procedure records. Additionally, more than 1,000 authority employees were affected by the incident. In response, the Authority announced immediate security measures, including the deployment of staff to supervise emergency maintenance and prevent illegal downloads. While the Authority is considering barring the involved company from future bidding opportunities, it declined to comment on terminating existing contracts or disciplining staff, citing an ongoing police investigation. Eric Wong, the Authority’s chief systems manager for IT strategy and architecture, revealed these new security protocols during a press briefing. This incident highlights critical vulnerabilities in healthcare data management and has triggered a formal law enforcement probe to determine the extent of the breach and identify responsible parties.
Wire timeline
Hong Kong Hospital Authority Suspends Contractor Data Access After Major Leak
The Hong Kong Hospital Authority has suspended all contractors' access to patient data following a significant security breach that compromised the personal information of over 56,000 patients at United Christian Hospital. The leaked data included sensitive details such as names, identity card numbers, dates of birth, and surgical procedure records. Additionally, more than 1,000 authority employees were affected by the incident. In response, the Authority announced immediate security measures, including the deployment of staff to supervise emergency maintenance and prevent illegal downloads. While the Authority is considering barring the involved company from future bidding opportunities, it declined to comment on terminating existing contracts or disciplining staff, citing an ongoing police investigation. Eric Wong, the Authority’s chief systems manager for IT strategy and architecture, revealed these new security protocols during a press briefing. This incident highlights critical vulnerabilities in healthcare data management and has triggered a formal law enforcement probe to determine the extent of the breach and identify responsible parties.
News - South China Morning Post