Hong Kong Hospital Authority Concedes Data Breach Affecting 56,000 Patients

Posted on

Hong Kong Data Breach Sparks Investigation into Patient Information Leak

Hong Kong’s privacy watchdog and police are currently investigating a major data breach involving over 56,000 patients served by the Hospital Authority. The incident has raised serious concerns about the security of sensitive personal and medical information.

The Hospital Authority reported that unauthorized access to patient data occurred, which included names, identity card numbers, genders, dates of birth, hospital visit dates, and details of surgical procedures. Affected patients were primarily those from hospitals in Kowloon East. The authority issued an apology for the breach and confirmed that its monitoring system detected a suspected unauthorized retrieval of patient information and a leak on a third-party platform at around 2am on Friday.

However, a subsequent review of the internal network systems did not indicate a cyberattack. Despite this, the authority immediately suspended the contractor’s system maintenance work and reported the breach to the Office of the Privacy Commissioner for Personal Data and the police. It also pledged full cooperation with the ongoing investigations.

Steps Being Taken to Address the Breach

The Hospital Authority stated that it would notify affected patients through various channels, including its HA Go mobile application, letters, and phone calls. A dedicated hotline was also set up for patients with inquiries. The authority urged patients to remain vigilant against the possible misuse of their personal data and to seek help from the police if necessary.

In addition, the authority has been continuously implementing measures to strengthen its healthcare system, such as enhancing cybersecurity safeguards and staff awareness. Libby Lee Ha-yun, the chief executive of the authority, mentioned in a letter to staff that the incident involved someone illegally obtaining patient data. She noted that the leaked files were in a raw format and included a small number of staff names and ranks. The authority has requested the relevant third-party platforms to remove all leaked material.

Response from Privacy Watchdog and Experts

The privacy watchdog confirmed that it had received a report from the Hospital Authority on Friday, noting that patients’ health information and hospital visit dates had been leaked. A spokesman for the office said they would investigate the incident according to their current mechanisms. They also urged affected patients to remain vigilant and exercise caution when receiving suspicious phone calls or messages.

Affected patients are advised to change passwords for their online accounts, check for unusual login records, and consider reviewing their bank accounts for any unauthorized transactions. The police have also launched an investigation into the incident, though no arrests have been made so far.

Francis Fong Po-kiu, honorary president of the Hong Kong Information Technology Federation, described the incident as grave, especially since it involved medical records. He emphasized the importance of encrypting all patient information to reduce the chances of being decoded in case of a data leak. Fong noted that the leaked data is now “spilt milk,” and the only course of action for victims is to remain vigilant.

He also suggested that changing system settings during the contractor’s maintenance work could have led to the leak, or that staff may have retrieved the information by mistake. Fong highlighted previous cases where contractors hired by government departments had compromised data due to negligence. He stressed the need for staff to supervise contractors and ensure they follow the authority’s rules. He also recommended that maintenance contractors should not be allowed to access personal privacy information.

Fong urged the authority to conduct security audits every six months, strictly follow auditor recommendations, and enhance staff training, including regular cybersecurity drills.

Broader Context of Data Leaks in Hong Kong

This incident follows another data leak last month involving the personal information of 6,800 current and former staff of the city’s prison authorities. The Correctional Services Department reported that a hacker had gained illegal access to one of its IT systems.

The privacy watchdog noted in February that data leaks increased by 21% last year, with hacking being the primary cause. Hacking accounted for 81 cases, which was about one-third of the total and 33% more than the 61 cases in 2024. Additionally, three data security cases involving employers’ improper handling of staff data were reported last year, including a hotel security head storing staff appraisal forms in an unlocked drawer accessible to others.

As the investigation continues, the focus remains on ensuring the security of personal data and preventing future breaches. The incident underscores the urgent need for stronger cybersecurity measures and greater oversight of third-party contractors handling sensitive information.

Leave a Reply

Your email address will not be published. Required fields are marked *