← Hospital Authority Hong Kong

2026 Hong Kong Hospital Authority — Kowloon East patient data leak (~56K+ patients; contractor; Apr 3–4)

2026 57.0K records affected Share on X

Data compromised

Names, HKID numbers, gender, DOB, hospital visits, surgical details; staff data cited in later police reporting

Technical writeup

Hong Kong’s Hospital Authority (HA) reported that routine monitoring around 2:00 a.m. on April 3, 2026 detected suspected unauthorized retrieval of patient information and material appearing on a third-party platform. The government press release and follow-on journalism described more than 56,000 patients in the Kowloon East cluster, with categories including names, gender, Hong Kong identity card numbers, hospital file numbers, and surgical procedure details; HA later indicated additional individuals such as staff may also be included in the overall scope (press cited roughly 1,000 staff in some reports). HA stated internal hospital networks showed no indication of a cyberattack, suspended a systems maintenance contractor’s work, notified the Privacy Commissioner and police, and opened a public hotline (5215 7326). Subsequent police updates described an arrest of a contractor employee and seizures of digital devices; some reporting later narrowed preliminary scope to systems associated with United Christian Hospital. Victim counts are subject to official updates.

Root cause

Unauthorized data retrieval from contractor-maintained systems; insider/contractor abuse alleged in police investigation

References