Online links revealed the cell phone numbers and schedules of healthcare workers at Penn Medicine, Children’s Hospital of Philadelphia, and at least 50 other health systems nationwide.
The data, managed by the scheduling software QGenda, was taken down in late August by Philadelphia-area hospitals. While the leak included months of internal scheduling data, no private patient information was affected.
“We are adding controls that both preserve appropriate protection and provide reliable access for those who need the information to coordinate patient care,” a Penn Med spokesperson wrote.
The spokesperson added that the affected platform “includes work-related provider information used to support clinical operations” and “does not contain patient information.”
It remains unclear when the data leak occurred, as many hospitals were informed of the online links by news reports.
According to an email to employees from CHOP — first reported by The Philadelphia Inquirer — the hospital has taken “an abundance of caution” by enforcing security updates that renew access to on-call schedules. Other affected hospitals have also either removed the link or created a password requirement.
QGenda is used by thousands of organizations to streamline scheduling and access to patient care. The software allows users to access their schedules in multiple ways, including through “QuickLinks,” which can be accessed by staff without a QGenda account.
The breach follows a string of cybersecurity incidents on Penn’s campus and across higher education. In May, cybercrime group ShinyHunters shut down several university’s access to Canvas — including Penn.
RELATED:
Cybercrime group crashes Penn’s Canvas system, demands ransom to prevent data release
Over 300,000 Penn users affected in Canvas hack, cybercrime group claims
The group first targeted Penn in the fall of 2025, when it released thousands of internal files — such as donor records, internal memos, and other confidential University files. The hack became apparent on Oct. 31, 2025, when mass spam emails criticizing the University’s security measures and admissions practices were sent from email addresses affiliated with the Graduate School of Education.






