Seoul National University Hospital skips cybersecurity disclosure for years despite breach affecting 830,000
Seoul National University Hospital did not file mandatory cybersecurity disclosures for years, even after a breach that affected 830,000 people. An investigation revealed the hospital had been operating under an exemption from the standard reporting requirements that apply to other large hospitals.
Why this matters: 830,000 people had their data exposed, and the hospital was not required to tell regulators anything. That exemption is doing a lot of work here. Disclosure rules exist so that breaches get counted, patterns get noticed, and institutions face some pressure to improve. When a hospital this large can sidestep that process, the people whose data was taken have no way to know the system is watching out for them. The real issue is whether an exemption that made sense on paper was ever meant to cover a breach of this scale.
Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.