Skip to content

Links exposed physician cell numbers and work schedules at health systems in Philly and nationwide

QGenda web links revealed the information for thousands of providers at Children's Hospital of Philadelphia, Penn Medicine, ChristianaCare, and at least 50 other health systems across the country.

The public on-call schedule of Penn Presbyterian Medical Center, with provider names and cell numbers redacted, from QGenda.
The public on-call schedule of Penn Presbyterian Medical Center, with provider names and cell numbers redacted, from QGenda.Read moreScreenshot

Philadelphia-area health systems have been moving swiftly to pull offline web links that publicly revealed the daily work schedules and cell phone numbers of healthcare workers, information that hospitals traditionally do not make available online.

The information for thousands of medical workers at Penn Medicine, Children’s Hospital of Philadelphia, ChristianaCare, and dozens of hospitals nationwide was published online through a popular scheduling service, QGenda.

Experts said the online availability of internal information raises serious security and privacy concerns at a time when healthcare workers increasingly face the threat of workplace violence and doxing.

The Philly-area health systems took down the schedules in late August after The Inquirer alerted them that the information was publicly available. Penn and CHOP did not respond to questions about whether they were aware the link was accessible without a log in.

A spokesperson for ChristianaCare said the system “recently became aware” the pages were public, and “immediately” worked with the QGenda to “eliminate the vulnerability.”

“We are not aware of any impact to caregivers, clinicians, patient care, or operations,” Christiana’s statement said. “Protecting the privacy and security of our caregivers, clinicians, patients, and information systems remains a top priority.”

Other Philadelphia-area systems did not appear have publicly available links.

The web pages managed by QGenda, an Atlanta-based workforce management software company, exposed months of schedules of physicians, nurse practitioners, social workers, and other hospital employees.

The links don’t appear on Google searches, but anyone with access to basic AI chatbots could pull up live schedules showing the hours and assigned hospital service for on-call doctors and other providers.

“That’s very concerning,” said Lane Kantor, a fourth-year medicine-pediatrics resident at Penn and CHOP, explaining that healthcare providers’ work “sometimes comes with patients who can harass and threaten us.”

Kantor, a leader at Penn’s resident union, said the public information of providers who work with undocumented immigrants or in the areas of gender-affirming or abortion care was especially concerning.

QGenda is used by more than 4,500 organizations, according to the company’s website, including many hospitals that use the software as a one-stop source of information about providers who are on-call and available for consult at any given moment.

It is not clear how the schedules became public, how long the information was available online, to what extent hospital administrators knew the information was not safeguarded with a log in requirement, or whether anyone — let alone someone wishing to inflict harm — accessed the information.

QGenda did not respond to multiple requests for comment.

The Hearst-owned company offers “QuickLinks” to allow “any staff member without a QGenda account” to easily access the schedule, according to the company’s website. The site also notes that “on-call schedules may contain sensitive information” and that there is risk of “unauthorized access or data breaches” without proper safeguards.

The platform also enables healthcare systems to restrict access, “so that only devices on your practice’s secure network can access schedule data on the public-facing landing page,” the company’s site says.

Health systems in the Philadelphia area and across the country have taken steps in recent years to minimize doctors’ publicly available information in response to the growing politicization of many health services, especially those involving diversity, equity and inclusion, abortion, and gender-affirming care.

CHOP, for example, removed provider names from the webpage of its gender and sexual development program in 2022 as the clinic received threats because it provides gender-affirming care for teens. But information on clinic’s providers was available through the now-removed public schedule.

Security experts say releasing public work times and locations alongside cell numbers leaves providers vulnerable to being targeted by dissatisfied patients, or individuals who disapprove of the type of medicine a doctor practices.

“This is really alarming,” said Will Owen, a spokesperson for Surveillance Technology Oversight Project, a New York-based privacy nonprofit. “Hospitals must scrutinize the platforms they work with in their data collection to minimize information that can be weaponized.”

Live hospital schedules exposed

After receiving a confidential tip that three East Coast health systems had public QGenda web pages, The Inquirer identified public landing pages for nearly 50 health systems or hospitals nationwide, including Veterans Affairs hospitals, using OpenAI’s Codex.

For some, like Penn and CHOP, the landing pages for the entire system were public. For other hospitals, schedules for only one department or service surfaced.

Some of the United States’ largest and most prestigious institutions had public QGenda links, including Johns Hopkins Medicine and the University of California-San Francisco.

The Inquirer attempted to reach out to each hospital or system for which it found schedules before publication. At least 10, including Hopkins and UCSF, have removed the public link completely or added a password requirement.

A spokesperson for Cedars-Sinai Medical Center in Los Angeles said it was unaware” that its anesthesia department’s schedule was public. The schedule has since been removed.

CHOP informed hospital staff last week about security updates made to QGenda “out of an abundance of caution.”

“We are taking a precautionary step to update access to the QGenda platform used to display CHOP on-call schedules,” CHOP said in an email to staff obtained by The Inquirer.

QGenda’s platform does not contain patient information, and CHOP “continually assess our systems, processes, and technologies with an eye toward privacy, security, and operational needs,” a CHOP spokesperson said in a statement.

Penn said it uses QGenda to support communication among care teams.

“We continually monitor the risk environment surrounding online information and, as it continues to evolve, we are adding controls that both preserve appropriate protection and provide reliable access for those who need the information to coordinate patient care,” Penn said in a statement.

Privacy concerns rattle doctors

Healthcare workers have been reporting increased rates of online harassment and workplace violence since the COVID-19 pandemic.

The problem has become so pronounced that Colorado, for example, enacted in 2021 an anti-doxing law that made it a crime to share the personal information of health workers and their families online.

An American Medical Association policy from 2024 says the organization supports data privacy and anti-doxing laws to prevent threat and harassment.

Gennadiy Ryklin, a hospitalist at ChristianaCare, was surprised to learn a colleague had done a work-hour analysis for ChristianaCare’s attending union using an AI model.

“I asked him, ‘well, how’d you do that without having Claude get access to our private schedules?’ And, well, it’s not private, there’s a public link here,” Ryklin said.

Privacy and data security are principles are drilled into physicians through policies, procedures, and training courses, Ryklin said.

“We understand that patient information in the wrong hands can cause a lot of harm,” the doctor said. “Where’s that same concern for us?”

A June shooting that killed one IT intern and left another injured in ChristianaCare’s Wilmington Hospital underscored for Ryklin the threat of violence within health systems. Law enforcement charged a third intern in connection to the incident.

» READ MORE: Suspect in custody after shooting inside Wilmington Hospital leaves 1 dead, another injured

He reached out to hospital administrators and last week the hospital began removing the public web pages.

Employee privacy exists in a legal gray area, with protections often dependent on institutional policies, said Matthew Bodie, a law professor at the University of Minnesota.

Publicly sharing schedules and cell numbers does “feel invasive,” Bodie said, “especially if employees didn’t know about it.”

The combination of cell numbers and work schedules could be used to cause harm, whether by patients, politically motivated individuals, or stalkers, said Sharona Hoffman, a co-director of the Law-Medicine Center at Case Western Reserve University.

The lack of any sweeping federal employee privacy requirements makes the online availability of the information, “not surprising though very disturbing,” the professor said.