The news
Two health data exposure cases reported in late September 2026 show how patient records leak through reporting tools and software vendors. Washington, DC's Medicaid agency found hidden personal data in public web reports, while Poland is investigating a hack of the Medyc medical software platform.
The District of Columbia Department of Health Care Finance (DHCF) said it learned on July 21, 2026, that two reports on its website contained hidden personal information. The reports were meant to show summary figures, such as enrollment counts, but the agency said the underlying data may have been reachable by unauthorized users from 2023 through July 2026.
According to DHCF, the data included Medicaid ID numbers, dates of birth, provider names, race, gender, ward and ethnicity, but not names, Social Security numbers or financial account information. SecurityWeek reported that DHCF told the US Department of Health and Human Services that 399,086 Medicaid and DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026 were affected. DHCF said it removed the reports and has no reason to believe anyone looked at or misused the information.
In Poland, attackers exploited a SQL injection flaw, a technique that slips database commands into web input fields, in Medyc, a cloud platform from Qbusoft that healthcare providers use for medical records, scheduling and prescriptions, The Record reported. Rzeczpospolita reported that Qbusoft is based in Olsztyn. The intrusion was detected overnight on September 9, and Qbusoft fixed the flaw that day, according to The Record.
The Record reported that names, national identification numbers, home addresses, phone numbers and email addresses were stolen. One affected provider, the Addiction and Psychiatric Treatment Center in Inowrocław, said hospital treatment records and discharge summaries may also have been compromised for patients its addiction day treatment unit treated between July 2024 and August 2026, according to The Record. A person or group calling itself "fingerprint" claimed to hold records on 5 million patients and 8 million photographs, according to Polish outlet Zaufana Trzecia Strona as cited by The Record. That claim has not been verified.
Digital Affairs Minister Krzysztof Gawkowski criticized Qbusoft for not initially reporting the incident to CERT Polska, the national incident response team, The Record reported. Rzeczpospolita reported that Poland's data protection office, UODO, plans to inspect Qbusoft and that the Central Cybercrime Bureau is investigating. The Record noted that an earlier breach at MyDr, another medical software provider, potentially involved data on about 19 million people and 12,000 healthcare organizations.
The numbers
- DC beneficiaries affected (DHCF filing with HHS, per SecurityWeek)
- 399,086
- Period DC data may have been reachable (DHCF)
- 2023 to July 2026
- Medyc intrusion detected (The Record)
- Overnight on September 9, 2026
- Records claimed by "fingerprint" (unverified)
- 5 million patients; 8 million photographs
- Earlier MyDr breach scope (The Record)
- About 19 million people; about 12,000 healthcare organizations
Why CEOs should care
For CIOs and data leaders at health systems and public agencies, the DC case was not a hack. DHCF said reports designed to show group statistics carried the individual records behind them. Ask which dashboards and published reports on your websites are built on person-level data, who checks what a downloaded file or page source contains beyond what is displayed, and when that was last tested.
For buyers of clinical software, Medyc shows how one vendor flaw can put many providers' patients at risk at once. Contracts should set a fixed window for the vendor to notify customers and national authorities, require evidence of application security testing for common flaws such as SQL injection, and grant audit rights. The Record reported that Gawkowski proposed mandatory security certification and limits on how private companies process medical data, so vendors serving Polish providers may face new rules.
For boards and CFOs, the costs start before any proof of misuse: notification, call centers, reviews and regulator inquiries. DHCF set up a toll-free line but did not offer credit monitoring. Boards should ask whether cyber insurance covers regulatory investigations and whether the incident plan names who notifies which authority, and how fast.
The bigger picture
Both incidents involved well-known weaknesses. SQL injection is one of the oldest web flaws, and SecurityWeek noted that the DC exposure did not result from hacking but from reports that carried hidden personal data. Gaps this basic matter more as AI lowers the skill attackers need, a shift Anthropic has described. In an August 2025 report, Anthropic (the maker of the Claude AI models) said a criminal used its Claude Code tool to automate reconnaissance and credential theft in an extortion campaign against at least 17 organizations, including healthcare and emergency services, with ransom demands that sometimes exceeded $500,000.
Anthropic said AI now lets criminals with few technical skills run complex operations, such as developing ransomware, that once took years of training. For health organizations with thin security teams and many software suppliers, the practical result is more attempts against the same basic gaps.
What’s next
In Poland, watch the outcome of the UODO inspection and the Central Cybercrime Bureau investigation, and whether the government moves ahead with certification rules for medical software providers. Further notices from affected Polish clinics should clarify how many patients were involved. DHCF said it has begun a review and is strengthening internal processes; its findings would show whether other published reports carried the same flaw.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








