The news
Attackers stole Polish patients' personal data in the Medyc data breach, exploiting an SQL injection flaw at software maker Qbusoft in late August, an affected clinic said. Poland's data protection authority said on September 25 that it would inspect Qbusoft.
Qbusoft develops Medyc, a medical records and practice management platform used by healthcare providers. One affected provider said, according to The Record, that an intruder abused an SQL injection weakness in the Medyc application's interface in late August and exfiltrated an encrypted database archive from Qbusoft's systems. SQL injection is a flaw that lets attackers slip database commands into a website's inputs to pull out stored data. The break-in was spotted on the night of September 9, the provider said.
Medyc said on September 25 that the attackers obtained names, PESEL national ID numbers, home addresses, phone numbers and email addresses, The Record reported. The company said it had not confirmed that medical records were stolen, but an affected provider said Qbusoft found signs the attackers ran scripts on tables holding medical data, making theft of some medical records very likely. Qbusoft patched the flaw the day the attack came to light, the provider said, and told it to assume encrypted names and PESEL numbers could easily be decrypted. Medyc added that frequent attack attempts in recent weeks could slow or briefly interrupt parts of its service.
The Addiction and Psychiatric Treatment Center in Inowrocław said patients of its day treatment unit treated between July 2024 and August 2026 were affected. The center said the medical details at risk include hospital treatment records and discharge summaries. Other affected providers have not been named in the sources reviewed.
The scale is unclear. Poland's data protection authority, citing media reports, said on September 25 the leak may involve medical data of up to five million Poles. Polish cybersecurity publication Zaufana Trzecia Strona said a person or group using the name fingerprint claimed responsibility and claimed to hold records on 5 million patients and 8 million private photographs, according to The Record. The publication said it could not independently verify those figures.
The response has been sharp. The Record reported that Digital Affairs Minister Krzysztof Gawkowski said on September 24 that the Central Bureau for Combating Cybercrime was investigating, and criticized Qbusoft for not initially reporting the incident to CERT Polska or the health sector's incident response team. In its September 25 announcement, the data protection authority, known as UODO, said its president, Mirosław Wróblewski, would inspect the company, including its technical and organizational safeguards and risk analysis.
The numbers
- Intrusion detected
- Overnight on September 9, 2026 (affected provider, via The Record)
- Patient treatment period covered at Inowrocław unit
- July 2024 to August 2026
- Possible scale, per regulator
- Up to 5 million Poles (UODO, citing media reports)
- Records claimed by the attacker, unverified
- 5 million patients and 8 million photos (Zaufana Trzecia Strona, via The Record)
- Earlier MyDr breach scope
- About 19 million people and about 12,000 healthcare organizations (Polish authorities, via The Record)
Why CEOs should care
For boards and CFOs, this is a third-party risk story. A single records vendor holds data for many clinics, so one flaw at the vendor becomes a breach at every customer, each with its own patients to notify and regulators to answer. Ask which suppliers hold your most sensitive data, how many of your customers or patients each one touches, and whether your contracts require prompt notice of any intrusion.
For CIOs and CISOs at healthcare providers, the details point to specific questions. SQL injection is a long-known class of flaw that routine testing should catch, so ask vendors how often they test their web interfaces and who does it. Ask how data is encrypted and where keys sit, since Qbusoft told a client to assume encrypted names and PESEL numbers could be easily decrypted. Confirm that vendors will report incidents to national authorities, because Gawkowski publicly faulted Qbusoft for not initially doing so.
For technology buyers in Poland, regulation may tighten. Gawkowski warned that the strictest consequences would be enforced when a private company breaches security procedures, and The Record reported he discussed mandatory security certification and limits on how private companies process medical data. Buyers should expect vendor certification to become a procurement requirement and should start asking for evidence now.
The bigger picture
The Medyc breach follows the MyDr incident, which Polish authorities said potentially involved information on about 19 million people and roughly 12,000 healthcare organizations, according to The Record. MyDr also makes practice management software, and Zaufana Trzecia Strona has previously linked the fingerprint name to that breach, The Record reported. The Inowrocław center was affected by both. Healthcare software vendors concentrate highly sensitive data, which makes them efficient targets.
What’s next
UODO's inspection will examine Qbusoft's safeguards and risk analysis, and the cybercrime bureau's investigation continues. Watch for the number of affected providers and patients to become clearer, and for any draft rules from Gawkowski's ministry on certification and on how private companies may process medical data.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





