Necva Tastan Sevinc
25 September 2026•Update: 25 September 2026
A cyberattack on a Polish healthcare software provider compromised the confidentiality of patients’ personal data, a treatment center said, weeks after a separate breach reportedly exposed records belonging to nearly 19 million people, local media reported on Friday.
The latest attack targeted Qbusoft, the company behind Medyc software used by healthcare providers to manage patient records, Polish broadcaster TVP World reported.
The Rehabilitation and Psychiatric Treatment Center in Inowroclaw said Thursday that patients’ contact details and national identification numbers may have been affected. It did not specify how many patients were involved.
Digital Affairs Minister Krzysztof Gawkowski said the Central Office for Combating Cybercrime was examining the incident as part of a broader investigation. He said the government had issued new security recommendations to companies supplying software to the healthcare sector.
“In the event of a breach of any security procedure by a private company, strict consequences will be imposed,” Gawkowski said.
The incident follows an August breach involving MyDr, a system used by about 12,000 healthcare providers. Data belonging to almost 19 million people, including information on medicines and prescriptions, was reportedly exposed in that attack.