Skip to content
Security & Trust

Two Polish health-software breaches show where clinic risk sits

A treatment center was affected by both the MyDr and Medyc incidents. The exposure sat in supplier databases.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Two Polish health-software breaches show where clinic risk sits

AI-generated image for WebPulse. About our images

Key finding

Period covered by affected records at one center: July 2024 – August 2026 (Source: The Record, citing the Addiction and Psychiatric Treatment Center in Inowrocław (September 28, 2026))

The clinic's perimeter is its vendor's database

A clinic can run its own systems carefully and still lose its patients' records, because the records no longer live at the clinic. The risk did not disappear when medical records moved to a cloud platform. It moved to a supplier the clinic does not control. When that supplier is breached, the clinic is still the party patients look to for an explanation.

That is the lesson in two recent incidents at Polish healthcare software providers, reported by The Record on September 28, 2026. One is Qbusoft, the company behind Medyc, a cloud platform that Polish providers use for electronic records, patient scheduling and prescriptions. The other is MyDr, a separate vendor.

What happened at Medyc

The account comes from a notification issued by one affected provider, the Addiction and Psychiatric Treatment Center in Inowrocław. It describes an outsider abusing an SQL injection flaw in Medyc's application interface toward the end of August. SQL injection is a class of weakness in which crafted input makes an application run database commands its designers never intended. A database archive, itself encrypted, was then copied off Qbusoft's systems. Discovery came on September 9, according to the center, and Qbusoft closed the flaw that same day.

In its public statement, Medyc confirmed that names, PESEL national ID numbers, addresses, phone numbers and email addresses were taken. The company said it had not confirmed theft of medical records. The center, however, said it was told Qbusoft had found evidence that scripts were run against database tables holding medical information, making it "highly likely" that some medical records were also taken. At this center, the material potentially exposed covers treatment and discharge paperwork for people attending its daytime addiction program.

July 2024 – August 2026
Period covered by affected records at one center
Source: The Record, citing the Addiction and Psychiatric Treatment Center in Inowrocław (September 28, 2026)

Two vendors, one clinic

That same center appears on the affected list for the earlier MyDr breach as well. Polish authorities have said that incident potentially involved information on about 19 million people and roughly 12,000 healthcare organizations. MyDr says it removed the cause and added safeguards, but it has not publicly detailed the vulnerability.

About 19 million
People potentially involved in the MyDr incident
Source: Polish authorities, as reported by The Record (September 28, 2026)
Approx. 12,000
Healthcare organizations potentially involved in the MyDr incident
Source: Polish authorities, as reported by The Record (September 28, 2026)

One clinic exposed through two suppliers is a single data point, not a trend. It does show what concentration means in practice. A clinic that relies on two vendor platforms for records, scheduling and prescriptions has put its patient data inside two other companies' security programs. Digital Affairs Minister Krzysztof Gawkowski described a recent uptick in criminal targeting of the sector that authorities have been tracking.

Encryption is only as good as the path around it

Some identifying data at the center, including names and PESEL numbers, was encrypted in the database. Even so, the center was told to treat that protection as easily defeated by the attackers. The source does not explain why. For a buyer, the practical point is that a vendor's assurance that data is "encrypted" is where the questioning starts. Who can decrypt it, through which path, and did that path survive a compromised application interface?

Disclosure is the second exposure. Gawkowski took Qbusoft to task because CERT Polska and the health sector's national response team were not told at the outset. The data protection regulator's president has directed that the firm responsible for Medyc be audited. The minister also said authorities are preparing regulations that include mandatory security certification and limits on how private companies process medical data.

Attribution remains unsettled. Zaufana Trzecia Strona reported contact from a party calling itself "fingerprint" that claimed the Medyc intrusion, along with records on 5 million patients and 8 million photographs. The publication could not verify those figures. Polish authorities have not attributed the breach to any individual or group, and the stolen data has not been publicly released.

Questions to put to your team

First, list every supplier that holds customer or patient records for you, and how much history each one retains. In this case the affected records span more than two years. Second, check what your contracts require of a vendor after an incident: who is told, how fast, and whether you learn of it before regulators or after. Third, ask whether identifiers encrypted by a vendor can be decrypted by that vendor's own application layer, and what that means when the application is the point of entry. Fourth, ask whether your incident plan assumes you will hear from the vendor first, and what happens if you do not.

Outsourcing the database does not outsource the duty to explain what happened to the person in the record. Budget for the supplier's security as though it were your own, because in a breach your patients will treat it that way.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Record.

Share this insight