Cyber attack on Qbusoft: UODO president announces inspection following medical data leak

UODO President Mirosław Wróblewski announced an inspection of Qbusoft following a cyber attack on the Medyc application. Among the compromised data were PESEL numbers and patients' contact details.

Cyber attack on Qbusoft: UODO president announces inspection following medical data leak

UODO launches inspection of Qbusoft following attack on Medyc system

Mirosław Wróblewski, president of the Office for Personal Data Protection (UODO), announced on Friday an inspection of Olsztyn-based company Qbusoft in connection with a cyber attack on its Medyc application — software used, amongst other purposes, for maintaining electronic medical records. The information is reported by Dziennik Gazeta Prawna.

"The incident resulted from an attack on the Medyc application," the Office for Personal Data Protection stated in an official statement.

The breach was first publicly disclosed by the Odwykowo-Psychiatric Treatment Centre in Inowrocław. In a statement posted on the facility's website, the centre announced that Qbusoft Sp. z o.o., based in Olsztyn, fell victim to a cyber attack which may have resulted in the disclosure of patients' personal data — including contact details and PESEL numbers.

The Central Bureau for Combating Cybercrime is conducting proceedings into the incident. Deputy Prime Minister and Minister of Digitalisation Krzysztof Gawkowski announced this on Thursday.

Gawkowski added that CSiRT CeZ — the Cyber Security Incident Response Team operating under the eHealth Centre — and the Ministry of Health developed security recommendations for medical software suppliers. The document was transmitted to suppliers for implementation on 16 September 2026.

The attack on Qbusoft is the latest incident of this type affecting the healthcare sector in Poland. In August, the Ministry of Digitalisation revealed that as a result of a cyber attack on MyDr — a provider of an electronic medical records platform — data of approximately 19 million Poles was leaked, including information about medications and issued prescriptions. The incident affected 12,000 medical entities using the platform.

Source: Dziennik Gazeta Prawna

Read this article in the original language