Medical data leak from Medyc.pl – CBZC launches investigation, Minister Gawkowski responds
The Central Bureau for Combating Cybercrime is investigating an attack on Qbusoft systems, the producer of Medyc.pl software. The company has not reported the incident to CERT Poland to date.

Another attack on medical software – CBZC in action, Qbusoft failed to report incident
The Central Bureau for Combating Cybercrime is conducting operations in connection with a cyberattack on the systems of Qbusoft Sp. z o.o., based in Olsztyn – the producer of the Medyc.pl cabinet application. As Minister of Digitalisation Krzysztof Gawkowski stated on Thursday via the X platform, the case is part of a broader investigation. Medyc software is used, among other things, for managing medical documentation.
According to money.pl, the zaufanatrzeciastrona.pl website was the first to report the leak, informing of "a new major leak of personal and medical data from Qbusoft systems". The website reported that the same individuals behind the attack are responsible for a previous attack on the MyDr platform – from which data of over 18 million Poles was stolen.
Contact details, PESEL numbers and health information
The cyberattack was reported on Thursday by the Psychiatric and Neurological Treatment Centre in Inowrocław. In a statement posted on the facility's website, it was explained that "the system of the data processor, namely Qbusoft Sp. z o.o., fell victim to a cyberattack, which resulted in a breach of the confidentiality of patients' personal data". Among the data affected by the incident were contact details, PESEL numbers and information concerning health status.
The Centre noted at the same time that "investigative analysis conducted by MyDr confirmed that the incident has been contained and that there is no evidence indicating further unauthorised access to the systems".
Minister threatens consequences, company silent
Gawkowski emphasised that Qbusoft has not reported the cybersecurity incident to either CERT Poland or CSiRT CeZ (Cyber Security Incident Response Team Centre for e-Health). "In the event of any breach of security procedures by a private company, absolute consequences will be imposed," the minister wrote.
CSiRT CeZ and the Ministry of Health have developed security recommendations for healthcare software providers, which were sent for implementation on 16 September 2026.
Background: MyDr attack from August
In August, the Ministry of Digitalisation reported that a cyberattack on MyDr resulted in a data leak affecting 19 million Poles, including information on medicines and prescriptions. MyDr is a provider of an electronic medical documentation system used by 12 thousand medical entities. The current CBZC investigation covers both cases and points to the activity of the same group of perpetrators.
Source: Google News PL