Summary
- Poland’s UODO has announced an inspection of Qbusoft following an attack affecting the Medyc healthcare platform.
- One affected provider says forensic findings identified SQL injection followed by transfer of an encrypted database archive from the supplier environment.
- Media reports cited by UODO put the possible population at up to five million people, but that figure has not been confirmed by the regulator.
Poland’s data protection authority will inspect Qbusoft following a cyberattack affecting its Medyc healthcare software, as authorities and affected medical organisations work to establish the wider scope of patient-data exposure.
Qbusoft develops Medyc, a platform used by healthcare organisations to manage patient and clinical information. Poland’s Office for Personal Data Protection, UODO, said on 25 September that its president, Mirosław Wróblewski, would inspect the company following reports of a new medical-data leak.
UODO said media reports suggested the incident could involve medical information relating to as many as five million people. The regulator has not confirmed that figure, and it should not be treated as an established breach population.
The authority said Poland’s Central Bureau for Combating Cybercrime was investigating the incident. It also cited Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski as saying the inquiry included a cybersecurity incident involving Qbusoft’s Medyc software.
Information published by at least one healthcare organisation using the platform provides more detailed evidence about the attack affecting its patients.
The Odwykowo-Psychiatryczny Ośrodek Leczniczy in Inowrocław said findings supplied by Qbusoft with support from forensic specialists showed an unauthorised party exploiting an SQL injection vulnerability in the application interface on 22 and 23 August.
According to the provider’s breach notification, the exploitation resulted in an encrypted database archive being transferred outside Qbusoft’s system environment. The incident was detected during the night of 8 to 9 September.
For that provider, the notification says confirmed extracted data included patients’ names, PESEL identification numbers, addresses, telephone numbers, and email addresses. It also says analysis found scripts directed at tables containing medical information and that Qbusoft considered it highly probable that clinical documentation had also been obtained.
Those findings relate to the notifying healthcare organisation and should not automatically be extrapolated to every Medyc customer or to the reported five-million-person figure.
The provider said Qbusoft removed the SQL injection vulnerability on the day the incident was detected, restricted database permissions, rotated passwords and technical secrets, and increased monitoring.
The UODO inspection widens the issue from incident response into supplier accountability. Medical software providers occupy a particularly sensitive position because one platform can process protected information for many independent clinics and care organisations.
A supplier-level compromise can therefore trigger separate notification, investigation, and patient-communication duties across multiple data controllers even where the technical weakness itself exists within a shared processing platform.
The eventual scale will depend on which Medyc customer environments were affected, what records were transferred, and whether protections applied to the extracted information remained effective after the archive left the supplier environment.
UODO’s notice also raises questions over cybersecurity reporting. It cited the digital affairs minister as saying Qbusoft had at that point not reported the cybersecurity incident to CERT Polska or the healthcare CSIRT, while the affected provider’s notification says Qbusoft had supplied evidence to police and reported the matter to UODO.
Those are different reporting channels and obligations, and the apparent distinction will form part of the wider accountability picture as authorities establish the timeline.
UODO has not reached a regulatory finding against Qbusoft. Its announced inspection will examine the organisation following an incident that has already produced confirmed patient-data breaches at individual healthcare providers, while the total number of affected people remains to be established.





