Polish healthcare software provider Qbusoft has confirmed a data breach involving its Medyc platform, after an attacker exploited an SQL injection vulnerability in August. The intrusion was discovered on September 9, and the company says the attackers obtained names, national identification numbers, home addresses, phone numbers, and email addresses. Qbusoft has not confirmed that medical records were stolen, but one affected healthcare provider said it was told that scripts targeting database tables containing medical information made it highly likely that some medical records were also taken.

The Addiction and Psychiatric Treatment Center in Inowrocław said patients at its day treatment unit were affected, and that potentially compromised medical information included hospital treatment records and discharge summaries. The breach has drawn sharp criticism from Polish authorities. Digital Affairs Minister Krzysztof Gawkowski said Qbusoft failed to initially report the incident to CERT Polska or the national healthcare incident response team, and warned of strict consequences for companies that hide attacks. Poland's data protection authority has ordered an audit of the company. Gawkowski also said authorities are preparing regulations that would require mandatory security certification and restrict how private companies process medical data.

The Medyc attack follows a separate, larger breach at MyDr, another Polish healthcare software provider, which may have affected around 19 million people and 12,000 healthcare organizations. The Inowrocław center was also affected by that incident. A person or group using the name fingerprint claimed responsibility for the Medyc intrusion, according to Polish cybersecurity publication Zaufana Trzecia Strona, but the claim could not be independently verified and Polish authorities have not publicly attributed the attack.