Centrum Medyczne Enel-Med, one of Poland’s largest private healthcare networks, confirmed an IT security incident on September 24, 2026 that resulted in a breach of data confidentiality. The company says it immediately secured its network, systems, and customer data; that clinical and administrative operations were not materially affected; and that it notified Poland’s Central Bureau for Combating Cybercrime (CBZC), the e-Health Center’s CSIRT, CERT Polska, and the data protection authority (UODO). English-language coverage from Warsaw Business Journal and CEO Magazine Poland published the confirmation on September 26.
What Enel-Med has not disclosed — at least in the public notices those outlets summarize — is the categories of data involved, how many people may be in scope, or how attackers got in. That gap is the story patients will live with for weeks: a verified confidentiality breach at a named provider, without a finished field inventory or census. BreachHistory’s canonical record is enel-med2026.
Also critical: this is a separate incident from the August MyDr case ministers tied to roughly 19 million records, and from the September Qbusoft/Medyc confidentiality breach confirmed by an Inowrocław clinic. Same country, same PESEL risk model, different companies. Mixing those headlines helps scammers and confuses patients.
What happened: the Enel-Med timeline
September 24, 2026 is the date Enel-Med reported the IT security incident that produced a confidentiality breach. Trade press on September 26 frames the company’s response as immediate containment: secure the network, lock down systems and customer data, keep clinics running, then notify the national cybercrime bureau, the e-Health CSIRT, CERT Polska, and UODO.
That notification stack is deliberate. CBZC owns criminal cyber investigation. CERT Polska is the national CSIRT for coordination and technical advisories. The e-Health Center’s CSIRT sits on Poland’s digital-health rail — the same ecosystem that has been under pressure since MyDr. UODO is the GDPR supervisory authority that will eventually care about controller timelines, patient notices, and whether special-category health data left the environment.
What remains unpublished at indexing time:
- Exact intrusion or detection timestamps beyond the September 24 report date
- Root cause — ransomware, credential theft, vendor compromise, insider misuse, or something else
- Whether data was only accessed in place or also copied offline
- A field-level inventory (PESEL, contact details, visit notes, imaging, billing, corporate-plan HR files)
- A headcount of individuals or records
Absence of those details does not make the incident unverified. Enel-Med itself confirmed a confidentiality breach and said it notified the regulators and services listed above. Verified = company confirmation of confidentiality impact + containment + multi-agency notice. Unpublished = categories, census, and attack path.
What was exposed — and what we still do not know
Start with the company’s language. Enel-Med reported an IT security incident that resulted in a breach of data confidentiality. In GDPR terms, confidentiality breach means unauthorized disclosure or access — not necessarily that every clinic system went offline. The company also said operations were not materially affected, which points away from a clinic-crippling ransomware wipe, at least in the public narrative. It does not prove that no files left the building.
Enel-Med is a multi-site private medical operator serving individual and corporate patients. Systems like that commonly hold identification and contact data, appointment histories, insurance or employer-plan information, and clinical records. CEO Magazine Poland correctly notes why a healthcare confidentiality breach is especially sensitive: medical environments may process not only IDs and phones, but information related to patients’ health and treatment. That is a risk framing, not a published inventory for this incident.
To be clear about what sources support right now:
- Confirmed: confidentiality of data was breached; systems and customer data were secured; ops not materially hit; CBZC, e-Health CSIRT, CERT Polska, and UODO were notified
- Not confirmed: which data categories left or were viewed; how many people; whether PESEL was in scope; whether clinical notes or imaging were involved; whether corporate-client HR files were involved
- Not claimed by Enel-Med: any multi-million actor census tied to this brand
Readers searching “Enel-Med data breach” or “was I affected Enel-Med” should treat the lack of a public census as unfinished forensics — not as proof they are safe. Controllers often finish scoping after the first press cycle. Patient letters, if required, usually lag the headline.
How the attack worked — still an open investigation
Neither WBJ nor CEO Magazine Poland publishes a finished CERT Polska forensic package for Enel-Med. No named ransomware group is tied to the company’s confirmation in those writeups. No SQL-injection path, no VPN brute-force admission, no rogue API key. The honest technical summary at indexing is short: unauthorized access or disclosure sufficient for Enel-Med to call it a confidentiality breach, followed by containment and multi-agency notification.
Unknowns that still matter for patients and corporate clients:
- Whether the incident touched a single application, a shared EMR layer, email, or a broader domain compromise
- Whether third-party processors sitting behind Enel-Med were involved
- Whether attackers still hold a copy of anything they viewed
- Whether UODO will require individual notifications under GDPR Articles 33–34
- Whether phishing that cites Enel-Med will use real partial identifiers from this incident or recycle data from MyDr / Medyc dumps
Cybercriminals do not wait for Enel-Med’s PDF to clear legal review. Polish healthcare headlines alone are enough to run appointment-themed SMS lures this week.
Distinct from MyDr and Qbusoft/Medyc
August’s MyDr breach is the national scale story: Digital Affairs officials described roughly 19 million records and a multi-terabyte corpus spanning prescriptions, appointments, medications, and related documents across thousands of facilities. Searchers still type “Poland medical data breach 2026” and land on MyDr first.
September’s Qbusoft/Medyc case is the second software-vendor shock: an Inowrocław rehabilitation and psychiatric center confirmed patient PII confidentiality may include contact details and PESEL, with CBZC examining that Medyc-stack incident. Actor marketing floated multi-million figures for Medyc that remain unverified.
Enel-Med is the third distinct thread: a named private medical network confirming its own IT confidentiality breach on September 24, with systems secured and operations still running. It is not “MyDr under another brand,” and it is not the Medyc SaaS case. If your clinic door says Enel-Med, this page is the correct map. If your clinic used MyDr or Medyc software from another vendor, follow those separate records.
Why the distinction matters in practice: scammers will deliberately blur the three. A text that says “your PESEL must be reserved after the Polish medical cyberattacks” can cite any brand and still harvest credentials. Accurate patient advice names the controller.
Who is at risk after the Enel-Med confidentiality breach
Individual Enel-Med patients
Anyone who visited Enel-Med medical centres, used Enel-Med ambulatory or specialty services, or held an Enel-Med patient account is in the first risk cohort until the company publishes a scoped notice saying otherwise. Contact data and national IDs are the usual first fields criminals monetize in Polish healthcare leaks — even when the provider has not yet said those fields were in scope. Treat unexpected “Enel-Med remediation” messages with suspicion.
Corporate and employer-plan members
Enel-Med serves corporate patients as well as individuals. Employer-sponsored care often means the provider holds workplace emails, plan identifiers, and billing relationships with HR. Secondary fraud can look like fake occupational-medicine appointment links, fake “benefits portal” password resets, or calls that mix a real employer name with a request to “confirm PESEL for Enel-Med security.”
Family members and caregivers
Parents who booked pediatric visits, adult children managing elder care, and spouses on shared plans may appear in scheduling and contact databases even when they were not the primary patient. Children’s PESEL numbers deserve the same caution as adult IDs.
Enel-Med staff and contractors
Workforce directories, badge systems, and helpdesk tooling are frequent collateral in healthcare IT incidents. Staff should assume helpdesk social engineering will cite this headline and demand MFA codes or remote-access installs.
People who only read the MyDr or Medyc headlines
If you never used Enel-Med, this confirmation does not automatically put you in scope. Keep MyDr and Medyc guidance separate. Do not assume one national SMS covers every Polish healthcare brand.
What Enel-Med and Polish authorities have said
WBJ’s September 26 summary is the tight English digest: Enel-Med reported the September 24 IT security incident; confidentiality was breached; categories, counts, and root cause were not disclosed; the network and customer data were secured; operations were not materially affected; CBZC, the e-Health Center’s CSIRT, CERT Polska, and the data protection authority were notified. WBJ also places the case in the sequence after Qbusoft/Medyc and MyDr without merging the victims.
CEO Magazine Poland’s September 26 piece adds institutional context: Enel-Med as a major private provider; the sensitivity of medical systems; the company investigating and analysing scope; and a patient-alert reminder about unexpected emails, texts, or calls that reference appointments, payments, test results, or patient accounts. It correctly frames the case amid a series of Polish healthcare cybersecurity incidents without inventing a census for Enel-Med.
At indexing, BreachHistory treats Enel-Med’s own confirmation — as reported by those outlets — as enough to mark the confidentiality breach verified. Official recordsAffected stays unpublished/0 in catalog terms until the company or a regulator publishes an attested count. Categories stay unpublished in prose until primary notices list them.
Industry context: Poland’s 2026 healthcare breach cluster
Poland’s health sector spent late summer and early autumn 2026 under continuous pressure. MyDr showed what happens when a widely deployed electronic-records vendor is emptied at national scale. Qbusoft/Medyc showed that a second healthcare-software stack can produce facility-confirmed PESEL confidentiality harm within weeks. Enel-Med shows that large private provider networks are also reporting IT confidentiality incidents even when clinics stay open.
Three patterns keep repeating across Europe’s 2026 healthcare wave:
- Concentration risk — one SaaS EMR or one national-scale vendor can expose millions overnight
- Provider-network risk — multi-site private operators hold dense patient graphs even without being “the MyDr of Poland”
- Notification lag — patients learn from headlines before they receive a personal letter, which is exactly when phishing works best
Poland’s PESEL-centric identity stack raises the stakes relative to systems where medical record numbers stay local. A stolen PESEL is reusable across banking, telecom KYC, and e-government. That is why an Enel-Med confidentiality breach still matters when the census is unpublished: residual identity-fraud risk does not wait for UODO’s PDF.
Related BreachHistory reading for boards writing comparison slides: MyDr’s ~19M Poland breach, Qbusoft Medyc’s clinic-confirmed PESEL leak, and Laboratoria Optimed’s Polish lab-network incident. Different controllers, same lesson: Polish patients now need a vendor-and-provider map, not a single “medical breach” bookmark.
Was I affected? How to think about Enel-Med exposure
There is no public “search your PESEL in the Enel-Med dump” portal from the company at indexing time. Practical triage:
- If you are or were an Enel-Med patient (individual or corporate-plan), watch for an official Enel-Med notice and treat unexpected third-party “breach help” as hostile until verified.
- If your care was only through a different clinic that used MyDr software, follow the MyDr guidance — not this page.
- If your care was through a Medyc/Qbusoft facility such as the Inowrocław center, follow the Medyc guidance — not this page.
- If a stranger already texts you with an Enel-Med appointment detail and asks you to “confirm PESEL after the cyberattack,” elevate risk whether or not your formal letter has arrived.
- If you only saw social posts claiming “all Polish patients are in Enel-Med,” ignore the census invention. Enel-Med has not published that claim.
Waiting passively for a postcard is a weak strategy when phone number plus PESEL — if either later proves in scope — is enough for loan fraud and fake e-recepta portals. Act on hygiene now; refine later when Enel-Med or UODO publish categories.
What you should do
- Confirm which provider and software you used. “Enel-Med clinic,” “MyDr EMR,” and “Medyc/Qbusoft” are different incidents. Ask your facility if you are unsure.
- Watch for official Enel-Med notices on the company’s own channels and any patient portal you already use. Bookmark the real domain; do not trust a link in a cold SMS.
- Reserve or restrict PESEL through official government channels such as mObywatel if you use that service — especially if you also may be in MyDr or Medyc scope. It will not erase leaked copies, but it can blunt some new-contract fraud.
- Ignore unexpected Enel-Med / CBZC / CERT / UODO / NFZ / e-recepta messages that demand PESEL confirmation, a fee, a remote-support install, or a “secure results viewer” download. Call Enel-Med on a number from a prior visit letter or the official site.
- Enable MFA on email and any patient portals; change reused passwords. Email takeover turns a contact leak into full account-recovery fraud.
- Monitor bank and telecom accounts for new loans, KYC resets, or SIM-swap attempts that cite PESEL.
- Corporate-plan members: tell HR/benefits if you receive occupational-medicine phishing that cites Enel-Med; do not approve unexpected SSO grants.
- Keep written records of notice dates for insurers, employers, or a later UODO complaint.
- Enel-Med staff: verify helpdesk callbacks on known internal numbers; assume attackers will spoof IT during the investigation window.
- Parents and caregivers: children’s and elders’ PESEL numbers in family booking files deserve the same caution as your own.
Phishing and secondary fraud to expect
When a major private Polish medical network confirms a confidentiality breach while MyDr and Medyc are still in the news, call centers do not wait for Enel-Med’s final census. Expect:
- SMS claiming your Enel-Med appointment must be “re-verified” after the September 24 cyberattack
- Emails with clinic logos asking you to download a “secure results viewer” or “CBZC evidence pack”
- Voice calls that mix a real Enel-Med centre name with PESEL last digits the caller already knows from another dump
- Fake UODO or CERT Polska messages urging immediate password resets via a lookalike domain
- Lures that deliberately confuse Enel-Med with MyDr or Medyc so victims reuse panic from the 19-million headline
- Corporate-plan lures that look like employer benefits portals tied to “Enel-Med security remediation”
The tell is urgency plus a request for secrets a real clinic already holds or should never ask for over SMS. Hang up. Redial from a known number. Real CBZC investigators do not demand PESEL confirmation through a random link in your texts.
Regulator, insurer, and board angles
UODO scrutiny is predictable once a controller confirms a confidentiality breach and notifies the authority. Enel-Med’s multi-agency notice list — CBZC, e-Health CSIRT, CERT Polska, UODO — is the right opening posture under Polish practice. What still matters for accountability is the next wave: scoped field inventory, affected-person counts, individual notifications if required, and whether special-category health data was involved.
Insurers writing cyber policies for Polish medical networks will ask the same questions months later: when detection occurred, when containment completed, which systems were in scope, whether a copy left, and how patient communications were timed. Boards that equated “operations not materially affected” with “no privacy harm” are learning again that availability and confidentiality are different controls.
For journalists and researchers, stick to primary contours — Enel-Med’s confirmation as reported by WBJ and CEO Magazine Poland, plus any later company FAQ, UODO statement, or CERT Polska advisory — rather than social posts that invent a multi-million Enel-Med census. Precision protects patients: overstating what is confirmed makes real notices harder to trust when they finally arrive.
How this compares to related healthcare breaches
Compared with MyDr, Enel-Med is earlier in the public census phase and smaller in attested scale — a provider-confirmed confidentiality breach without a minister-quoted multi-million figure. Compared with Qbusoft/Medyc, Enel-Med is a named private network speaking for its own systems, not a clinic speaking about a third-party Medyc stack. Compared with pure unverified leak-site marketing, it is stronger: the company itself said confidentiality was breached and named the agencies it notified.
Compared with U.S. HHS OCR mega-filings that publish tidy headcounts, European healthcare incidents often look messier for months — which lengthens the phishing window. Searching only “my clinic breach” may miss the Enel-Med story until the provider names itself in your letter. Searching only “MyDr” may miss that your private network had a separate September incident.
International parallels for boards: other 2026 health-sector rows such as Alaxione’s unverified French patient claim and Astrana Health’s social-engineering breach show the same patient confusion problem — brand names in headlines do not always match the software logo on the clinic screen.
Canonical record and sources
Canonical BreachHistory page: 2026 Enel-Med (Poland) — company confirms confidentiality breach; systems secured.
Related catalog context: MyDr Poland ~19M and Qbusoft/Medyc clinic-confirmed breach.
Sources: Warsaw Business Journal — Data breach reported at Enel-Med Medical Center, CEO Magazine Poland — Enel-Med confirms data confidentiality breach.
Published 2026-09-27. Verified: Enel-Med confirmed September 24, 2026 IT security incident resulting in data confidentiality breach; systems and customer data secured; operations not materially affected; CBZC, e-Health CSIRT, CERT Polska, and UODO notified. Unpublished: data categories and affected-person census. Distinct from mydr-poland2026 and qbusoft-medyc2026.
Closing
Enel-Med’s September 24 confirmation is a verified confidentiality breach at a major Polish private healthcare network — systems secured, clinics still running, regulators and cyber services notified — without a public field list or headcount yet. Keep it separate from MyDr’s ~19 million case and from Qbusoft/Medyc. Ask which provider actually held your records, lock down PESEL where you can, and treat urgent “Enel-Med remediation” texts as hostile until you verify out of band.