← Blog

Qbusoft Medyc Breach: Poland Clinic Confirms PESEL Leak

Share on X

Weeks after Poland’s MyDr electronic-records disaster, a second healthcare software vendor is in the headlines — and this time a named clinic has already said patient confidentiality was breached. The Rehabilitation and Psychiatric Treatment Center in Inowrocław confirmed that a cyberattack on Qbusoft’s Medyc platform exposed patients’ personal data, which may include contact details and national identification numbers (PESEL). Digital Affairs Minister Krzysztof Gawkowski said Poland’s Central Bureau for Combating Cybercrime (CBZC) is examining the incident as part of a broader investigation.

That is the verified core. What is not verified is the underground “fingerprint” marketing that floated figures around 5 million people and 8 million private images. Treat those actor tallies as unverified claims until a facility, Qbusoft, UODO, or CBZC publishes an attested census. BreachHistory’s canonical page is qbusoft-medyc2026.

Also important: this is a separate incident from the August MyDr breach that ministers tied to roughly 19 million records. Same country, same PESEL risk model, different vendor. Mixing the two stories helps scammers and confuses patients.

What happened: the Qbusoft Medyc timeline

English-language coverage from TVP World and Anadolu Agency on September 25, 2026 framed the story as Poland’s second medical-data cyberattack in weeks. Both cite the Inowrocław Rehabilitation and Psychiatric Treatment Center’s Thursday notice that an attack on Medyc-backed systems breached the confidentiality of patients’ personal data.

Polish trade and security reporting — summarized in BreachHistory’s catalog writeup and echoed in outlets such as Gazeta.pl — places the intrusion window around August 22–23, 2026, with discovery in early September (roughly September 8–9 for the vendor side). That multi-week gap between access and public clinic acknowledgment is classic for healthcare SaaS incidents: forensics first, controller notices later, national headlines last.

Minister Gawkowski’s public comments matter for two reasons. First, they move the story from a single-facility privacy notice into a national cybersecurity probe under CBZC. Second, he said the government had already issued new security recommendations to companies that supply software to the healthcare sector — a direct policy reaction to the MyDr wave, now applied again to Medyc. His warning was blunt: if a private vendor breaches security procedures, “strict consequences will be imposed.”

What remains unpublished at indexing time is a nationwide headcount. The Inowrocław center did not say how many of its patients were in scope. Qbusoft had not, in the English sources reviewed, released a total Medyc customer census for this event. That is why the catalog row uses recordsAffected 0 for the official count while still marking the confidentiality breach as company-/facility-confirmed.

What was exposed — and what was only claimed

Start with the facility language. The Inowrocław center said confidentiality of patients’ personal data was breached and that this may have included contact details and national identification numbers. In Poland that national ID is PESEL. Polish coverage has also discussed health-status information in the same incident context; treat clinical-field inventory as still being clarified, not as a finished HHS-style field list.

Now the unverified layer. Actor “fingerprint” material circulating in Polish channels claimed on the order of 5 million people and roughly 8 million private images. Those numbers are useful for phishing forecasts and board briefings only if you keep the label: unverified. They are not a Qbusoft attestation, not a CBZC census, and not interchangeable with MyDr’s minister-confirmed ~19 million figure.

Why PESEL exposure hurts even when the official count is still “unknown”:

  • PESEL is permanent and reused across banking, telecom KYC, e-government, and healthcare
  • Contact data (phone, email, address) lets criminals personalize clinic and NFZ-themed lures
  • Psychiatric and rehabilitation context — if health-status fields were in scope — raises blackmail and stigma risk beyond ordinary credit fraud
  • Patients often never see the Qbusoft or Medyc brand; they see the clinic door, so vendor headlines arrive as a surprise

What this is not, based on verified sources: a published proof that every Medyc tenancy in Poland was emptied, a confirmed dump of 5 million clinical charts, or a government statement that 8 million images left the environment. Verified = confidentiality breach for patient PII at least at the reporting Inowrocław facility, with CBZC looking into a potential cybersecurity incident involving the Medyc stack.

How the attack is described

Open English reporting does not include a finished CERT Polska forensic package. Industry and Polish press accounts have described a possible SQL injection path into Medyc-related systems. Treat that technical path as reported trade-press detail, not as a Department of Defense-style attestation or a vendor post-mortem. Until Qbusoft or CBZC publish an official root-cause note, the honest summary is: unauthorized access to a healthcare software environment used to manage patient records, discovered weeks after the suspected intrusion window.

Unknowns that still matter for patients and clinics:

  • Which Medyc customers besides Inowrocław are confirmed in scope
  • Whether data was only accessed, or also copied and retained offline
  • Whether imaging files are part of any confirmed set (actor claim: yes; facility notice: not that specific)
  • Whether UODO notifications and patient letters will arrive facility-by-facility
  • Whether the actor corpus, if real, will be sold, leaked, or used quietly for fraud

That ambiguity is exactly why PESEL phishing will spike regardless of the final census. Criminals do not wait for Qbusoft’s PDF to finish legal review.

Distinct from MyDr — do not merge the incidents

August’s MyDr Poland breach is the scale story: Digital Affairs Minister Gawkowski said the company itself confirmed about 19 million records stolen, totaling more than 2 terabytes, with prescriptions, appointments, medications, and doctor-presented documents among the categories described. Roughly 12,000 medical facilities were in the notification wave for that vendor.

Qbusoft Medyc is the follow-on story: a different software provider, a named rehabilitation and psychiatric center confirming a confidentiality breach, CBZC investigating again, and no minister-attested multi-million census yet. Searchers typing “Poland medical data breach 2026” will hit both. Accurate copy should name the vendor. Clinic letters should name the vendor. Patients asking “was I affected” need to know which EMR their facility actually runs.

If your clinic used MyDr, follow the MyDr guidance and mObywatel PESEL steps from that incident. If your clinic used Medyc / Qbusoft, this page is the correct map. If you do not know, ask the facility — do not trust a SMS that claims to know for you.

Who is at risk after the Medyc confidentiality breach

Patients of the Inowrocław Rehabilitation and Psychiatric Treatment Center

They are the first verified risk group. The center’s own notice is the attestation. Contact data and PESEL may be in play. People treated for psychiatric or rehabilitation needs face a sharper privacy harm model than a typical outpatient PESEL leak: stigma, employment risk, and coercion attempts that cite real visit context.

Patients of other Medyc-using facilities

Until Qbusoft or controllers publish a scoped customer list, other Medyc clinics should assume they may need to investigate and notify. Absence of a letter this week is not proof of safety. Processor incidents in European healthcare usually surface as staggered controller notices, not one national SMS blast.

Clinic operators and medical staff

Under GDPR, facilities remain controllers even when Qbusoft is the processor. Controllers need timelines: when they learned of the incident, what Qbusoft told them, what fields may be involved, and when patient notices go out. Front-desk staff need scripts now for patients who already read TVP World or Polish tabloids.

Banks, telecoms, and e-government desks

Secondary institutions will see PESEL-backed social engineering whether or not they ever heard of Medyc. Fraud teams should treat late September 2026 as another elevated-risk window for Polish identity proofs.

People who only saw the 5 million claim

If you are panicking because a social post said “5 million Poles,” pause. That figure is an unverified actor claim. Still take PESEL hygiene seriously — but do not treat the fingerprint marketing as a confirmed national census.

What Gawkowski, CBZC, and the clinic have said

The Inowrocław center’s Thursday statement is the patient-facing confirmation: confidentiality breached; contact details and national IDs may be included. Anadolu Agency’s English writeup stresses that the center did not specify how many patients were involved.

Minister Gawkowski said CBZC is looking into the “potential cybersecurity incident” as part of a broader investigation, and that new security recommendations have already gone out to healthcare-software suppliers after the recent attack series. Polish reporting around the minister’s comments also described friction over how quickly and completely the vendor notified services — another reason controllers should document their own clocks carefully for UODO.

At indexing, BreachHistory treats the facility notice plus ministerial/CBZC acknowledgment as enough to mark the confidentiality breach verified for catalog purposes, while keeping actor scale claims labeled unverified and the official recordsAffected at 0 until an attested count exists.

Industry context: Poland’s health-IT concentration problem

Europe’s 2026 healthcare breach wave keeps hitting the software layer between clinics and national e-health rails — EMR SaaS, billing platforms, prescription gateways — rather than a single hospital’s on-prem EHR. France’s Cegedim Santé administrative-dossier incident, U.S. RCM breaches, and Poland’s MyDr case all show the same pattern: compromise one widely deployed vendor and the patient census jumps overnight.

Poland’s PESEL-centric identity stack raises the stakes relative to jurisdictions where medical record numbers stay local to a provider. A stolen PESEL is reusable across sectors. That is why a Medyc confidentiality breach is not “just another clinic IT ticket.” Banks and mObywatel workflows inherit residual risk even when the forensic report is still incomplete.

Related BreachHistory reading for boards writing comparison slides: the MyDr Poland post on this site, plus other 2026 health-vendor rows such as Amgen, Xsolis, and Baylor Genetics. Different countries, same lesson: processor opacity leaves patients searching the wrong brand name.

Was I affected? How to think about Medyc exposure

There is no public “search your PESEL in the Medyc dump” portal from Qbusoft at indexing time. Practical triage:

  1. If you were a patient of the Inowrocław Rehabilitation and Psychiatric Treatment Center during the relevant window, treat contact data and PESEL as potentially exposed based on the center’s own notice.
  2. If another Polish clinic treated you and uses Medyc, ask that clinic whether it has received a processor notification about this Qbusoft incident.
  3. If your clinic used MyDr, not Medyc, follow the separate MyDr guidance — do not assume one notice covers both.
  4. If a stranger already texts you with your clinic’s name and partial PESEL digits, elevate risk whether or not your formal letter has arrived.

Waiting passively for a postcard is a weak strategy when PESEL plus phone number is enough to open loans, SIM-swap narratives, and fake e-recepta portals.

What you should do

  1. Ask your facility which EMR it runs. Get “Medyc / Qbusoft,” “MyDr,” or another name in writing if you can. Action items differ by vendor.
  2. Reserve or restrict PESEL through official government channels such as mObywatel if you use that service. It will not erase leaked copies, but it can blunt some new-contract and credit fraud.
  3. Ignore unexpected “Medyc / Qbusoft / Inowrocław / NFZ / e-recepta” messages that ask you to confirm PESEL, click a remediation link, or install an app. Call the clinic on a number from your last visit letter.
  4. Watch bank and telecom accounts for new loans, KYC resets, or SIM-swap attempts that cite your PESEL.
  5. Enable MFA on email and any patient portals; change reused passwords. Email takeover turns a contact leak into full account recovery fraud.
  6. Psychiatric and rehab patients: tell a trusted clinician or advocate if you receive blackmail-style messages that reference treatment. Do not pay; preserve evidence for police / CBZC channels.
  7. Keep written records of clinic notice dates for insurers, employers, or a later UODO complaint.
  8. Clinics using Medyc: inventory processing agreements, freeze unnecessary exports, brief front-desk staff, and coordinate counsel on patient-notification timing. Document when Qbusoft informed you.
  9. Clinic IT: rotate Medyc admin credentials, review SQL/WAF logs around late August, and assume helpdesk social engineering will cite this headline.
  10. Parents and caregivers: children’s PESEL numbers in family clinic files deserve the same caution as adult IDs.

Phishing and secondary fraud to expect

When a second Polish healthcare software breach hits national media, call centers do not wait for Qbusoft’s final census. Expect:

  • SMS claiming your PESEL must be “re-verified” after the Medyc cyberattack
  • Emails with clinic logos asking you to download a “secure results viewer” or “CBZC evidence pack”
  • Voice calls that mix a real facility name with PESEL last digits the caller already knows
  • Fake minister / Digital Affairs messages urging immediate password resets via a lookalike domain
  • Lures that deliberately confuse Medyc with MyDr so victims reuse panic from the 19-million headline

The tell is urgency plus a request for secrets a real clinic already holds or should never ask for over SMS. Hang up. Redial from a known number. Real CBZC investigators do not demand PESEL confirmation through a random link in your texts.

Regulator and insurer angles

UODO scrutiny is predictable once controllers confirm patient data left a processor environment. Clinics should preserve: processor notices, forensic summaries they received, patient-communication drafts, and decisions about whether health-status fields were in scope. Insurers writing cyber policies for Polish medical practices will ask the same questions months later.

Gawkowski’s “strict consequences” line is a political warning to vendors that treat incident reporting as optional. Boards that equated “we buy certified EMR software” with residual-risk zero are learning again: certification is not containment.

For journalists and researchers, stick to primary contours — the Inowrocław notice, TVP World / Anadolu Agency English summaries, minister/CBZC comments, and any later UODO or CERT Polska advisories — rather than social posts that inflate the unverified 5 million claim into “all of Poland’s psychiatric records leaked” without evidence. Precision protects patients: overstating what is confirmed makes real notices harder to trust when they finally arrive.

How this compares to related healthcare breaches

Compared with MyDr, Qbusoft Medyc is earlier in the public census phase and smaller in attested scale — a facility-confirmed confidentiality breach plus government investigation language, not a minister-quoted ~19 million company confirmation. Compared with pure unverified leak-site marketing, it is stronger: a named clinic said patient confidentiality was breached.

Compared with U.S. HHS OCR mega-filings that publish tidy headcounts, European processor incidents often look messier for months — which lengthens the phishing window for anyone whose PESEL and phone may already be in criminal hands. Searching only “my clinic breach” may miss the Qbusoft Medyc story until your facility names the vendor.

Canonical record and sources

Canonical BreachHistory page: 2026 Qbusoft/Medyc (Poland) — clinic confirms patient PII breach; CBZC investigating.

Related catalog context: MyDr Poland ~19M.

Sources: TVP World — Fresh cyberattack targets Polish healthcare software provider, Anadolu Agency — 2nd cyberattack in weeks targets Polish healthcare data.

Published 2026-09-26. Verified: Inowrocław facility confidentiality breach + ministerial/CBZC investigation acknowledgment. Unverified: actor fingerprint claims of ~5M people / ~8M images. Official nationwide census unpublished. Distinct from mydr-poland2026.

Closing

Qbusoft Medyc is Poland’s second major healthcare-software shock in weeks: an Inowrocław clinic confirmed patient PII confidentiality may include contact details and PESEL, while Gawkowski says CBZC is investigating. Actor claims of millions of people and images remain unverified. Keep MyDr’s ~19 million case separate. Ask which system your clinic runs, lock down PESEL where you can, and treat urgent “Medyc remediation” texts as hostile until you verify out of band.