Polish authorities are investigating another breach of medical data, this one traced to a small software house that supplies practice-management tools to clinics.
The vendor, Qbusoft of Olsztyn, builds the Medyc system. Attackers reached an encrypted database archive, and one customer has already gone public: the Addiction Treatment and Psychiatric Centre in Inowroclaw, which said records tied to its day-treatment unit were exposed, spanning July 2024 through August 2026.
The incident follows a far larger hit weeks earlier on MyDr, another medical software provider, that left records for roughly 19 million Poles exposed. Reports put the potential reach of the new attack at up to five million people, though the final figure is not settled.
Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski has responded to the reports, and the same intruder is suspected in both campaigns. Regulators have fielded hundreds of breach reports since the first incident.
The pattern is familiar to US healthcare defenders: a single small vendor holding records for thousands of providers becomes a force multiplier for attackers. Poland’s experience shows how one compromised supplier can push notification duties onto hundreds of clinics at once, and why vendor risk programs need depth beyond the biggest platforms.