New leak of medical data in Poland through the Medyc system
In Poland, a new cyber incident is being investigated, as a result of which unauthorized persons gained access to personal data of patients of the Medyc medical system. Among the compromised information are names, PESEL numbers, contact details, and possibly medical documentation.
The investigation is reported by TVP Info citing Deputy Prime Minister and Minister of Digital Affairs of Poland Krzysztof Gawkowski. The Central Bureau for Combating Cybercrime is conducting investigative actions regarding an incident related to Qbusoft, the developer company of the Medyc software.
Details of the attack were disclosed by one of the medical facilities in Inowrocław that used the system. According to the institution, on August 22-23, the attacker exploited an SQL injection vulnerability in Medyc and was able to download an encrypted database archive outside the provider's infrastructure. The incident itself was detected on the night of September 8-9.
In the case of this medical facility, the leak concerned patient data for the period from July 1, 2024 to August 23, 2026. The download of names and surnames, PESEL numbers, addresses, telephone numbers, and emails has been confirmed.
Some fields, including name, surname, and PESEL, were stored in encrypted form. However, the system provider recommended assuming that due to the specifics of the protection implementation, the attackers could relatively easily decrypt this data. The analysis also recorded access to tables with medical information. Qbusoft considers it highly probable that the attackers obtained part of the medical documentation, including treatment summaries.
After detecting the attack, the company fixed the vulnerability, restricted access rights to databases, forcibly changed passwords and technical secrets, and enhanced system monitoring. According to the medical facility, Qbusoft handed over materials to the police on September 9, and the next day notified the Polish Personal Data Protection Office.
At the same time, Gawkowski stated that the company did not notify CERT Polska or the cyber incident response team of the e-Health Centre about the incident. The minister warned that if violations of security procedures are established, appropriate measures may be applied to the private company.
The new incident occurred shortly after a large-scale August attack on another medical software provider - MyDr. Then Polish authorities reported that unauthorized access could have affected data of about 18.8 million people and over 12 thousand medical facilities. After that, the Personal Data Protection Office decided to expand cybersecurity checks in the healthcare sector.
Patients whose PESEL numbers were leaked are advised to block them through the state service mObywatel or in municipal institutions, and to be more careful with phone calls, SMS, and emails in which interlocutors may use stolen personal or medical information.
Sources: TVP Info, Odwykowo-Psychiatryczny Ośrodek Leczniczy w Inowrocławiu, UODO