English Section
Follow us on Google

Follow us on Google to get our latest news at the top of your search results

Poland probes cyberattacks after patient data leaks

30.09.2026 20:30
Poland's cybersecurity authorities are investigating three recent attacks on healthcare companies that exposed or may have exposed data belonging to millions of patients.
Pixabay License
Pixabay LicenseImage by Gerd Altmann from Pixabay

The Research and Academic Computer Network (NASK), Poland’s national cybersecurity research institute, is analyzing attacks on private healthcare provider Enel-Med and software companies Qbusoft and MyDr.

"The medical sector is particularly exposed to cybercriminal activity, mainly because of the sensitive data stored in service providers' systems," NASK spokeswoman Daria Tomczuk said.

The latest case involves Enel-Med, which said it identified a cyberattack on September 24. The attackers gained access to some patient data, potentially affecting about 3 percent of the company's patient database.

Enel-Med said the attack was quickly detected and stopped. Its medical facilities are operating normally, and patients can continue to book appointments through its app and call center.

The company reported the incident to the Central Bureau for Combating Cybercrime (CBZC), CERT Polska, the Computer Security Incident Response Team at the e-Health Center (CSIRT CeZ) and the Personal Data Protection Office (UODO).

Enel-Med is one of Poland's larger private healthcare providers. It operates 72 facilities directly and provides services through a network of almost 2,000 locations.

The largest of the three attacks involved MyDr, which supplies electronic medical-record software to more than 12,000 healthcare facilities.

The government said in August that unauthorized access to historical data held by MyDr could affect about 18.8 million people. The stolen information included data concerning medicines and prescriptions.

Police from the Central Bureau for Combating Cybercrime are investigating the MyDr breach under the supervision of the Warsaw District Prosecutor's Office.

Another recent attack targeted Qbusoft, the developer of Medyc, software used by doctors and healthcare facilities to register patients, issue electronic prescriptions and manage medical records.

Polish cybersecurity websites CyberDefence24 and Zaufana Trzecia Strona reported that the breach may affect about 5 million people.

Qbusoft said stolen information included names, PESEL personal identification numbers, home addresses, telephone numbers and email addresses. It said there was no confirmation that medical records had been stolen.

Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski said Qbusoft had failed to report the incident to CERT Polska or CSIRT CeZ, which he said should have been notified under Polish law.

Qbusoft said it reported the incident to the Personal Data Protection Office and police on September 9 and also informed the Central Bureau for Combating Cybercrime, NASK's incident response team, the e-Health Center and the Social Insurance Institution (ZUS).

Gawkowski said the growing number of attacks meant the healthcare sector needed to intensify its security measures.

Polish Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski. Polish Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski. Photo: Piotr Podlewski/Polskie Radio

Polish cybersecurity agencies issued additional security recommendations to healthcare providers in September.

The Personal Data Protection Office has begun an inspection of MyDr and plans wider inspections of healthcare organizations before the end of the year to examine how they protect patient data.

(rt/gs)

Source: IAR, PAP