Security News

SQL Injection Attack on Polish Medical Software Provider Exposes Patient Data

The Record · 28 Sept 2026
Key Takeaway SMBs using third-party medical or customer management software should confirm their vendor regularly tests for SQL injection and other common web vulnerabilities, and should ask what encryption and monitoring protections are in place for stored personal data.

Qbusoft, developer of the Medyc medical records and practice management platform used in Poland, was breached in August after an attacker exploited an SQL injection vulnerability, a flaw that tricks a website into revealing database contents it should protect. The company confirmed that names, national identification numbers, home addresses, phone numbers and email addresses were stolen. While Qbusoft has not confirmed theft of medical records, one affected healthcare provider said it was told that attackers ran scripts against database tables containing medical information, making it likely that clinical data was also taken.

The Addiction and Psychiatric Treatment Center in Inowrocław confirmed that patients treated at its day unit between July 2024 and August 2026 may have had records exposed, including hospital treatment records and discharge summaries. Some identifying data such as names and national ID numbers had been encrypted, but Qbusoft warned the attackers could likely decrypt it. The intrusion was detected on September 9, and Qbusoft has since patched the vulnerability, restricted database permissions, rotated credentials, and added monitoring. Medyc says its systems have faced repeated attack attempts since, and some services may be intermittently unavailable.

This incident adds to a string of cyberattacks targeting Poland's healthcare sector in recent months, underscoring how attractive medical software providers are as targets due to the sensitive personal and clinical data they hold.

healthcare data breach SQL injection Poland patient data

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.