The Polish authority announces an inspection following a new medical data breach affecting millions of people

The Polish Personal Data Protection Authority (UODO) has announced an inspection of the company Qbusoft following a medical data breach, and has decided to intensify its controls in the health sector.

A cyberattack targeting the Medyc software, developed by the company Qbusoft Sp. z o. o., may have exposed the health data of five million Polish citizens. The Central Bureau of Cybercrime is conducting an investigation into this cybersecurity incident. The president of the UODO, Mirosław Wróblewski, confirmed the opening of an inspection within the company. The Deputy Prime Minister and Minister of Digitization specified that security recommendations had been sent to medical software providers on 16 September 2026 and that the company Qbusoft had not yet notified the incident to CERT Polska or CSiRT CeZ, warning that consequences would be drawn from any violation of security procedures.

This decision comes in a context of multiple breaches, including a previous data leak in August 2026 concerning the MyDr software, which affected 19 million people. For this incident, the UODO had already received, as of 17 September, more than 50 complaints and more than 2,000 notifications from data controllers. Consequently, on 16 September, the president of the UODO decided to launch larger-scale controls on the processing of health data, with additional inspections planned until the end of 2026.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire