A medical record carries a different kind of weight from an ordinary digital file. Behind names, prescriptions and identification numbers are fragments of people's daily lives, collected over years as they move through hospitals, clinics and pharmacies.
That information has become the focus of investigations in Poland after a series of cyberattacks affecting healthcare companies and software providers. The national cybersecurity research institute NASK is examining incidents involving Enel-Med, Qbusoft and MyDr.
One of the most recent incidents involved private healthcare provider Enel-Med. The company said it detected an attack on September 24 and determined that some patient information had been accessed, potentially affecting about 3% of its patient database.
Enel-Med reported the incident to several relevant authorities, including Poland’s Central Bureau for Combating Cybercrime, CERT Polska, the e-Health Center’s incident response team and the Personal Data Protection Office. The company said its medical facilities continued operating normally.
A separate breach involving MyDr has attracted attention because the company supplies electronic medical-record software to more than 12,000 healthcare facilities. Polish authorities said unauthorized access to historical data could affect approximately 18.8 million people. The information involved included data concerning medicines and prescriptions.
Another incident targeted Qbusoft, whose Medyc software is used by doctors and healthcare facilities for patient registration, electronic prescriptions and medical records. Reports indicated that the breach may affect about five million people.
Qbusoft said the information involved included names, national identification numbers, home addresses, telephone numbers and email addresses. The company said there was no confirmation that medical records themselves had been stolen.
The incidents demonstrate why healthcare systems are particularly attractive targets for cybercriminals. Medical organizations hold large quantities of information that can remain valuable long after it has been collected, while healthcare services increasingly depend on interconnected digital systems.
Polish cybersecurity authorities have responded by issuing additional security recommendations to healthcare providers. The Personal Data Protection Office has also begun an inspection of MyDr and plans broader inspections of healthcare organizations to examine how patient information is protected.
For patients, the issue extends beyond the technical language of cybersecurity. A breach can turn an ordinary piece of personal information into something that must be monitored and protected long after the original incident has ended.
Poland’s healthcare system is therefore facing a challenge that sits between medicine and technology. Digital systems have made it easier to manage appointments, prescriptions and medical records, but the same interconnected infrastructure requires increasingly careful protection. The recent attacks have brought that responsibility into sharper focus as authorities investigate what happened and how similar incidents can be prevented.
Published by Banx Network. This article is part of the Banx decentralized media programme, powered by the BXE token on the XRP Ledger.





