Data Breaches · Web App Attack

Medyc Breach Exposed Patient Identity Data

Qbusoft’s Medyc medical records and practice-management platform was breached in August after an attacker exploited an SQL injection flaw, and affected providers say patient personal data was taken. Medyc said the stolen data included names, national identification numbers, home addresses, phone numbers and email addresses.

The attack worked by feeding crafted input into Medyc’s web application interface and turning that path into database access. One provider said Qbusoft found evidence of scripts aimed at tables containing medical information, and Qbusoft told it to assume encrypted identifiers could be decrypted, so “encrypted in the database” did not mean safe here.

For clinics using Medyc, the exposure is not limited to a website incident: identity data can be enough for fraud even if clinical notes were never taken. What remains unsettled is how much medical record content left the system, but the patient-data breach already sits inside the trusted workflow that stores and serves it.

2 sources · 7h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-29

Every edition of this story: Medyc Breach Exposed Patient Identity Data

More from today