A hacker used one database flaw to steal national ID numbers.

Medyc runs records for many providers, exposing patients across Poland to one software flaw.

The breach began in August and went undetected until September 9, when Qbusoft found an encrypted archive missing.

Medyc has not confirmed medical records were taken, though an affected clinic calls it highly likely.

Poland’s digital affairs minister criticized Qbusoft for not reporting the breach sooner, as the cybercrime bureau investigates.

Sources: The Record