ChipSoft ransomware attack disrupts Dutch hospital software supplier
Dutch electronic patient record vendor ChipSoft, whose software is used by around 80% of hospitals in the Netherlands, was hit by ransomware, prompting hospitals to disconnect from its systems and later confirming that patient data was stolen from its cloud-hosted HiX 365 platform.
- Victim
- ChipSoft
On 7 April 2026, ChipSoft, the Dutch company whose electronic patient record software (HiX) is used by around 80% of hospitals in the Netherlands, was hit by a ransomware attack. Z-CERT, the national computer emergency response team for the healthcare sector, confirmed it had been notified of the incident that day. Parts of ChipSoft's infrastructure, including its public website, were knocked offline.
Z-CERT advised healthcare institutions to disconnect from ChipSoft's systems, check their networks for suspicious traffic and report anything unusual. At least eleven hospitals took their patient portals offline as a precaution, although most hospitals using ChipSoft software kept working.
Patient data stolen
ChipSoft initially told clients that personal data was "probably" safe. It later confirmed that patient medical information had been stolen from its cloud-hosted HiX 365 platform. Those affected were customers of the hosted service, including dozens of family doctors' practices (with the largest concentration in North Limburg), rehabilitation clinics and the Rotterdam Eye Hospital. Hospitals running ChipSoft software on their own servers were not affected. The Dutch data protection authority received dozens of breach reports from affected organisations. No ransomware group had publicly claimed the attack at the time of reporting, and ChipSoft did not say whether it was in contact with the attackers.
Why it matters
Because a single vendor underpins patient records for most Dutch hospitals, the attack showed how a breach at one software supplier can force a sector-wide defensive response. The Dutch Patients' Federation criticised the lack of timely information for patients whose sensitive treatment data was exposed. The incident followed other attacks on European healthcare providers, including the January 2026 attack on Belgian hospital network AZ Monica.
Timeline
Z-CERT, the Dutch healthcare CERT, is notified that ChipSoft has fallen victim to a ransomware attack; the company's website goes offline and hospitals are advised to disconnect and monitor their networks.
At least eleven hospitals take their patient portals offline as a precaution.
ChipSoft confirms that patient data was stolen from its cloud-hosted HiX 365 platform, after initially telling clients personal data was probably safe.
Sources
- theregister.comhttps://www.theregister.com/security/2026/04/08/ransomware-knocks-dutch-healthcare-software-vendor-offline/5220887
- dutchnews.nlhttps://www.dutchnews.nl/2026/04/patient-medical-data-stolen-in-chipsoft-ransomware-attack/