Skip to content
Back to Blog
7 min readdata-breachransomwarehealthcaresupply-chain

ChipSoft data breach: how one ransomware attack reached most of the Dutch hospital sector

On 7 April 2026, ransomware hit ChipSoft, the company behind the patient-record systems most Dutch hospitals run on. The group Embargo stole roughly 100 gigabytes, including medical data. One supplier compromise became a breach across most of the sector.

TL;DR

Healthcare software supplier ChipSoft was hit by ransomware on 7 April 2026, claimed by the group Embargo. Attackers stole roughly 100 gigabytes of data, including medical records, in a double extortion attack. Because ChipSoft serves the majority of Dutch hospitals, the breach cascaded to dozens of care organisations, from hospitals to forensic (TBS) clinics.

Incident Response PlaybookExpand
  1. Activate the incident response plan. Bring IT, security, legal, communications, and external responders together within the first hour.
  2. Isolate affected systems from the network. Disconnect, do not power off, so memory evidence survives.
  3. Identify the variant and its known tactics to guide containment.
  4. Run structured forensic evidence collection across endpoints, servers, and logs.
  5. Establish the initial access point and dwell time. The encryption is usually the last step of an intrusion that began weeks earlier.
  6. Confirm whether data left the building before encryption. Modern groups steal first, encrypt second.
  7. Notify legal counsel and insurer. Any contact with the attackers runs through specialist counsel.
  8. Notify law enforcement (politie cybercrime, and NCSC-NL where it applies).
  9. As a data processor, tell every downstream customer fast, so each controller can meet its own 72-hour notification duty.
  10. Where personal data is involved, support notification to the Autoriteit Persoonsgegevens (the Dutch data protection authority) within 72 hours.
  11. Restore only from backups you have confirmed the attacker never touched.
  12. Run a post-incident review covering segmentation, detection, and supplier dependency.

When the supplier is the single point of failure

The ChipSoft data breach is the clearest example this year of how a single supplier compromise can reach an entire sector. On 7 April 2026, the Dutch healthcare software company ChipSoft was hit by ransomware. ChipSoft builds the electronic patient record (EPD) systems used by most Dutch hospitals, so when its systems went down, the disruption spread far beyond one company. Hospitals pulled patient portals offline, severed connections, and waited for answers while the scope was still unknown. Within weeks it was confirmed that medical data had been stolen, turning an availability problem into a serious personal data breach across the care sector.

What happened

The first warning came from Z-Cert, the expertise centre for digital security in Dutch healthcare, which sent a confidential alert to care institutions. ChipSoft initially described a "data incident" with possible unauthorised access and would not immediately confirm ransomware. According to NOS, around 11 hospitals took their patient portals offline as a precaution, and UMC Utrecht temporarily cut its connection to ChipSoft.

By mid-April the picture had hardened. On 16 April ChipSoft confirmed a data breach and that medical data had been taken. On 23 April it became clear the data was genuinely exfiltrated, with the ransomware group Embargo threatening to publish it on the dark web and claiming roughly 100 gigabytes. On 28 April, as MAX Meldpunt reported, ChipSoft stated that the stolen data had been destroyed after the company negotiated with the attackers, with chief executive Hans Mulder acknowledging that the theft itself could not be undone.

How the attack worked

This was a double extortion ransomware attack, the now-standard model in which criminals steal data first and encrypt systems second, then threaten to leak the data if no ransom is paid. The group named is Embargo, a ransomware-as-a-service operation. Reporting indicates the intrusion did not begin at ChipSoft itself but reached it through the wider care supply chain before landing on the real target, which fits the pattern of attackers moving from a softer entry point toward a high-value central system.

What made the impact so wide is architectural rather than exotic. ChipSoft sits at the centre of the digital infrastructure of Dutch hospitals through its HiX platform, the patient portal, and connected services. When the supplier is compromised, every organisation that depends on it inherits the uncertainty, even where no attacker ever touched the hospital's own network.

Who is affected

ChipSoft supplies care systems to a large share of Dutch hospitals. NOS put the figure at roughly 70 percent of hospitals, which makes the company the market leader and a single point of failure for a big part of the sector. The fallout reached well beyond general hospitals: care organisations confirmed stolen patient data including forensic (TBS) clinics, rehabilitation clinics, and the Oogziekenhuis Rotterdam, according to NOS.

Several hospitals filed precautionary breach notifications with the Autoriteit Persoonsgegevens because they could not rule out that traffic passing through ChipSoft servers had been seen. Under the AVG (the Dutch implementation of the GDPR), ChipSoft acts as the processor and the hospitals as controllers, which means the legal duty to notify regulators and patients largely lands on the care organisations, not only on the supplier. The Autoriteit Persoonsgegevens confirmed it received multiple notifications and expected more.

What this means for your organisation

Three lessons stand out, and none of them is about ChipSoft specifically.

First, your supplier's breach is your breach. If a vendor processes personal data on your behalf, their incident triggers your notification clock. Map which suppliers hold or touch your sensitive data, and confirm in writing how fast they will tell you when something goes wrong.

Second, double extortion makes backups necessary but not sufficient. Clean backups get your systems running again, but they do nothing about stolen data already in criminal hands. A vendor saying the data was "destroyed" after a negotiation is not a control you can rely on, and as ChipSoft's own chief executive acknowledged, the theft cannot be reversed.

Third, the time between first signal and confirmed scope is where reputations are decided. Hospitals that had a clear plan for taking portals offline and notifying the regulator moved faster than those improvising under pressure. That difference is preparation, not luck.

If your organisation is dealing with an active ransomware incident or a supplier breach right now, SecDesk's incident response team works directly with Dutch organisations in crisis, from containment through regulator notification. You can reach the team at response.secdesk.com.

Talk to a senior responder about ChipSoft data breach: how one ransomware attack reached most of the Dutch hospital sector.

Schedule a response call
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now