INTELLIGENCE
ZERO|TOLERANCE
Intelligence Advisory
HIGH CORROBORATED

ChipSoft HiX Ransomware Vendor Says Data Theft Was Confined to Its Hosted Tier

Apr 8, 2026 · HiX 365 hosted tier · 11 hospital portals offline · 60+ DPA notifications · HIGH

Publication Date
2026-04-08
Category
Ransomware
Author
K. Ellabban
Organization
Zero|Tolerance Security Research

ChipSoft B.V. detected anomalies in its systems on April 7, 2026. The Amsterdam company builds HiX, the electronic patient record used by the majority of Dutch hospitals. security.nl put its market share at an estimated seventy percent; the M&I/Partners EPD-inventarisatie published January 15, 2026 puts it higher, at 76 percent of hospitals against Epic's 16 percent.

By the morning of April 8, Z-CERT, the computer emergency response team for the Dutch healthcare sector, had told care institutions the incident was a ransomware attack and advised hospitals to break their VPN connections to ChipSoft. ChipSoft's own website was offline. The company notified customers of an incident but did not itself call it ransomware.

Eleven hospitals took their patient portals offline, according to an inventory by NOS. ChipSoft's initial guidance to those hospitals was that patient data was in all likelihood not involved. That guidance did not hold. On April 15 NOS reported that a data leak could no longer be excluded. On April 16 ChipSoft confirmed that medical patient data had in fact been stolen. According to the company, the theft did not touch every HiX customer. It touched the ones who had moved to the vendor's hosted tier.

Executive Summary

KEY FACTS

  • WhatRansomware and data theft at the vendor of the electronic patient record system used by most Dutch hospitals
  • WhoChipSoft B.V., Amsterdam. HiX holds 70 to 76 percent of the Dutch hospital EHR market depending on source. Affected downstream parties include GP practices, rehabilitation clinics, forensic care institutions and the Rotterdam Eye Hospital
  • HowUndisclosed initial access into ChipSoft's hosted environment. Neither ChipSoft, Z-CERT nor the NCSC has published an entry vector
  • DataMedical treatment information, names and dates of birth belonging to patients of HiX 365 hosted-tier customers
  • ActorEmbargo claimed possession of 100 GB on a darkweb leak site. No formal technical attribution has been issued
  • Impact11 hospital patient portals offline, over 60 breach notifications to the Dutch DPA, approximately 6,000 forensic care clients affected at a single provider, ministerial intervention, roughly three weeks to full digital restoration
Incident Overview

WHAT HAPPENED

ChipSoft detected system anomalies on April 7, 2026. The company informed customers of an incident. It did not characterise it publicly as ransomware, and its corporate website was still offline the following morning.

Z-CERT supplied the characterisation ChipSoft would not. In a bulletin to care institutions on April 8, reported by NOS, Z-CERT confirmed ransomware and advised hospitals to sever VPN connectivity to ChipSoft immediately. Hospitals complied and went further, pulling patient-facing services offline as a precaution. Slingeland Ziekenhuis in Doetinchem, Diakonessenhuis in Utrecht, Rijnstate in Arnhem and Tergooi MC all published notices.

Tergooi disabled mijn.tergooi.nl along with its integrations to BeterDichtbij, Luscii, Sananet and Gezondheidsmeter, leaving patients unable to log in, view results, book or change appointments, or check in online. Tergooi also reported that the self-service check-in kiosks in the hospital had stopped working.

What did not happen matters as much as what did. Slingeland stated plainly: "De zorg voor onze patiënten gaat onverminderd door en patiëntendossiers blijven intern volledig toegankelijk" - care for our patients continues undiminished and patient records remain fully accessible internally. Rijnstate reported "Op dit moment ervaren wij geen verstoringen in ons systeem" - at this time we are experiencing no disruptions in our system. The portals went dark. The wards did not.

This was a patient-facing availability event and a confidentiality event, not a clinical continuity event, and the distinction should not be blurred.

The confidentiality picture then deteriorated in stages. ChipSoft's early message, relayed by Slingeland, was that "patiëntgegevens naar alle waarschijnlijkheid niet betrokken zijn bij het incident" - patient data was in all likelihood not involved. On April 15, NOS reported that sources inside and outside ChipSoft no longer excluded a data leak. On April 16, ChipSoft confirmed the theft outright. CEO Hans Mulder: "Na veertig jaar toewijding aan betrouwbare zorg-ICT doet het ons pijn dat deze situatie is ontstaan.

" After forty years of dedication to reliable healthcare ICT it pains us that this situation has arisen. This removal of data we cannot undo.

Downstream disclosures followed through late April. De Forensische Zorgspecialisten, operator of De Waag and the Van der Hoeven Kliniek, reported theft affecting approximately 6,000 forensic care clients, with a spokesperson describing the data as "persoonsgegevens zoals voor- en achternaam en geboortedatum" - personal data such as first and last name and date of birth. The Rotterdam Eye Hospital reported theft.

Huisartsenpunt, a GP cooperative running four practices in Limburg at Grathem, Heel, Ittervoort and Vlodrop, reported theft and told patients it was not yet clear which personal data was involved. ChipSoft set up a service line for affected patients and made specialised lawyers available to speak with them. Hospitals began restoring digital access in the final days of April, with Diakonessenhuis, Meander MC and Martini Ziekenhuis back online and data exchange resuming between OLVG Amsterdam and UMC Utrecht by April 30.

Analysis

TECHNICAL ANALYSIS: THE ARCHITECTURE SPLIT

The single most useful claim in this incident is a negative one. According to ChipSoft, not every HiX customer lost data. The company's spokesperson drew the line precisely: "Instellingen die de software van ChipSoft in eigen beheer uitvoeren of door derden laten beheren, zijn niet getroffen." Institutions that run ChipSoft's software under their own management, or have it managed by third parties, were not affected. The spokesperson confirmed that the affected parties were customers of the HiX 365 platform.

Same vendor. Same product family. Same codebase. Two deployment models, and only one of them lost patient data.

One caution belongs on that finding before anything is built on it. The claim is ChipSoft's own, made by its spokesperson about its own product on April 16, while the company was still describing its investigation as ongoing. It has not been independently verified by Z-CERT, the NCSC or the Autoriteit Persoonsgegevens. The same company's previous reassurance, that patient data was in all likelihood not involved, survived nine days before collapsing.

No self-hosted victim has surfaced and the architecture reasoning below holds on its own terms, but the negative is a vendor assertion rather than an established fact and should be read as one.

On that basis, this is not a story about a vulnerability in HiX. No CVE has been published, and there is no indication in any retrieved source that the software itself was the entry point. It is a story about where the data was sitting and who was responsible for the perimeter around it. Customers who kept HiX in their own data centres, or contracted a third party to run it, retained control of their own attack surface and their own blast radius. When ChipSoft's hosted environment was compromised, those customers had nothing in it to lose.

Customers who moved to HiX 365 had transferred operation of that perimeter to the vendor. The compromise of one vendor environment was therefore the compromise of all of them at once.

The architecture decision was the security outcome. Every self-hosted customer had, without necessarily framing it as a security control, retained an isolation boundary that the hosted customers had traded away for operational convenience. That trade is legitimate and often correct: most healthcare providers cannot staff a 24/7 security operations centre, and a competent vendor genuinely does run infrastructure better than a 200-bed hospital's four-person IT team. The point is not that hosted is wrong.

The point is that the trade converts many independent, uncorrelated risks into one shared, perfectly correlated one, and almost nobody prices that correlation when signing the contract.

Impact Assessment

SUPPLY CHAIN IMPACT ANALYSIS

Concentration is what turns a single vendor's bad week into a national event. At 76 percent of Dutch hospitals by the M&I/Partners count, ChipSoft is not one supplier among several. Z-CERT's containment advice illustrates the dependency directly: the recommended action was for hospitals to cut their VPN connections to ChipSoft, which is only a meaningful instruction because essentially every hospital has one.

The blast radius extended past hospitals into primary and specialist care. GP practices, rehabilitation clinics, forensic psychiatric institutions and a specialist eye hospital all appeared in the disclosure sequence. These are organisations with no meaningful relationship to one another, in different care sectors, under different governance, sharing nothing except a hosting provider. That is the defining signature of concentration risk: the correlation between victims is invisible on any org chart and only appears in the supplier register.

The Dutch state noticed. On April 21, 2026, in written answers to parliamentary questions, health minister Sterk said ChipSoft must take full responsibility as a supplier, and framed the broader issue in terms of digital autonomy, arguing that care providers must have insight into vulnerabilities and must make deliberate choices about dependence on dominant market parties.

The market context sharpens the point. On the same day, the Gerechtshof Arnhem-Leeuwarden ruled against ChipSoft in its challenge to UMCG's plan to extend its Epic electronic patient record to Treant and Ommelander Ziekenhuis Groningen without a fresh European tender. The appeals court found it significant that UMCG's 2015 procurement had already contemplated an EHR to which other hospitals could connect. UMCG said it was extremely pleased the court confirmed the regional collaboration could proceed. A separate civil case between ChipSoft and UMCG remains pending in Groningen.

A dominant vendor litigating to constrain a competitor's regional expansion, in the same month a compromise of its hosted platform hit customers across four care sectors, is the concentration problem stated twice in one week.

Attribution

THREAT ACTOR

No formal technical attribution has been issued by ChipSoft, Z-CERT or the NCSC, and no entry vector has been published.

A group operating under the name Embargo claimed responsibility. On or about April 20, 2026, described by NOS only as "begin deze week", it posted a message on a darkweb leak site claiming to hold 100 GB of ChipSoft data, accompanied by two countdown timers due to expire that week. Harm Teunis, security researcher at ESET, quoted by NOS, described the mechanism plainly: "Die klok is erop gericht om hun slachtoffers onder druk te zetten" - that clock is aimed at putting their victims under pressure.

The pattern is standard double extortion, encryption for disruption plus exfiltration for leverage.

The listing was subsequently withdrawn. ChipSoft confirmed at the time that negotiations with the criminals were under way, declining to say more: "Ter bescherming van de belangen van alle betrokkenen kunnen wij op dit moment geen verdere uitspraken doen" - to protect the interests of all involved we can make no further statements at this time. On April 28 ChipSoft announced that publication had been prevented and the stolen data destroyed: "Mede met ondersteuning van cybersecurity-experts is het ons gelukt om te voorkomen dat de gegevens gepubliceerd zijn.

" The company added that "onze cybersecurity-experts hebben bevestigd dat deze vernietiging op technisch juiste wijze heeft plaatsgevonden" - our cybersecurity experts have confirmed that this destruction took place in a technically correct manner.

ChipSoft has not disclosed whether it paid, has not explained how destruction was verified, and has not excluded the possibility that copies were retained. Teunis noted that withdrawal of a leak-site threat often follows payment, though it can also be a negotiating move. A criminal's assurance that it deleted its only leverage is not evidence, and no independent verification exists.

The LHV, the Dutch national GP association, issued balanced guidance on May 1. It relayed Z-CERT's assessment that publication of the data "inderdaad minder waarschijnlijk lijkt" - indeed appears less likely - and told GPs they may tell patients "dat het risico kleiner is", that the risk is smaller. In the same guidance it told practices not to say that everything is safe or that the risk has passed, warning that it cannot be excluded that something happened with the data earlier or that something will happen with it in future.

Impact Assessment

WHAT WAS EXPOSED

  • Medical treatment information. A single anonymous source told de Volkskrant, in reporting relayed by NOS, that the attackers were specifically looking for medical information about treatments. This is special category data under GDPR Article 9, and the claim rests on one unnamed source
  • Patient names, first and last, and dates of birth, per De Forensische Zorgspecialisten
  • The fact of association with forensic psychiatric care for approximately 6,000 clients of De Waag and the Van der Hoeven Kliniek. No source establishes that clinical content was taken from these institutions; the confirmed data classes are name and date of birth. The association alone is sensitive irrespective of clinical content, and carries stigma and legal consequence that no reissue can undo
  • Ophthalmology patient data from the Rotterdam Eye Hospital
  • GP practice patient data, including four Limburg practices under Huisartsenpunt
  • Rehabilitation clinic patient data

Data class matters here for a reason that outlives the incident. A password is revoked in seconds. A diagnosis is permanent. Facts about psychiatric treatment, forensic care and ophthalmic conditions cannot be rotated, reissued or invalidated, and their sensitivity does not decay on any schedule.

Root Cause Analysis

TECHNICAL FAILURE CHAIN

1
Undisclosed initial access to the vendor-hosted environment.

No entry vector has been published by ChipSoft, Z-CERT or the NCSC. This gap is material: every downstream customer is currently unable to determine whether the same technique would work against their own estate.

2
Custody concentration across unrelated tenants.

The compromise reached the data of unrelated customers across four distinct care sectors, spanning GP practices, rehabilitation clinics, forensic psychiatry and a specialist hospital. Whether those tenants were logically separated and the separation was defeated, or were co-located by design, is not publicly documented. What is established is that one intrusion reached all of them.

3
Concentration of custody at the vendor.

HiX 365 aggregated patient data from organisations with no operational relationship into one environment under one operator, making a single compromise sufficient to affect all of them.

4
Exfiltration was not prevented or detected before completion.

Embargo's claim of 100 GB indicates bulk egress from the hosted environment. ChipSoft's confirmation on April 16 came nine days after detection on April 7, indicating the theft was established through investigation rather than caught by egress controls in flight.

5
Incident communications outran the forensics.

ChipSoft told customers patient data was in all likelihood not involved. Hospitals repeated that to patients. It was wrong, and the correction took until April 16. Assurances issued before the evidence supports them are a control failure with real downstream cost: every organisation that relayed the early message had to retract it.

6
Detection dependency on the supplier.

Customers could not independently determine their own exposure and had to wait for ChipSoft to tell them. Hospitals' only available unilateral control was the blunt one Z-CERT recommended, cutting the VPN entirely.

Detection

INDICATORS OF COMPROMISE

No threat actor IOCs have been published. Neither ChipSoft, Z-CERT nor the NCSC has released hashes, C2 infrastructure, IP addresses, domains or a CVE, and no ransomware family has been named by any authority. Treat any IOC list circulating for this incident as unsourced.

TECHNICAL IDENTIFIERS ESTABLISHED BY REPORTING
  • Affected platformChipSoft HiX 365, the vendor-hosted deployment tier
  • Configuration ChipSoft states was unaffectedHiX under customer own management (eigen beheer) or third-party management
  • Containment control pointVPN connectivity from hospital networks to ChipSoft, which Z-CERT advised severing on April 8, 2026
  • Claimed exfiltration volume100 GB, asserted by Embargo on a darkweb leak site, not independently verified
  • Actor aliasEmbargo, self-claimed on leak site, on or about April 20, 2026
  • Extortion modeldouble extortion, encryption plus exfiltration, with two countdown timers used for pressure
  • Exposure timelinedetection April 7, 2026; ransomware confirmed by Z-CERT April 8; leak not excluded April 15; theft confirmed April 16; leak-site listing on or about April 20; listing withdrawn and destruction claimed April 28; broad restoration of hospital digital access by April 30
Compliance Impact

REGULATORY EXPOSURE

GDPR fine ceilings are tiered, and both tiers apply here to different obligations. Article 83(5)(a) covers the basic principles for processing pursuant to Articles 5, 6, 7 and 9, and carries up to 20 million euro or 4 percent of total worldwide annual turnover, whichever is higher. Article 83(4)(a) covers controller and processor obligations pursuant to Articles 8, 11, 25 to 39, 42 and 43, and carries up to 10 million euro or 2 percent. Articles 28, 32, 33 and 34 all sit in the lower tier, not the higher one.

Higher tier, up to 20 million euro or 4 percent of worldwide annual turnover, under Article 83(5)(a):

  • GDPR Article 9 - the stolen data includes health information and the fact of forensic psychiatric care association, special category data attracting the highest protection standard
  • GDPR Article 5(1)(f)integrity and confidentiality. Patient data held in the hosted tier was neither

Lower tier, up to 10 million euro or 2 percent of worldwide annual turnover, under Article 83(4)(a):

  • GDPR Article 32 - security of processing. Applies to ChipSoft directly as processor, not only to the care providers as controllers
  • GDPR Article 28 - controller obligations when engaging a processor. Every affected hospital, clinic and GP practice must be able to demonstrate it verified ChipSoft offered sufficient guarantees. Volume of customers is not a substitute for that assessment
  • GDPR Articles 33 and 34 - notification to the supervisory authority within 72 hours and to data subjects where risk is high. The Autoriteit Persoonsgegevens confirmed it received over sixty notifications connected to the hack, including one from ChipSoft itself

Civil liability rather than administrative fine:

  • GDPR Article 82 - compensation. Controllers and processors can be held jointly liable for the full damage, and a controller that pays can then recover from the processor. This runs through the courts, not the supervisory authority, and is uncapped by the Article 83 ceilings

National and sectoral:

  • Dutch UAVG - the national implementing act under which the Autoriteit Persoonsgegevens exercises its enforcement powers
  • Cyberbeveiligingswet (Cbw)the Dutch implementation of NIS2, passed by the Tweede Kamer on April 20, 2026 and expected to take effect in mid-2026. It applies to entities with more than 50 employees and annual turnover of 10 million euro or more, and holds directors responsible for approving and supervising security measures, with personal liability where there is gross negligence
  • Wet weerbaarheid kritieke entiteiten (Wwke)passed the same day, implementing the CER directive, with additional requirements for entities designated critical by the health minister

Note the timing. Dutch healthcare boards were handed personal liability for security oversight four days after ChipSoft confirmed a supplier compromise had exposed their patients' medical data. The next incident of this shape will be adjudicated under a materially different accountability regime.

Analytical Limitations

INTELLIGENCE GAPS

?
The initial access vector is unknown.

No phishing, credential, vulnerability or third-party route has been identified publicly. Until it is, no HiX 365 customer can assess whether the underlying weakness has been eliminated or merely contained.

?
The claim that self-managed customers were unaffected is unverified.

It originates with ChipSoft's spokesperson, concerns ChipSoft's own product, and was made while the investigation was still open. No regulator or CERT has confirmed it. It is the load-bearing negative in this analysis and it rests on a single interested party.

?
The total number of affected individuals is unknown.

Only fragments are public: approximately 6,000 forensic care clients at one provider, four GP practices in Limburg, the Rotterdam Eye Hospital, unspecified rehabilitation clinics. No aggregate figure has been published by ChipSoft or the Autoriteit Persoonsgegevens.

?
Whether a ransom was paid is unknown.

ChipSoft confirmed negotiations, then announced the data was destroyed, then declined to say whether money changed hands. NOS reported plainly that "het is niet bekend of ChipSoft de hackers heeft betaald."

?
The destruction claim is unverified.

ChipSoft says its cybersecurity experts confirmed technically correct destruction but has not explained the method, named the experts, or excluded retained copies. There is no mechanism by which a victim can verify that a criminal deleted data.

?
The 100 GB figure is an actor claim.

It comes from Embargo's leak-site post and has not been confirmed by ChipSoft or any investigator. Leak-site volume claims are routinely inflated.

?
Attribution is uncorroborated.

Embargo self-claimed. No investigating authority has confirmed the group's involvement or published technical evidence linking it to the intrusion.

?
The scope of stolen medical content is thinly sourced.

The only specific data classes confirmed by an affected institution are name and date of birth. The claim that attackers targeted treatment information traces to one anonymous source quoted by de Volkskrant.

?
No primary artifact documents the incident.

Every fact about the attack here rests on Dutch press reporting. No statement about the incident is discoverable on ChipSoft's public site: the homepage resolves and contains no reference to the attack, and the news index does not resolve to a usable page. The Z-CERT site returned HTTP 403 and could not be read. The Autoriteit Persoonsgegevens site resolves but publishes nothing case-specific, and its only public position is the statement it gave to NOS. The vendor at the centre of a national healthcare breach has published nothing findable under its own name, which is itself a finding: patients and customers were left to learn their exposure from journalists.

?
Regulatory outcome is pending.

The Autoriteit Persoonsgegevens has acknowledged receiving over sixty notifications but has not announced an investigation, findings or enforcement action.

Assessment

ZERO|TOLERANCE Advisory

1
Treat deployment model as a security control and record it as one.

On ChipSoft's account, the determining variable was not software version but who operated the environment. Add hosting model to the risk register for every clinical system, alongside an explicit statement of what the organisation loses the ability to detect when it moves to a vendor-hosted tier. Self-managed HiX customers appear to have come through this incident without data loss, and that outcome was produced by an architecture choice most organisations never evaluate as security.

2
Demand contractual isolation guarantees and evidence of them.

Require every hosted clinical supplier to document tenant separation architecture, provide the most recent penetration test against the multi-tenant boundary specifically, and commit to notification timelines with penalties. Under GDPR Article 28 the controller must verify sufficient guarantees before engaging a processor, and a supplier's market share is not a guarantee. In this case, market share was the risk.

3
Build the capability to determine your own exposure.

Affected hospitals had to wait nine days for their supplier to tell them whether their patients' data had been stolen, and are still relying on that supplier's word about who was spared. Negotiate contractual rights to your own tenant's audit logs, egress telemetry and alerting, delivered in a form your SOC can ingest, so exposure assessment does not depend on the compromised party's investigation timetable or its self-assessment.

4
Pre-authorise the containment decision.

Z-CERT's advice to sever VPN connectivity to ChipSoft worked because hospitals executed it within hours. Write the supplier-isolation runbook now: which connections get cut, who has authority to cut them at 03:00, which clinical workflows degrade, and what the manual fallback is. Slingeland's ability to state that records remained fully accessible internally while external connections were closed is the outcome this planning produces.

5
Do not communicate reassurance ahead of forensic evidence.

ChipSoft's early advice that patient data was in all likelihood not involved was repeated by hospitals to patients and was wrong. Adopt a standing rule that public statements describe only what has been confirmed and explicitly flag what remains under investigation. The LHV's guidance after this incident, which paired an honest acknowledgement that the risk had fallen with a refusal to say the risk was over, is the correct model.

6
Treat criminal deletion assurances as worthless for risk purposes.

Whatever ChipSoft's negotiation achieved, notify data subjects, maintain heightened phishing and social-engineering monitoring for affected populations, and brief patients on identity fraud indicators. A promise from an extortion group that it destroyed its own leverage does not reduce residual risk and does not satisfy Article 34.

7
Board-level owners should act on the Cyberbeveiligingswet now, not at commencement.

With NIS2 implemented in Dutch law and personal liability attaching to directors for gross negligence in approving and supervising security measures, supplier concentration in clinical systems becomes a documented board decision. Record the assessment, the alternatives considered, and the accepted residual risk, before the regime takes effect in mid-2026.

References

SOURCES

security.nl, "Ziekenhuizen halen patiëntportalen offline wegens ransomware-aanval op ChipSoft", April 8, 2026 - https://www.security.nl/posting/931627/ NOS, "Lekken van ziekenhuisdata toch niet uitgesloten bij Chipsoft-hack", April 15, 2026 - https://nos.nl/artikel/2610491-lekken-van-ziekenhuisdata-toch-niet-uitgesloten-bij-chipsoft-hack NOS, "Toch patiëntgegevens buitgemaakt bij hacken van softwarebedrijf Chipsoft", April 16, 2026 - https://nos.nl/artikel/2610742-toch-patientgegevens-buitgemaakt-bij-hacken-van-softwarebedrijf-chipsoft NOS, "Zorgorganisaties melden diefstal patiëntgegevens na Chipsoft-hack", April 17, 2026 - https://nos.nl/artikel/2610854-zorgorganisaties-melden-diefstal-patientgegevens-na-chipsoft-hack NOS, "Hackersgroep dreigde patiëntgegevens van ChipSoft te publiceren", April 23, 2026 - https://nos.nl/artikel/2611703-hackersgroep-dreigde-patientgegevens-van-chipsoft-te-publiceren NOS, "Chipsoft: alle gestolen data van ransomware-aanval vernietigd", April 28, 2026 - https://nos.nl/artikel/2612332-chipsoft-alle-gestolen-data-van-ransomware-aanval-vernietigd Skipr, "ChipSoft bevestigt: medische patiëntgegevens gestolen bij ransomware-aanval", April 16, 2026 - https://www.skipr.nl/nieuws/chipsoft-bevestigt-medische-patientgegevens-gestolen-bij-ransomware-aanval/ Skipr, "Tweede Kamer neemt cybersecuritywetten aan: extra eisen en persoonlijke aansprakelijkheid voor zorgbestuurders", April 20, 2026 - https://www.skipr.nl/nieuws/tweede-kamer-neemt-cybersecurity-wetten-aan-extra-eisen-en-persoonlijke-aansprakelijkheid-voor-zorgbestuurders/ Skipr, "Minister Sterk: ChipSoft moet volle verantwoordelijkheid nemen voor hack", April 21, 2026 - https://www.skipr.nl/nieuws/minister-sterk-chipsoft-moet-volle-verantwoordelijkheid-nemen-voor-hack/ Skipr, "Rechter veegt vorderingen ChipSoft tegen UMCG van tafel", April 21, 2026 - https://www.skipr.nl/nieuws/rechter-veegt-vorderingen-chipsoft-tegen-umcg-van-tafel/ Skipr, "Limburgse huisartsen melden diefstal patiëntgegevens via ChipSoft-systeem", April 22, 2026 - https://www.skipr.nl/nieuws/limburgse-huisartsen-melden-diefstal-patientgegevens-via-chipsoft-systeem/ Skipr, "ChipSoft: 'gehackte gegevens vernietigd'", April 28, 2026 - https://www.skipr.nl/nieuws/chipsoft-gehackte-gegevens-vernietigd/ Skipr, "Ziekenhuizen herstellen digitale toegang na cyberaanval ChipSoft", April 30, 2026 - https://www.skipr.nl/nieuws/ziekenhuizen-herstellen-digitale-toegang-na-cyberaanval-chipsoft/ Skipr, "LHV: blijf alert op misbruik persoonsgegevens na ChipSoft-hack", May 1, 2026 - https://www.skipr.nl/nieuws/lhv-blijf-alert-op-misbruik-persoonsgegevens-na-chipsoft-hack/ M&I/Partners, "EPD-inventarisatie ziekenhuizen 2026: tussen standaardisatie en innovatie", January 15, 2026 - https://mxi.nl/kennis/746/epd-landschap-2026-tussen-standaardisatie-en-innovatie Computable, "Nederlandse epd-markt is een triopolie", January 24, 2024 - https://www.computable.nl/2024/01/24/nederlandse-epd-markt-is-een-triopolie/ de Volkskrant, reporting on affected institutions and on data sought by the attackers, cited by NOS, April 2026