Polish data protection authorities are investigating a significant cybersecurity incident at MyDr, a privately-owned software company supplying patient management systems to thousands of doctors, clinics, and healthcare providers across Poland. The breach potentially affects up to 19 million people — roughly half of Poland's total population.
MyDr stated it had identified and removed the cause of the breach and introduced additional security measures, but Polish regulators are not waiting for assurances.
What Happened
MyDr, whose software is widely used across the Polish healthcare system, confirmed late Friday that it detected unauthorized access to its systems. The company provides practice management software used by general practitioners, specialists, and clinics throughout Poland, meaning its systems hold sensitive patient records including names, contact information, medical history, and appointment data.
The company said it acted swiftly once the breach was identified, taking steps to contain the incident and notify relevant authorities. However, the scale of potential exposure — up to 19 million records — has alarmed the country's data protection watchdog.
Regulatory Response
Poland's Office for Personal Data Protection (UODO — Urząd Ochrony Danych Osobowych) has opened a formal investigation into the incident. Under the EU's General Data Protection Regulation (GDPR), organizations that process personal data — particularly sensitive health data — must notify supervisory authorities within 72 hours of becoming aware of a breach.
Healthcare data is classified as special category data under GDPR Article 9, requiring heightened protection. Breaches involving this category carry the heaviest potential fines — up to €20 million or 4% of global annual turnover, whichever is greater.
UODO has not yet determined the full scope of the breach or whether MyDr met its GDPR notification obligations.
What Data May Be Affected
While MyDr has not published a full list of compromised data types, healthcare software of this nature typically contains:
| Data Category | Sensitivity |
|---|---|
| Full name and date of birth | High |
| National identification number (PESEL) | Critical |
| Home address and contact details | High |
| Medical history and diagnoses | Critical |
| Prescription records | Critical |
| Appointment history | Medium |
| Health insurance details | High |
The PESEL number — Poland's universal personal identification number — is particularly sensitive as it is used across government services, banking, and healthcare. Exposure of PESEL numbers in combination with medical records creates significant risk of identity theft and medical fraud.
Scale of the Incident
With up to 19 million people potentially affected, this ranks among the largest healthcare data breaches in European history. For context:
- Poland's total population is approximately 38 million
- This breach would represent data for roughly 50% of the country
- It would dwarf most national healthcare breaches in the EU in recent years
The actual number of affected individuals may be lower once forensic analysis is complete, but the potential scale has prompted urgent action from regulators and healthcare providers.
MyDr's Response
In a statement, MyDr said it:
- Identified the unauthorized access and removed the cause
- Introduced additional security measures to prevent recurrence
- Notified the appropriate authorities as required under GDPR
- Is cooperating with the ongoing investigation
The company has not publicly disclosed the attack vector, whether data was exfiltrated (or only accessed), or which specific systems were compromised. Full transparency will likely be required by UODO as part of the investigation.
What Patients Should Do
If you are a patient of a Polish healthcare provider that uses MyDr software, consider the following precautions:
- Monitor for phishing: Expect targeted phishing attempts using your name, address, or healthcare details
- Review financial accounts: Watch for signs of identity theft, especially if your PESEL number was part of your record
- Be cautious of unsolicited medical communications: Scammers may use leaked health data to build convincing impersonation schemes
- Contact your healthcare provider: Ask directly whether their practice uses MyDr software and what their status is
- Check UODO notifications: The Polish data protection office will publish updates as the investigation progresses
Healthcare Sector Under Pressure
This breach is the latest in a growing wave of cyberattacks targeting healthcare organizations globally. The sector remains a prime target due to:
- The high market value of health records on criminal forums
- Legacy IT infrastructure common in clinical settings
- Concentrated data — a single software vendor breach can expose millions of records
- Regulatory and operational pressure that can force rapid settlements
Healthcare software providers have become a particularly attractive target since a breach at one vendor can cascade to hundreds or thousands of healthcare organizations simultaneously — a supply chain risk that regulators are increasingly scrutinizing.
What to Watch
- UODO findings: The investigation will determine whether MyDr violated GDPR obligations and may result in significant fines
- Patient notification: Affected individuals must be notified under GDPR Article 34 if the breach poses a high risk to their rights and freedoms
- Technical disclosure: What was the attack vector? Was data encrypted at rest? These questions will shape the regulatory outcome
- Civil litigation: In Poland and across the EU, affected individuals can pursue compensation for non-material harm under GDPR
Source: The Record