Decoding the world of cybersecurity

Poland’s old health breach raises reporting questions

Prosecutors have confirmed a separate 2024 incident involving MyDr and Poland’s health-entitlement system, raising questions over why central cyber and data authorities apparently did not know about it.

Poland’s old health breach raises reporting questions
Summary
  • Poznań prosecutors confirmed an investigation opened in April 2024 after unauthorised queries accessed data relating to more than 13 million people.
  • The incident was separate from the current MyDr breach affecting nearly 19 million people.
  • Reporting indicates Poland's Digital Affairs Ministry and data protection authority were not notified, creating an incident-governance problem beyond the technical compromise.

Polish prosecutors have confirmed a separate 2024 incident involving healthcare platform MyDr and data belonging to more than 13 million people, deepening concern over how major cyber incidents move between healthcare organisations, law enforcement, data-protection authorities, and central government.

The Regional Prosecutor’s Office in Poznań opened an investigation on 8 April 2024 after receiving notification from Poland’s National Health Fund. Prosecutors say five people have faced charges in connection with the investigation.

The incident is distinct from the current MyDr breach affecting nearly 19 million people, which Polish authorities disclosed this month. The similarity in headline victim numbers initially created confusion over whether the two events were connected.

In the earlier case, prosecutors said an intruder compromised the network of a medical centre and inserted a script into MyDr that generated roughly 18 million automated queries to eWUŚ, the National Health Fund system used to verify a patient’s entitlement to publicly funded healthcare.

Prosecutors said the perpetrators obtained information relating to more than 13 million people through those queries. Reporting has also cited a document referring to more than 18.8 million sets of identifying information, making it important to distinguish the number of queries, records, and unique individuals rather than treating the figures as interchangeable.

The more consequential new question is what happened after the incident was detected. Brussels Signal, citing Polish reporting and official comments, says the Ministry of Digital Affairs was not informed about the breach or resulting investigation and that Poland’s data-protection authority, UODO, was also not notified.

Deputy Digital Affairs Minister Michał Gramatyka said this week that he had only just learned of the earlier incident. That statement does not establish why information failed to reach the ministry, nor whether another statutory or organisational reporting path was followed. The notification sequence requires further official clarification.

If the accounts are confirmed, the episode illustrates a failure mode that technical controls alone cannot resolve. A significant incident can be detected, investigated, and even produce criminal charges while still failing to create a complete picture at the government bodies responsible for national cyber policy, data protection, or systemic healthcare resilience.

Healthcare makes those boundaries particularly complicated. Private software providers, medical centres, the National Health Fund, prosecutors, regulators, national incident-response bodies, and government ministries may each hold only part of an event. Unless reporting responsibilities are explicit and information can cross organisational boundaries, an incident can remain legally active yet strategically invisible.

That has become more important under European cyber regulation. NIS2 is intended partly to improve incident reporting and situational awareness across important sectors, while healthcare organisations also operate under strict data-protection requirements where sensitive medical information is involved. Neither framework is useful if organisations cannot agree that an incident occurred, who must be told, and which authority owns the wider response.

The current MyDr attack makes the older case more than a historical footnote. MyDr is used by thousands of medical facilities, and the latest investigation involves a much larger collection of patient information including medical records and prescription details. Understanding the 2024 incident could therefore reveal whether earlier warning signs, architectural weaknesses, or governance problems had already been identified.

There is currently no evidence that the two attacks were conducted by the same people or used the same method. The confirmed technical descriptions differ, and Polish reporting has treated them as separate events.

The next issue for authorities is consequently not whether Poland suffered the same breach twice. It is why an incident affecting data on millions of people could become the subject of a criminal investigation without apparently becoming common knowledge across the institutions responsible for the country’s cyber and data-governance system.

×