Decoding the world of cybersecurity

Polish health breach exposes millions of records

Polish authorities are investigating a major breach at healthcare software provider MyDr after roughly 19 million records linked to patients and more than 12,000 medical facilities were stolen.

Polish health breach exposes millions of records
Summary
  • Polish authorities say roughly 19 million records were stolen from healthcare software provider MyDr.
  • The incident potentially affects data associated with patients across more than 12,000 medical facilities.
  • Healthcare services continued operating, shifting the immediate risk towards confidentiality, identity fraud, regulatory scrutiny, and supplier accountability.

Poland is investigating one of its largest healthcare data breaches after attackers stole roughly 19 million records from MyDr, a software provider whose services are used by doctors and more than 12,000 medical facilities across the country.

Deputy prime minister and digital affairs minister Krzysztof Gawkowski said the compromised material amounted to around two terabytes of data. The stolen records contain different fragments of information linked to patients, while authorities and the company continue to establish exactly whose information was affected and which fields were exposed in individual cases.

The incident did not shut down the healthcare services supported by MyDr. Polish officials said systems had been secured and were operating normally, leaving the immediate consequences concentrated around stolen information rather than disruption to appointments, prescriptions or clinical operations.

That distinction limits the patient-safety impact but leaves a substantial confidentiality problem. Medical data can combine ordinary identity information with details that cannot be replaced after an incident. Names, contact details, national identifiers and medical information can retain value long after a breach has been contained, particularly when records can be correlated across other stolen datasets.

The Polish government has directed people towards its Bezpieczne Dane service, where affected breach information can be checked once supplied to the database. Authorities have also urged people whose PESEL national identification numbers are exposed to consider restricting their use through government services to reduce the potential for identity fraud.

Poland’s data protection authority, UODO, has separately said it will inspect MyDr. The regulatory response broadens the investigation beyond identifying the attacker towards questions about how the information was protected, how long it was retained, and the responsibilities of organisations that entrusted patient data to the supplier.

The number of medical facilities involved illustrates the concentration risk created by shared technology providers in healthcare. A compromise does not have to spread independently through thousands of clinics if a supplier already holds information on their behalf. Centralised software creates operational efficiency, but it can also turn one security failure into an incident with national reach.

Healthcare organisations face an especially difficult version of that dependency because availability and confidentiality have to be managed together. Strong continuity arrangements can keep consultations and prescribing running during a cyber incident, but resilience of the clinical service does not compensate for the loss of sensitive patient information.

The incident also lands as European organisations face more formal expectations around cyber governance, incident reporting and supplier management. Healthcare sits firmly within that environment, while personal data remains separately governed by the GDPR. A breach affecting a processor or technology supplier can therefore generate obligations and scrutiny across several organisations even when the original intrusion occurred outside their own infrastructure.

Investigators have not publicly established the complete intrusion path or provided a final count of individuals whose data was compromised. Nor should the roughly 19 million records be interpreted automatically as 19 million complete patient files: the government has described records containing different fragments of data that can potentially be linked.

The scale is nevertheless sufficient to make supplier governance part of the incident. Once a healthcare technology company accumulates information from thousands of practices, retention, segmentation, access control and oversight become national resilience questions rather than matters confined to one application provider.

×