Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 17, 2026 · 7 min read

Poland Breach Exposes Medical Data on 19M People

On 12 August 2026, Poland's Ministry of Digital Affairs confirmed that attackers took more than 2 terabytes of patient data from MyDr, a medical records platform used by over 12,000 clinics. Prescriptions, diagnoses and PESEL national identity numbers were in the haul.

Poland's digital affairs minister called it "one of the largest incidents in Poland's history," and the arithmetic backs him up. On 12 August 2026, Krzysztof Gawkowski confirmed that attackers had taken more than 2 terabytes of patient data from MyDr, a medical records platform used by clinics across the country. The stolen set touches nearly 19 million people. Poland has about 36.5 million residents. Half a country's medical history now sits in someone else's hands.

Key Takeaways

  • Poland's Ministry of Digital Affairs confirmed on 12 August 2026 that attackers stole over 2 terabytes of data from MyDr, a records platform serving more than 12,000 medical facilities.
  • The compromised set covers historical data through April 2024 and may involve up to 19 million people, roughly half of Poland's population.
  • Stolen records reportedly include names, PESEL national identity numbers, phone numbers, email addresses, consultation notes, diagnoses and prescription histories.
  • Minister Krzysztof Gawkowski advised citizens to check bezpiecznedane.gov.pl and block their PESEL number through the mObywatel app, Poland's equivalent of a credit freeze.
  • Poland's Central Cybercrime Bureau (CBZC) is investigating, and officials have said there is no current indication of a foreign state actor.

What Happened to MyDr?

MyDr is a privately owned Polish company that sells electronic medical records software to doctors, clinics and other healthcare providers. According to Notes From Poland, the alleged perpetrators contacted the Polish security outlet Zaufana Trzecia Strona over the weekend of 8 August with samples. Public reporting followed on Monday. MyDr confirmed on Wednesday that it had been "the target of an external, deliberate criminal activity."

The company says it identified and removed the cause of the incident, added security measures, and has seen no evidence the data has been published. Access reached historical records held through April 2024, and officials have cautioned that not every MyDr customer or patient is necessarily in the stolen set.

Scale is what makes this one different. MyDr's platform serves over 12,000 facilities and handles roughly 3 million consultations and 2.7 million prescriptions each month. Gawkowski also ordered the replacement of digital certificates linking medical systems to P1, Poland's national e-health platform, as a precaution, The Record reported. Poland's health minister said P1 itself remained secure.

What Was in the Stolen Data?

The stolen records combine identity data with clinical detail, which is the worst possible pairing. Reporting from Poland's state news agency PAP and other outlets describes names, PESEL numbers, phone numbers, email addresses, appointment schedules, prescribed medications, consultation notes, disease information and documents patients handed to their doctors.

The PESEL is the piece that turns a medical leak into a financial one. It is Poland's permanent national identity number, used for banking, lending and government services, and it appears alongside the medical detail in the same records.

An empty medical clinic reception desk in the evening with stacks of paper patient files beside a desktop computer under cool window light

Why Are Medical Records Worse Than a Password Dump?

Because you cannot rotate a diagnosis. A leaked password is an inconvenience with a fifteen second fix. A leaked record showing that you filled a prescription for an antipsychotic, an HIV antiretroviral or a fertility drug in March 2024 is permanent, and it stays true and stays sensitive for the rest of your life.

That permanence is exactly why the GDPR places health data in Article 9's special category, alongside biometric data, religious belief and sexual orientation, and prohibits processing it absent specific conditions. Regulators treat it that way because the harm model is different: extortion, discrimination by employers or insurers, and social exposure, not just fraudulent charges you can dispute.

The second problem is credibility. A criminal who knows only your email address writes a generic lure. A criminal who knows your name, your PESEL, your pharmacy and the exact medication you were prescribed writes something you will believe.

What This Means for Your Inbox

Every large health data theft is followed by a wave of email that quotes it back to you. The pattern is consistent across the sector, and it defeats the standard advice. "Watch out for suspicious messages" assumes the message will look suspicious. When the sender can cite your medication name, your clinic and your national identity number, nothing about it looks off.

Expect three shapes. Fake clinic notices asking you to "confirm your details after a system migration." Fake insurance or reimbursement messages that use a real prescription as proof of legitimacy. And direct extortion, where a sender threatens to publish a diagnosis unless paid. Generative tooling has made the writing effortless. One analysis found AI now drafts 82% of phishing emails, and personalisation at this data volume is a scripting problem, not a writing one.

The practical rule is to invert your default. Treat any unexpected email referencing your health, your clinic or your prescriptions as hostile until proven otherwise, however accurate its contents are. Accuracy is now evidence of a breach, not evidence of authenticity. Verify by calling the clinic on a number you already have, never one supplied in the message, and never through an embedded link.

Who Answers for 19 Million Records?

Legally, the 12,000 medical facilities are almost certainly the controllers, and MyDr is almost certainly the processor. That distinction matters enormously here. Under GDPR Article 33, a controller must notify its supervisory authority within 72 hours of becoming aware of a personal data breach, and Article 34 requires notifying affected individuals when the risk to their rights is high. A processor's duty under Article 33(2) is to notify the controller without undue delay.

So a single vendor compromise creates thousands of parallel notification obligations, each sitting with a clinic that may have learned about the incident from the news. Poland's data protection authority, UODO, has signalled an inspection, and officials have warned of consequences if procedures were not followed. European health sector enforcement has historically focused on security measures under Article 32 and on notification failures rather than the intrusion itself, so the questions for each controller will be what due diligence it performed on MyDr and how quickly it moved once informed. No penalties have been announced, and any figure quoted at this stage is speculation.

The Vendor Is the Attack Surface Now

Here is the implication the coverage has mostly skipped. Attacking one records vendor compromises every clinic downstream simultaneously, at a cost no attacker could justify for a single practice. That asymmetry is why third party compromise has become the dominant route into health data rather than a footnote to it.

The comparison makes the point. A single Polish software vendor produced a breach covering nearly 19 million people, larger than the biggest single healthcare entity breach reported in the United States this year, and several times the scale of recent vendor incidents like the 3.8 million patient Unlimited Technology Systems breach or Amgen's third party cloud exposure. Clinics are not being outfought. They are being bypassed, because the software they all bought is a shared single point of failure that none of them individually controls. It echoes the pattern in France's DGFiP tax authority breach, where the state kept its own systems intact while data walked out through the layer around them.

What to Do Right Now

Polish residents should start at bezpiecznedane.gov.pl to check whether their data appears in the stolen set, then block their PESEL through the mObywatel app or gov.pl. Blocking is free, instant, reversible, and available at any hour. Since 1 June 2024, banks and notaries must check PESEL status before granting a loan or a large cash withdrawal, and a lender that ignores a block loses the right to collect on that debt. More than 4.5 million Poles had already blocked their numbers by August 2024, according to Notes From Poland.

Outside Poland, the equivalent move is a credit freeze with each national credit bureau. It is the same mechanism under a different name: stop the identity number from authorising new credit.

Then harden the account the follow on attacks will target. Enable phishing resistant multifactor authentication on your primary email, which in practice means a passkey or a hardware security key rather than SMS codes. CISA's guidance explains why the difference matters. Your inbox is the recovery channel for everything else you own, and it is the channel these attackers will use.

Looking Ahead

Two things are worth watching. The first is whether the data surfaces publicly. MyDr says it has seen no evidence of publication, but that status has historically been temporary once extortion negotiations stall. The second is whether UODO's inspection reaches past MyDr to the controllers, because a finding that clinics owed independent due diligence on their software vendor would reset procurement expectations across European healthcare far more than any single penalty would.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.