
Cyberattack on MyDr exposes medical data of nearly 19 million Poles, triggering UODO inspection and liability fears for 12,000 clinics
A cyberattack on MyDr, a private platform used by 12,000 medical facilities across Poland, has potentially exposed the health data of nearly 19 million citizens, prompting a UODO inspection, a criminal investigation, and warnings that clinics themselves may face GDPR penalties.
The breach
On Wednesday, August 12, Poland's Ministry of Digitalization confirmed a cyberattack on MyDr, a private company supplying electronic medical records systems to approximately 12,000 medical facilities across the country. The compromised database potentially holds data on nearly 19 million patients and exceeds 2 terabytes of information. MyDr's platform processes 3 million medical visits monthly and issues 2.7 million prescriptions each month, according to the company's website. The stolen data likely originates from 2024 and earlier years and may not cover all MyDr clients or their patients, the firm stated.
- Patients potentially affected
- 19 million
- Monthly visits
- 3 million
- Monthly prescriptions
- 2.7 million
What data was exposed
The leaked information extends beyond basic identifiers such as names and PESEL numbers to include sensitive health data: prescription records, medication details, and medical visit histories. Prime Minister Donald Tusk and Minister of Digitalization Krzysztof Gawkowski both indicated that nothing suggests involvement of foreign intelligence services, and the data has not yet appeared for sale online. Lawyer Michał Czarnuch warned that stolen data can be sold on the darknet to entities building AI models, or used for blackmail against individuals and companies.
Today we are in a new reality, where defending digital security becomes as important as physical defense.
Investigation and regulatory response
The Warsaw Regional Prosecutor's Office is overseeing an investigation conducted by the Central Bureau for Combating Cybercrime. On August 13, the head of the Personal Data Protection Office (UODO) launched an inspection of MyDr to examine the company's technical and organizational safeguards, risk analysis methods, and whether security measures were regularly tested against evolving threats. The government's "Bezpieczne Dane" portal will allow citizens to check whether their data was stolen, but officials say it will take at least a week before the database is populated, as services need several days to collect information from all affected facilities.
- Ministry of Digitalization confirms cyberattack on MyDr; data of nearly 19 million patients potentially leaked
- UODO head launches inspection of MyDr's technical and organizational safeguards
- Services still collecting data from 12,000 affected facilities; Safe Data portal not yet populated
Liability concerns for clinics
Legal experts warn that the 12,000 clinics using MyDr may face penalties, as they served as data administrators. Professor Dominik Lubasz of the University of Łódź told Rzeczpospolita that delegating data processing to a provider does not transfer liability. Professor Grzegorz Sibiga of the Institute of Legal Sciences PAN identified the systemic problem as the concentration of vast amounts of sensitive data in a single private provider's system. Lawyer Maciej Gawroński of GP Partners noted that while data leaks occur frequently, actual misuse for financial fraud remains less common in practice.
- Govt/Minister failure
- 33 %
- Fears of digitalization
- 8 %
- Provider security gaps
- 6 %
- Consequence fears
- 6 %
- Company solely to blame
- 4 %
Medical networks assess exposure
Leading private medical networks are investigating their potential exposure. Medicover confirmed that several of its dental clinics used MyDr software and has initiated contact with the provider while conducting an internal analysis. Lux Med stated that preliminary findings indicate a limited scope of affected data, describing it as "disproportionately small" relative to the overall incident. PZU Zdrowie reported using its own system and was not affected. enel-med used MyDr for patient services within the National Health Fund framework.
Public reaction
An analysis by Res Futury identified five main online narratives surrounding the breach. Approximately 33% of commentary framed the incident as a failure of the government and Minister Gawkowski, while around 8% expressed concerns about further digitalization of public services. Roughly 20% of responses contained contempt or mockery, and about 18% expressed anger or outrage. Marcin Jaworski of the Bureau of the Financial Ombudsman cautioned that stolen data could enable more sophisticated social engineering attacks, as criminals armed with real patient details can more convincingly impersonate bank or government officials.


