VYPR
breachPublished Aug 17, 2026· 1 source

Poland Probes MyDr Healthcare Software Breach Potentially Affecting 19 Million

Polish authorities are investigating a significant data breach at healthcare software provider MyDr, potentially exposing the personal and medical data of up to 19 million individuals and over 12,000 medical facilities.

Polish authorities are actively investigating a cyberattack that targeted MyDr, a critical healthcare software provider in the country. The breach, disclosed by the company last week, may have compromised the sensitive personal and medical data of an estimated 19 million people and affected more than 12,000 medical facilities that utilize MyDr's services.

MyDr, a privately-owned Polish company, supplies essential software to doctors, clinics, and other healthcare providers, playing a key role in the nation's digital health infrastructure. The company confirmed that "external, intentional criminal activity" led to the incident, and stated that they have since identified and removed the vulnerability's cause, implementing enhanced security measures. However, MyDr has not yet disclosed specific details regarding the exploited vulnerability or the exact methods used by the attackers to gain access.

According to Polish authorities, the hackers gained unauthorized access to historical data stored within MyDr systems up to April 2024. While the full scope is still under investigation, it is acknowledged that not all MyDr customers or their patients may have been impacted. Crucially, MyDr has reported finding no evidence to date that the compromised data has been published or made publicly available, offering a sliver of reassurance to affected individuals.

The affected MyDr software is integral to Poland's nationwide electronic health platform, P1, facilitating services such as electronic prescriptions and referrals. The company also provides tools for managing medical practices and electronic health records. In response to the breach, Polish Digital Affairs Minister Krzysztof Gawkowski announced that the country's e-Health Center would be replacing digital certificates used by medical systems to connect to P1 as a precautionary measure.

Gawkowski emphasized that these certificate replacements are not expected to disrupt patient services, including the issuance of electronic prescriptions and referrals. Health Minister Jolanta Sobierańska-Grenda further stated that the incident does not pose a threat to Poland's public healthcare systems, and that the P1 platform remains secure. MyDr has also assured users that its systems are operational and safe for continued use by healthcare professionals and patients.

Poland's Personal Data Protection Office is slated to conduct an inspection of MyDr, while national security agencies are working diligently to identify the perpetrators behind the attack. Minister Gawkowski indicated that MyDr could face legal consequences if the investigation reveals a failure to adhere to proper security procedures or adequately protect its systems.

While the attack has not been officially attributed to any specific threat actor, Polish cybersecurity publication Zaufana Trzecia Strona reported that individuals claiming responsibility had contacted them, providing evidence of the breach, including a screenshot containing information purportedly belonging to a notable Polish politician. Claims circulating in Polish cybersecurity media suggest that the stolen data could encompass names, dates of birth, identification numbers, prescription details, and other medical records, though these claims remain unverified.

This incident follows closely on the heels of another significant cyberattack disclosed earlier this month by Polish convenience store chain Żabka, which involved unauthorized access to internal systems via a third-party contractor's account. It remains unclear whether these two separate incidents are connected.

Synthesized by Vypr AI