Posted

Poland faces massive medical data breach

Polish authorities have officially confirmed one of the largest personal data leaks in the country’s history. On 12 August 2026, Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski stated that a cyberattack on the systems of the company MyDr compromised the data of nearly 19 million people.

MyDr is one of Poland’s largest providers of software for electronic medical documentation (EDM). The company provides around 12,000 medical facilities (private practices, clinics and medical centres). Approximately 3 million visits and 2.7 million prescriptions pass through its systems every month. Since 2023, MyDr has been part of the DocPlanner group (owner of the ZnanyLekarz platform), although the systems of the two services are separate and do not exchange patient data.

The attack affected information accumulated roughly up to April 2024. The current operation of medical facilities, the issuing of prescriptions and access to healthcare services have not been disrupted. Central state e-health systems were also unaffected.

The volume of stolen data exceeds 2 terabytes. Hackers had previously claimed to possess 18,814,422 unique PESEL numbers. The stolen database contains names and surnames, dates of birth, PESEL numbers, phone numbers, prescription details, visit information, NFZ (National Health Fund) regions and other data related to medical care.

Gawkowski described the incident as “unprecedented and very large” in the field of Polish cyberspace security. An emergency meeting of the Joint Cybersecurity Operations Centre was held. The investigation involves the Central Bureau for Combating Cybercrime, the National Prosecutor’s Office, the Personal Data Protection Office (UODO), the Ministry of Health and the e-Health Centre.

Authorities emphasise that there are currently no indications of a state-sponsored (including foreign) origin of the attack. According to preliminary data, it was carried out by cybercriminals pursuing financial goals.

MyDr has confirmed the unauthorised access and is conducting an internal investigation with the involvement of external cybersecurity experts. The company’s systems have already been restored and are operating normally.

This is one of the largest cases of medical and personal data leakage in Poland. The authorities have promised to keep the public regularly informed about the progress of the investigation.