Poland is investigating a major healthcare data breach involving MyDr, an electronic medical services provider whose systems contain information connected to millions of patients. Polish Digital Affairs Minister Krzysztof Gawkowski said data relating to as many as 19 million people may have been affected, describing the incident as exceptionally serious.

 

 

MyDr provides digital services used by patients and medical professionals, including tools connected to appointments, medical documentation and electronic prescriptions. Because the compromised environment handles healthcare information, the investigation is focused not only on ordinary identifying details but also on potentially sensitive medical records.

The company has confirmed that it suffered a cyberattack but has not yet established the final scope of the breach. MyDr said forensic work is continuing and that it cannot currently confirm exactly how much information was exposed or precisely which categories were accessed. According to the company’s preliminary information, the affected material is believed to come from 2024 or earlier and does not cover every patient or customer using its services.

That distinction is important because the figure approaching 19 million is currently an estimate discussed by Polish officials rather than a confirmed count of individuals whose complete medical records were stolen. Gawkowski said the incident involves a large collection of particularly sensitive information associated with people who received healthcare services.

MyDr’s own privacy documentation shows the type of sensitive environment involved. The company processes personal information in connection with its healthcare services and may exchange required information with Poland’s P1 electronic health platform. Its privacy policy also describes relationships with healthcare professionals and other service providers that process information necessary for MyDr’s operations.

Separate Polish media reports have provided more detail about what the attackers claim to possess. According to the supplied reporting, individuals claiming responsibility said they obtained approximately 2.5 terabytes of information concerning 18.8 million people. Those figures have not yet been confirmed by MyDr’s forensic investigation.

The alleged attackers reportedly attempted to demonstrate their access by providing journalists with information associated with a prominent Polish politician. The sample was said to contain a PESEL identification number, two telephone numbers and details of 25 prescriptions. This reported disclosure has increased concern that the compromised material may contain considerably more than basic contact information.

Polish authorities have not publicly attributed the intrusion to a specific hacking group. Gawkowski has also said investigators currently have no indication that the operation was politically motivated. According to the government’s assessment reported by Polish media, officials believe with a high degree of confidence that financially motivated cybercriminals are responsible rather than an actor conducting a political operation.

There is also an important difference between information being stolen and it being publicly released. Gawkowski said on August 13 that authorities had not found the affected database publicly available or offered for sale and that Polish services were monitoring for its appearance.

The government is preparing a way for individuals to determine whether their own information was included in the incident. Gawkowski said a separate announcement would explain how people could perform that check, meaning details of the verification process were not yet available at the time of the announcement.

For now, several crucial details remain unresolved: the confirmed number of affected individuals, the complete categories of compromised information, how the attackers entered MyDr’s systems, and whether the stolen database will ultimately be published or sold. MyDr says those answers depend on the forensic investigation that is still underway.

Leave a Reply