MyDr, a privately-owned Polish company that supplies software to doctors, clinics and healthcare providers, was breached. The data taken covers nearly 19 million people — roughly half of Poland’s population — across more than 12,000 medical facilities.
The stolen database exceeds 2 terabytes. It contains names, dates of birth, identification numbers, prescription records, appointment histories, registered medicines and documents provided to doctors, covering historical data held in MyDr systems through April 2024.
The attackers demonstrated the breach by contacting Polish cybersecurity media with sample records belonging to a prominent Polish politician: his PESEL number — Poland’s national identification number — his phone numbers, and 25 of his prescriptions.
MyDr says it has identified and removed the cause of the incident, introduced additional security measures, and found no evidence that the stolen data has been publicly released. It has not disclosed the vulnerability or the attack vector.
The P1 Question
The detail that determined Poland’s government response is what MyDr connects to.
P1 is Poland’s nationwide electronic health system — the national infrastructure that handles e-prescriptions, e-referrals and medical records for the entire country. MyDr’s platform is one of the software layers that connects individual providers to it.
Health Minister Jolanta Sobierańska-Grenda stated that P1 itself remained secure. Digital Affairs Minister Krzysztof Gawkowski nonetheless ordered the replacement of digital certificates used by medical systems connecting to P1, as a precaution.
That combination — the national system is fine, but rotate every certificate that touches it — is the correct read of the risk, and it is the same structural exposure we have written about repeatedly in healthcare. The national platform was not compromised. A private vendor sitting between thousands of providers and the national platform was, and that vendor held enough credential material to make the government treat the trust boundary as suspect.
Poland’s Personal Data Protection Office (UODO) has planned inspections. Security agencies opened an investigation, and officials say with a high degree of confidence that the perpetrators are financially motivated cybercriminals rather than a state actor.
One Vendor, 12,000 Facilities
This is the healthcare third-party risk problem at national scale.
No individual clinic among those 12,000 was breached. Each of them made a reasonable procurement decision: buy practice management software from an established domestic vendor that integrates with the national health system. None of them had visibility into MyDr’s security posture, and none of them could have detected this.
The aggregation is what creates the exposure. A single vendor accumulated the prescription histories of half a country because that is what selling software to 12,000 facilities produces, and the security of 19 million people’s medical records collapsed to the security of one private company’s infrastructure.
We described the same mechanism at Craneware, whose breach reached into 2,000 hospitals, and at Conduent’s 62 million-record breach. The pattern does not change with jurisdiction. Healthcare digitizes through intermediaries, the intermediaries concentrate, and the concentration becomes the attack surface.
The distinguishing feature here is national coverage. A US healthcare vendor breach reaches a large number of patients. A Polish one reaches half the citizenry, because the country is small enough and the vendor market concentrated enough that a single compromise approaches total population coverage.
Prescription Data Is Not Ordinary PII
The stolen set is prescriptions, referrals and identifiers. It is worth being explicit about why that is worse than it sounds.
A prescription history is a diagnosis in machine-readable form. Antiretrovirals indicate HIV status. Antipsychotics and mood stabilizers indicate psychiatric conditions. Oncology regimens indicate cancer. Fertility treatment, addiction therapy, gender-affirming care, contraception — all of it reconstructable from the medication record without any diagnosis field being present.
Combined with a PESEL number, which is Poland’s universal identifier used for banking, government services and employment, the dataset supports both identity fraud and targeted coercion. The attackers demonstrated exactly this by publishing a politician’s prescriptions. That was not a random sample choice; it was a demonstration of leverage.
We made the same argument about the market in stolen therapy records: the standard breach remedy of credit monitoring does not address the harm model at all. There is no product that un-discloses a medication history.
The April 2024 Boundary
The data reportedly covers historical records through April 2024. That cutoff is the most technically informative fact in the disclosure, and nobody has explained it.
A clean date boundary usually means one of three things: the attackers accessed a backup or archive snapshot taken at that point; MyDr migrated systems around then and the compromised platform holds only pre-migration data; or the intrusion is older than anyone has yet stated and the attackers have simply been sitting on the archive.
The third possibility is the one that should concern investigators, and MyDr’s statement that it “identified and removed the cause” does not resolve it. An incident disclosed in August 2026 involving data that stops in April 2024 raises an obvious dwell-time question that the company has not addressed publicly.
Poland’s UODO inspection will presumably establish this. Under GDPR, MyDr as a processor and the 12,000 facilities as controllers have overlapping notification obligations, and the answer to when access began determines whether the 72-hour clock was met by a wide margin or missed by two years.
What Is Unresolved
- The vector. MyDr has disclosed nothing about how attackers got in.
- The dwell time. Unstated, and the April 2024 boundary implies it may be substantial.
- Whether the data is for sale. MyDr says no evidence of public release. The attackers approached media rather than posting to a leak site, which is consistent with either an unclaimed extortion attempt in progress or a group building credibility before a sale.
- Whether the certificate rotation was precautionary or necessary. Gawkowski ordered it as a precaution. If MyDr held valid P1 authentication material, “precaution” is doing considerable work.
For 19 million Poles, the practical position is that their prescription histories are in criminal hands, the vendor that lost them has not said how, and the notification obligation sits with 12,000 separate clinics who learned about it from the news.
Sources
- The Record — Poland probes MyDr healthcare software breach potentially affecting 19 million people
- Notes From Poland — Poland hit by theft of 19 million patients’ data from medical platform
- Polish Press Agency (PAP) — Medical data of 19 million Poles stolen in major breach, minister says
- GovInfoSecurity — Hack on Med Software Firm Hits Half of Poland’s Population
- Cybernews — MyDr medical data breach



