Poland calls the MyDr breach one of its largest ever, with nearly 19 million people potentially exposed
A cyberattack on MyDr, a company whose software is used by more than 12,000 Polish medical facilities, may have exposed the personal and medical data of nearly 19 million people. The digital affairs minister called it one of the largest incidents in the country's history. Here is what officials have confirmed, what is still only claimed, and why a breach at one private vendor can reach so many patients at once.

A cyberattack on MyDr, a private company that supplies software to more than 12,000 medical facilities in Poland, may have exposed the personal and medical data of nearly 19 million people. Poland's digital affairs minister called it one of the largest incidents in the country's history. Officials say the national e-health platform, P1, was not breached and that patient services were not disrupted. The data protection regulator plans to inspect MyDr, and the exact contents of any data taken have not been independently verified. No group has been formally identified as responsible.
A cyberattack on a single medical software company has turned into what Polish officials describe as one of the largest data breaches in the country's history. The target was MyDr, a private firm whose software connects doctors, clinics and other providers to the country's health systems. According to Polish officials, the incident may involve the personal data, including medical information, of nearly 19 million people, in a country of roughly 38 million.
This is the kind of breach that shows how a single supplier can become a single point of failure for an entire sector. Individuals never signed up with MyDr, yet their records could be caught up in it, simply because their clinic uses the company's software.
What happened, and how big is it?
The breach was first reported in mid-August by the Polish IT security outlet Zaufana Trzecia Strona, which reported that people claiming responsibility had contacted it and provided what they said was proof of the intrusion, including a screenshot they claimed contained the data of a prominent Polish politician. Shortly after, MyDr confirmed it had become the target of what it described as external, intentional criminal activity affecting some of its data.
Poland's digital affairs minister, Krzysztof Gawkowski, said the country was "dealing with one of the largest incidents in Poland's history," per Notes from Poland. The figure being cited is nearly 19 million people; the attackers themselves claimed access to the data of around 18.8 million. The scale comes from MyDr's reach rather than the volume of any stolen data: its software is used by more than 12,000 medical facilities, and the company says it processes around 3 million consultations and 2.7 million prescriptions a month.
One important qualifier from the authorities: officials said the attackers reached historical data held in MyDr's systems dating through April 2024, and that the breach may not involve all of MyDr's customers or their patients. In other words, the nearly-19-million figure is a ceiling on potential exposure, not a confirmed count of individually harmed people.
What data may have been taken, and what is still unconfirmed
This is where careful reading matters. The claims about exactly what was taken come largely from the alleged attackers and from Polish cybersecurity media, and as the reporting notes, those claims have not been independently verified.
With that caveat, the material said to be involved could include names, dates of birth, national identification numbers, certain prescription information and other medical records. MyDr has said that, as of its updates, it had found no evidence the data had been published or otherwise made public. The company also said it had identified and removed the cause of the incident and introduced additional security measures, though it has not disclosed the vulnerability or how the attackers got in.
No specific group or actor has been formally identified as responsible. Officials have described the perpetrators as very likely to be cybercriminals, and the investigation into who carried out the attack is ongoing.
The national system held, and that distinction matters
A crucial point that is easy to lose in the headlines: this was a breach of a private vendor, not of Poland's central health infrastructure. MyDr's software connects providers to P1, the nationwide electronic health platform that supports services such as electronic prescriptions and referrals. Health Minister Jolanta Sobierańska-Grenda said the incident did not threaten Poland's public healthcare systems and that P1 remained secure.
As a precaution, the country's e-Health Centre began replacing the digital certificates that medical systems use to connect to P1. Officials said they had found no evidence those certificates were stolen or misused, and that the swap was a preventive measure to stop any potentially compromised certificate being used later. They also said the change should not disrupt patient services such as prescriptions and referrals.
What happens next
Poland's Personal Data Protection Office (UODO) plans to inspect MyDr, while security agencies work to identify those behind the attack. Gawkowski said that if the investigation finds the company failed to follow proper procedures or adequately protect its systems, it will face legal consequences.
For a breach of this scale, the regulatory and legal questions will play out over months, not days. A question likely to shape the inquiry is whether a company holding records on so many patients had security measures proportionate to that role.
What people in Poland were advised to do
Officials pointed citizens to practical steps rather than waiting for a full accounting. Gawkowski urged people to use secure government services to check whether their data was affected, and to use the state mObywatel portal to "block" their PESEL, Poland's national identification number, a measure intended to stop fraudsters using it to take out credit or otherwise impersonate someone. This is guidance issued by Polish authorities for people in Poland, who were urged to rely on official government channels rather than third-party offers to "check" their data.
The wider lesson is not specific to one country. As more of healthcare runs through a small number of software suppliers, each of those suppliers becomes a concentrated target, and the blast radius of a single breach grows with them. It is the same concentration risk that runs through much of how personal data is collected and tracked online today.
Frequently asked questions
What is MyDr?
MyDr is a privately owned Polish company that supplies software to doctors, clinics and other healthcare providers. Its tools help manage medical practices and electronic medical records, and connect providers to P1, Poland's national electronic health platform. More than 12,000 medical facilities use its software.
How many people were affected by the MyDr breach?
Polish officials have cited a figure of nearly 19 million people whose data may have been exposed, and the alleged attackers claimed access to around 18.8 million. Authorities have cautioned that the breach may not involve every MyDr customer or patient, so this is the potential scale rather than a confirmed count.
Was Poland's national health system hacked?
No. Officials said the national P1 platform remained secure and that the breach was of MyDr, a private software vendor. As a precaution, digital certificates used to connect medical systems to P1 were being replaced, with officials saying there was no evidence those certificates had been stolen or misused.
Has the data been published?
As of the authorities' and MyDr's statements, there was no evidence the data had been made public. The specific contents said to have been taken come largely from the alleged attackers and cybersecurity media and have not been independently verified.


