Sunday, September 13, 2026
HomeE.U.Polish medical data breach exposes records of 19 million people in one...

Polish medical data breach exposes records of 19 million people in one of country’s largest leaks

Digital ministry says stolen database contains prescription details, appointment schedules and confidential patient records.

Scale of breach described as unprecedented

Poland has suffered one of the largest data breaches in its history after an attack on the systems of MyDr, a company that provides software to doctors and medical practices, resulted in the theft of records relating to nearly 19 million people, the country’s digital minister said on Wednesday.

“We are dealing with an extraordinary data leak that affects almost 19 million people. This is one of the largest incidents in Poland’s history,” said Krzysztof Gawkowski, the minister for digital affairs.

According to the minister, approximately 19 million records were taken from the company’s system, with the total volume of the database exceeding 2TB. The stolen information includes confidential patient data such as prescription details, prescribed medications, medical documents and scheduled appointments.

Cause remains unclear, say officials

Gawkowski said there was currently no evidence to suggest the incident was caused by an external hacking attack. Investigators are considering a range of possible explanations, including human error, system failure, negligence on the part of the company or deliberate sabotage.

“Today, nothing indicates that we are dealing with an external attack,” the minister said.

The MyDr system was used by roughly 12,000 medical facilities across Poland. Authorities have begun notifying doctors who worked with the platform, while medical institutions continue to operate as normal.

Authorities rule out ransom negotiations

The investigation is being led by Poland’s cybersecurity agencies and the Central Bureau for Combating Cybercrime. The digital ministry also plans to give citizens the opportunity to check whether their data has been included in the stolen database.

Officials have warned that the breach could trigger a fresh wave of fraud. If criminals are able to link a specific individual to a medical facility, appointment or prescription, they could use that information to craft more convincing phishing messages and attempt to extract money or gain access to online accounts.

The minister urged citizens whose data may have been compromised to block their PESEL national identification number as a priority. The government has said it has no intention of negotiating with cybercriminals or paying a ransom for the stolen database.

RELATED ARTICLES

Most Popular