Skip to main content

MyDr sp. z o.o.MyDr medical software breach exposed health records of ~18.8 million Polish patients

Poland's Central Bureau for Combating Cybercrime launched an investigation on August 12, 2026 after MyDr, an electronic health records vendor used by over 10,000 Polish clinics, suffered unauthorized access exposing roughly 18.8 million patients' data (about half of Poland's population), including PESEL national ID numbers, names, contact details, diagnoses, and prescription records from 12,000+ facilities. Because MyDr is a data processor rather than a controller under GDPR, it could not directly notify affected patients, instead relying on client clinics to pass notifications along, delaying individual disclosure. MyDr said its systems were secure and that no evidence of public sale of the stolen data had been found as of the investigation's start.

Scoring Impact

TopicDirectionRelevanceContribution
Corporate Transparency-againstsecondary-0.50
Data Security-againstprimary-1.00
Overall incident score =-0.483

Score = avg(topic contributions) × significance (critical ×2) × confidence (0.64)× agency (negligent ×0.5)

Evidence (2 signals)

Confirms Criticism Aug 13, 2026 documented

DataBreachToday: hack on medical software firm MyDr hits half of Poland's population

Reporting on the August 2026 breach investigation by Poland's Central Bureau for Combating Cybercrime, detailing scope of 18.8 million affected patients and 2.5TB of stolen data.

Confirms Criticism Aug 13, 2026 documented

Notes from Poland: theft of 19 million patients' data from MyDr medical platform

Poland-focused outlet reporting on the scale of the breach and the GDPR processor-notification gap that delayed direct patient disclosure.

Related: Same Topics