Medical records of nearly 19 million Poles stolen in breach of MyDr platform

Poland's Digital Affairs Minister Krzysztof Gawkowski confirmed on August 13 that hackers stole medical records belonging to nearly 19 million people from MyDr, one of the country's largest electronic medical records platforms used by doctors and clinics nationwide. The stolen database exceeds 2 terabytes, making it one of the largest healthcare data breaches reported in Europe this year.
What was taken
MyDr confirmed it was the target of what it described as an “external, deliberate criminal act” affecting a portion of its data. The stolen records reportedly include information tied to prescriptions, scheduled appointments, prescribed medications, and documents patients had submitted to doctors — data that in aggregate can be linked back to specific individuals rather than existing as anonymized fragments.
Gawkowski described the incident as “unprecedented” for a cyberattack targeting online patient records in Poland, given both the scale and the sensitivity of medical information involved. Poland's population is roughly 38 million, meaning the breach potentially exposed records for close to half the country.
Investigation still in early stages
Cybersecurity services and law enforcement are actively investigating how the intrusion occurred and who is responsible. Gawkowski noted that, at this stage, authorities have not conclusively confirmed the incident meets the formal legal definition of a data breach, even though there are strong indications of unauthorized access to the database. Officials have said there is currently no indication the attack was carried out by a foreign state, though that assessment could change as the investigation continues.
Government response
The Polish government is working to secure the affected data and prevent it from being sold or distributed online, and plans to stand up a dedicated database that will let individuals check whether their personal information was exposed in the breach — a response modeled on similar breach-notification tools used after large-scale incidents elsewhere in Europe.
The incident adds to a string of major healthcare data breaches disclosed globally in 2026, and comes as EU member states face growing pressure to harden medical data infrastructure under GDPR amid a rising volume of attacks specifically targeting health records, which carry a premium on dark web markets due to the difficulty of changing stolen medical information compared to something like a password.
Originally reported by Polish Press Agency (PAP). Read the original article for additional details.
View original source