Lead Analysis
Security & Risk5 min

Poland Confirms 2 TB Data Leak and Nearly 19 Million PESEL on MyDr Medical Platform

Sala de arquivo médico deserta à noite com gaveteiros metálicos entreabertos, prontuários espalhados no chão e um terminal de computador solitário exibindo tela de login.

The Ministry of Digitalization confirmed the theft of clinical data from 12,000 clinics via the MyDr platform, exposing prescriptions, schedules, and national identifiers of millions of citizens.

Poland's Deputy Prime Minister and Minister of Digitalization, Krzysztof Gawkowski, confirmed on Wednesday the theft of data linked to nearly 19 million citizens from the MyDr system, one of the largest electronic health record operators in the country. According to the announcement from the Ministry of Digitalization and the state agency PAP, over 2 terabytes of data were exfiltrated. The attackers claim to have possession of 18,814,422 unique PESEL numbers, the Polish national identifier.


MyDr is used by approximately 12,000 clinics and practices across Poland. The compromised data goes beyond the basic identification block: it includes issued prescriptions, appointment schedules, clinical records, registered medications, and mailing addresses. Gawkowski classified the incident as one of the largest in the country's history and publicly recommended that citizens place restrictions on the use of their PESELs until the full extent of the leak is mapped out.


The Scope


CERT Polska, the Central Bureau of Cybercrime, and the Personal Data Protection Office (UODO) have opened a joint investigation. The ministry has set up the Bezpieczne Dane (Safe Data) portal for citizens to check if they are included in the affected database. As this article was being finalized, MyDr had not published its own announcement detailing the access vector, containment timeline, or mandatory individual notification plan under the GDPR when the incident involves sensitive health data.


The government is refraining from attributing the attack to a foreign state. Gawkowski stated that the cause could be human error, systemic failure, sabotage, or negligence on the part of the contracted company. The choice of language matters legally: characterizing it as operator failure exposes MyDr to greater administrative sanctions under Article 83 of the GDPR, with a cap of 4% of global annual revenue.


A Repeating Pattern


The compromised arrangement is similar across much of the continent: a third-party platform centralizes the electronic health records of a network of independent clinics, with loose federated access control among units and little individual visibility of each node's security posture. A single compromised credential in a small unit exposes the aggregated data.


For the European CIO, the Polish precedent becomes an operational case study: the national authority confirmed the incident in less than 72 hours, moved residual data to state infrastructure, and communicated publicly before the platform operator did. If this dynamic becomes a standard response within the bloc, the reputational cost of a breach in Europe shifts, weighing more heavily on the vendor than on the state or the client clinic.


Readings Beyond Poland


In Germany, the Federal Office for Information Security (BSI) and the Ministry of Health are tightening requirements on operators of the Telematik-Infrastruktur, the backbone of the German electronic health record system. A MyDr incident shifts immediate political pressure to expedite audits on gematik and on the private operators within the network.


In Brazil, the private health sector operates electronic health records in a model identical to MyDr: specialized SaaS aggregating independent clinics and health plans. Providers like Feegow, iClinic, MV Sistemas, and Philips' Tasy serve thousands of establishments and aggregate identification data, CPF, and clinical history under a single operator. The National Data Protection Authority has been intensifying inquiries regarding security requirements for health data, and Anvisa has started requiring an incident response plan during the renewal of hospital licenses. The MyDr case accelerates this debate.


In the United States, the sector is still operating under a post-Change Healthcare response, the 2024 attack that paralyzed hospital reimbursements and forced a reevaluation of contracts among payers, providers, and EHR vendors. The thesis that the American CISO has been trying to sell to the board for eighteen months now receives a recent and verified European example.


Consultancies and Underwriters in the Crosshairs


The financial perspective also matters. Consultancies and cyber insurers will need to quickly reprice two blocks. Deloitte, PwC, and KPMG maintain health security practices with contracts indexed to risk levels by vendor; when the vendor assumes primary responsibility, the pricing for assessments increases. Underwriters like AIG, Chubb, and Munich Re, who have been tightening exclusions for incidents on aggregation platforms, gain immediate grounds to raise deductibles on SaaS EHR operators in the next renewal cycle. For the CFO of a medical platform provider, this means capital costs and policy costs moving in the same direction.


The operative point remains. The Polish crisis demonstrated that the state is capable of moving faster than the commercial operator in public communication, reversing the vector of reputational damage. European and Brazilian clinical platform providers that have not yet articulated a public response plan within 72 hours have just received an informal deadline imposed by the expectations created by the MyDr case.

Lead Analysis