Contents
Major Cybersecurity Incident Unfolds at MyDr, Affecting Millions in Poland
Cybersecurity services are reporting a potentially massive security incident involving MyDr, a prominent provider of electronic medical record (EMR) systems to thousands of Polish medical facilities. Individuals claiming responsibility for the attack allege they have obtained data concerning 18,814,422 unique national identification numbers (PESEL) and up to 2.5 terabytes (TB) of data. Here is what has been confirmed so far.
Understanding MyDr and Its Role in Polish Healthcare
What MyDr Does: A Brief Overview
MyDr specializes in delivering Electronic Medical Record (EMR) solutions to healthcare providers across Poland. Their MyDr EMR system is designed for both individual medical practices and larger medical facilities, including those operating within the public healthcare system (similar to the National Health Service in other countries).
According to data presented by the company, their system facilitates approximately 3 million patient visits and processes 2.7 million prescriptions monthly. This illustrates their significant footprint in the Polish healthcare infrastructure.
How MyDr Acquired Data for Millions of Poles
As a software provider for clinics, medical offices, and individual physicians, MyDr received patient data directly from the medical facilities utilizing its system. While the exact number of clinics and practices using MyDr is not publicly known, the company reportedly collaborates with 47,000 doctors.
To put this into perspective, as of June 30, 2026, the Central Register of Physicians in Poland recorded approximately 220,000 individuals with the right to practice medicine or dentistry. This highlights MyDr’s considerable reach within the country’s healthcare sector.
Details of the Alleged Data Breach
The Leak Notification and Claims
The alleged perpetrators contacted the cybersecurity portal Zaufana Trzecia Strona, claiming to possess data encompassing 18,814,422 unique PESEL numbers. It is crucial to note that this extensive scope of the data breach has not yet been fully confirmed. The editorial team at the portal emphasized that they could not verify the entire claimed dataset, which the attackers stated was 2.5 TB in size.
Verification Efforts and Official Response
The portal did manage to verify a portion of the samples provided. Identification data related to a specified politician, an article author, and selected individuals participating in a limited test were partially consistent with reality. This consistency lends credibility to the reports of unauthorized access but does not conclusively determine the exact number of affected individuals or the full scope of information acquired.
Relevant authorities have been informed about the incident. Deputy Prime Minister and Minister of Digital Affairs, Krzysztof Gawkowski, confirmed that services are conducting investigative actions.
⚠️ Ważna informacja dotycząca incydentu cyberbezpieczeństwa, do którego doszło w systemach i danych firmy MyDr. O zdarzeniu zostały poinformowane odpowiednie służby, które prowadzą intensywne działania związane z ustaleniem wszystkich okoliczności sprawy oraz wspierają firmę w… — Krzysztof Gawkowski (@KGawkowski) August 10, 2026
The incident is therefore under active investigation. However, the available clues are consistent enough to warrant serious attention and concern.
MyDr’s Response to the Incident
MyDr has confirmed that it is conducting an explanatory investigation into the reported incident. The company states it has activated response procedures, deployed security and infrastructure teams, is collaborating with external experts and authorities, and is maintaining contact with its clients (medical facilities).
It is important to note that MyDr operates as a data processor, while individual medical facilities are the primary data administrators responsible for the patient data.
Protecting Yourself: Beware of Phishing Scams
Current Status of Data Verification Tools
At this stage, no public tool has been made available for individuals to verify if their data is present in the potentially compromised database. Such a tool is unlikely to emerge until a clear understanding of what transpired, whether a data breach actually occurred, and how many individuals are affected, has been established.
Furthermore, as of now, MyDr’s data has not appeared in the history of breaches on the government’s “Secure Data” website.
Increased Vigilance Against Medical-Related Phishing
Phishing attempts frequently exploit public awareness surrounding major incidents to trick recipients into revealing login codes, card details, or other sensitive information. Therefore, everyone should exercise increased caution regarding messages received from clinics, the public healthcare system, or other medical services. For general cybersecurity tips against malware, consider reading our guide on Urgent Alert: Android BeatBanker Malware & Security Tips. Also, be wary of new deceptive tactics, such as those discussed in Fake Ads and TikTok Scams: A Cybersecurity Guide.
Frequently Asked Questions (FAQ)
MyDr is a company that supplies Electronic Medical Record (EMR) systems to thousands of medical facilities across Poland, handling millions of patient visits and prescriptions monthly.
Alleged perpetrators claim to have accessed data, including 18,814,422 unique PESEL numbers (Poland’s national identification numbers) and up to 2.5 terabytes of data. The full scope is still under investigation.
MyDr has launched an investigation, engaging security teams, external experts, and authorities. The Deputy Prime Minister and Minister of Digital Affairs has also confirmed that relevant services are actively investigating the incident.
Currently, no public tool is available to verify if your data is part of the alleged breach. Individuals are advised to await official updates as the investigation progresses. It is also important to be cautious of scams claiming to offer such verification.
Given the nature of the potential data breach involving medical information, it is highly recommended to be extremely vigilant against phishing attempts. Scammers often use such incidents as a pretext to trick individuals into revealing sensitive information. Exercise caution with any unsolicited messages, emails, or calls purporting to be from medical facilities, government health services, or MyDr. Always verify the authenticity of communication through official channels before clicking links or sharing personal details. Consider reviewing your accounts for suspicious activity and strengthening your passwords.
Source: Zaufana Trzecia Strona, X (formerly Twitter), National Medical Council.
Opening photo: National Cancer Institute / Unsplash.com