{"id":20668,"date":"2026-08-13T19:39:31","date_gmt":"2026-08-13T19:39:31","guid":{"rendered":"https:\/\/bizonews.com\/pl\/personal-data-leak-affects-19-million-patients-in-poland-what-administrators-and-patients-must-do\/"},"modified":"2026-08-13T19:39:38","modified_gmt":"2026-08-13T19:39:38","slug":"personal-data-leak-affects-19-million-patients-in-poland-what-administrators-and-patients-must-do","status":"publish","type":"post","link":"https:\/\/bizonews.com\/pl\/personal-data-leak-affects-19-million-patients-in-poland-what-administrators-and-patients-must-do\/","title":{"rendered":"Personal Data Leak Affects 19 Million Patients in Poland: What Administrators and Patients Must Do"},"content":{"rendered":"<p>Following a cybersecurity incident in MyDr systems disclosed on August 12, 2026, up to 19 million individuals face potential medical data exposure, prompting urgent guidance for data controllers and patients.  <\/p>\n<h4>What the Data Leak Involves<\/h4>\n<p>The Ministry of Digital Affairs reported on August 12, 2026, that a probable medical data leak linked to a cybersecurity incident in MyDr systems may affect approximately 19 million people. Unauthorized access to historical data up to April 2024 has been confirmed so far, with the company conducting an investigation and notifying relevant authorities after initial signs appeared around August 5, 2026.<\/p>\n<p>The President of the Personal Data Protection Office announced an inspection of MyDr to evaluate technical and organizational measures, testing regularity, and risk analysis. This case highlights the growing risks associated with the digitalization of healthcare and the heightened importance of data protection mechanisms for special category data like health information.<\/p>\n<h4>Why Medical Data Leaks Are Particularly Dangerous<\/h4>\n<p>Disclosing medical records represents a severe data protection breach involving special category data, risking identity theft, fraudulent accounts, and financial liabilities. Beyond traditional identity theft, perpetrators can exploit medical identity theft to obtain prescription drugs, medical services, or insurance benefits, while combining leaked records with other sources to build detailed profiles on individuals.<\/p>\n<p>The sensitive nature of health data can lead to privacy violations, reputational damage, blackmail, or pressure tactics affecting public figures and professionals. Because health data cannot be changed or invalidated like passwords or payment cards, the compromised information can remain in circulation for years, generating long-term risks.<\/p>\n<h4>Data Controller Responsibilities Under GDPR<\/h4>\n<p>Medical treatment providers act as data controllers for patient data processed during healthcare delivery, retaining responsibility for diagnoses, treatment, and medical records even when using IT vendors like MyDr. MyDr operates as an IT service provider and data processor under a data processing agreement, though its privacy policy indicates it may also act as a separate controller for user accounts, booking platforms, and service operations.<\/p>\n<p>Medical entities cannot exempt themselves from GDPR duties simply because a breach originated with an IT system vendor. Upon learning of an incident, controllers must analyze the event, assess risks to rights and freedoms, notify the President of the Personal Data Protection Office if criteria are met, inform affected individuals when high risks exist, and document the incident thoroughly.<\/p>\n<h4>Action Steps for Patients and Compliance Protocol<\/h4>\n<p>Controllers must guide patients on mitigating risks by checking secure data portals, reserving their PESEL numbers via mObywatel or banks, and staying vigilant against phishing scams. MyDr, as a data processor, remains responsible for security, incident detection, technical handling, and active cooperation with controllers under GDPR requirements.<\/p>\n<p>Controllers are not obligated to notify the Personal Data Protection Office until they obtain sufficient information confirming that the breach impacts data entrusted by their specific organization. This incident underscores broader EU cybersecurity concerns regarding supply chain vulnerabilities and third-party digital service providers in the healthcare sector.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Following a cybersecurity incident in MyDr systems disclosed on August 12, 2026, up to 19 million individuals face potential medical data exposure, prompting urgent guidance for data controllers and patients. What the Data Leak Involves The Ministry of Digital Affairs reported on August 12, 2026, that a probable medical data leak linked to a cybersecurity [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":20669,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"wpai_generated_summary":"","footnotes":""},"categories":[10],"tags":[],"class_list":["post-20668","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech"],"_links":{"self":[{"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/posts\/20668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/comments?post=20668"}],"version-history":[{"count":0,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/posts\/20668\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/media\/20669"}],"wp:attachment":[{"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/media?parent=20668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/categories?post=20668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/tags?post=20668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}