{"id":20812,"date":"2026-08-14T11:59:32","date_gmt":"2026-08-14T11:59:32","guid":{"rendered":"https:\/\/bizonews.com\/pl\/personal-data-leak-affects-19-million-patients-in-poland-what-administrators-and-patients-must-do-2\/"},"modified":"2026-08-14T11:59:38","modified_gmt":"2026-08-14T11:59:38","slug":"personal-data-leak-affects-19-million-patients-in-poland-what-administrators-and-patients-must-do-2","status":"publish","type":"post","link":"https:\/\/bizonews.com\/pl\/personal-data-leak-affects-19-million-patients-in-poland-what-administrators-and-patients-must-do-2\/","title":{"rendered":"Personal Data Leak Affects 19 Million Patients in Poland: What Administrators and Patients Must Do"},"content":{"rendered":"<p>On August 12, 2026, Poland&#8217;s Ministry of Digital Affairs announced that a cybersecurity incident in MyDr systems potentially compromised the medical data of approximately 19 million people.  <\/p>\n<h4>What data leak is involved?<\/h4>\n<p>The Ministry of Digital Affairs reported on August 12, 2026, that the likely medical data leak related to a cybersecurity incident in MyDr systems may affect approximately 19 million people. So far, unauthorized access to historical data up to April 2024 has been confirmed. In a statement published on the same day, MyDr announced that it is conducting an explanatory proceeding and indicated that the appropriate services have been notified to determine the circumstances of the incident. Available information also indicates that the first signals suggesting unauthorized data access appeared around August 5, 2026.<\/p>\n<p>In connection with the incident and the possible leak of patient health data, the President of the Personal Data Protection Office announced an inspection of MyDr.<\/p>\n<p>The inspection will assess implemented technical and organizational measures, the regularity of their testing, and the conducted risk analysis, particularly regarding the identification of threats to processed data and the adequacy of applied security measures.<\/p>\n<p>Although the actual scope of the incident and the scale of the potential security breach remain under ongoing investigation, the MyDr case highlights the level of risk associated with the advancing digitalization of healthcare. It also shows that as the number of data processed in electronic systems increases, the importance of effective protection mechanisms grows, especially for special categories of personal data, which include health information.<\/p>\n<h4>Why is a medical data leak particularly dangerous?<\/h4>\n<p>The disclosure of medical records is one of the most serious violations of personal data protection because it includes information classified as special categories of data. In the most obvious scenario, cybercriminals can use acquired personal identification data to steal identities, create fake accounts, extort services, or incur financial liabilities on behalf of the victims.<\/p>\n<p>Much more serious consequences, however, may result from medical identity theft and abuses related to access to health and insurance benefits. Having information about a patient, perpetrators may attempt to impersonate them to obtain prescription drugs, medical services, or other benefits involving the use of someone else&#8217;s health records. Furthermore, disclosed data can be combined with information from other sources held by various entities, enabling the creation of detailed profiles of individuals. Such profiling may include not only identification data but also information allowing conclusions to be drawn about a person&#8217;s health status, family, professional, or financial situation. Consequently, the risk of targeted fraud, extortion, identity theft, and other abuses utilizing detailed knowledge about the data subject increases.<\/p>\n<p>The particularly sensitive nature of health data also means that their disclosure can lead to privacy violations, loss of reputation, and even attempts at blackmail or exerting pressure on individuals whose data are affected. The risk also applies to public figures, company managers, and those performing public trust professions, as such information can be used to exert pressure, conduct disinformation activities, or organize discrediting campaigns.<\/p>\n<p>Additionally, the effects of a medical data leak can be long-lasting. Unlike access passwords or payment cards, health data cannot be changed or revoked. This means that once disclosed, information can remain in circulation for many years, generating risks for the individuals concerned long after the incident itself has ended.<\/p>\n<h4>Who is the data controller?<\/h4>\n<p>From the perspective of the GDPR, properly determining the roles of participants in data processing is crucial when handling a confirmed data protection breach.<\/p>\n<h4>Healthcare provider as the personal data controller<\/h4>\n<p>A healthcare provider acts as the personal data controller regarding patients&#8217; personal data processed in connection with the provision of health services. A doctor, clinic, or other medical facility decides on the purposes and methods of processing this data, particularly for diagnosis, treatment, keeping medical records, and fulfilling legal obligations. Using IT system providers such as MyDr does not change this status if the system provider processes personal data on behalf and upon the instruction of the healthcare provider.<\/p>\n<p>MyDr acts as an IT service provider for such an entity, which generally involves concluding a personal data processing agreement, under which the company processes patient data on behalf of the controller.<\/p>\n<h4>MyDr as a controller<\/h4>\n<p>However, it should be noted that MyDr&#8217;s privacy policy indicates the company may also act as a separate personal data controller for data processed to run user accounts, operate the appointment booking platform, manage reservation history, publish reviews, or pursue its own service operation goals. In such cases, patient data may be shared with doctors or medical facilities, which process them as independent data controllers.<\/p>\n<p>This means that depending on the specific service and processing circumstances, MyDr can act both as a processor and as an independent personal data controller.<\/p>\n<p>A healthcare provider acting as a personal data controller is not exempt from GDPR obligations just because a breach occurred on the side of the IT system provider.<\/p>\n<p>Upon obtaining information about the incident, the controller should first analyze the event, assess the risk to the rights and freedoms of data subjects, and then determine the scope of required actions.<\/p>\n<p>In particular, the controller should: 1. Verify the nature and scope of the personal data breach; 2. Conduct a risk assessment for individuals whose data were affected by the incident; 3. Report the breach to the President of the UODO if the conditions specified in the GDPR are met; 4. Inform data subjects if the breach is likely to result in a high risk to their rights and freedoms; 5. Document the incident, actions taken, and remedial measures applied in accordance with the accountability principle.<\/p>\n<h4>Important<\/h4>\n<p>The data controller will be obliged to demonstrate to the President of the UODO that it properly assessed the consequences of the incident and undertook adequate actions provided for by the GDPR.<\/p>\n<p>MyDr as a processor is responsible for the security of entrusted data, incident detection, technical handling, providing information to controllers, and cooperation in fulfilling GDPR obligations. MyDr as a processor must, among other things, demonstrate that it implemented appropriate security measures, detected the incident in a timely manner, informed controllers without undue delay, and actively supported them in managing the consequences of the breach.<\/p>\n<p>In the event of a data protection breach, responsibility does not rest solely on the controller or solely on the processor. The GDPR imposes obligations on both entities, so each is responsible for the proper execution of tasks assigned by the regulations. The scope of responsibility of the controller and processor differs, but it can be assessed in parallel within the same incident.<\/p>\n<h4>Should you wait for full confirmation from MyDr or report the personal data breach to the President of the UODO?<\/h4>\n<p>The mere fact of using the services of a processor where a security incident occurred does not yet mean that a specific controller&#8217;s data has been breached. If the processor is still conducting explanatory activities and cannot confirm whether and to what extent the incident included a given controller&#8217;s data, there is no basis to assume that the controller has identified a breach within the meaning of Article 33 of the GDPR. In such a situation, the confirmed obligation to report a data breach to the President of the UODO arises only after obtaining information allowing a reasonable assessment that the breach also applies to data entrusted by that controller.<\/p>\n<h4>How should patients react?<\/h4>\n<p>Until it is confirmed that a specific person&#8217;s data has been compromised in the breach, patients should monitor announcements published by data controllers and relevant public institutions, as well as regularly check the government&#8217;s Safe Data service, where data concerning individuals affected by the leak are to be published after information is provided by entities affected by the cyberattack.<\/p>\n<p>At the current stage, it is not yet known which specific patients are affected by the incident.<\/p>\n<p>In connection with the incident, the President of the Personal Data Protection Office published a guide reminding people of actions to limit the risk of data exploitation by unauthorized persons when a personal data breach has occurred.<\/p>\n<p>UODO particularly recommends: &#8211; Exercising special caution against data phishing attempts, &#8211; Changing passwords for e-mail, online banking, and other accounts containing personal or medical data, especially if the same password was used across multiple services, &#8211; Enabling multi-factor authentication (MFA), &#8211; Reserving the PESEL number, &#8211; Using anti-virus software and firewalls, and &#8211; Permanently deleting data from devices and storage media before selling or disposing of them.<\/p>\n<h4>Growing significance of threats to digital service providers<\/h4>\n<p>The incident concerning MyDr fits into a trend identified by ENISA (European Union Agency for Cybersecurity) related to the growing importance of supply chain threats and digital service providers. A security breach at an entity providing services to multiple organizations can trigger a cascading effect involving a significant number of clients and end users. The MyDr case confirms that the security of the healthcare sector depends not only on the security measures implemented by medical entities themselves, but also on the level of cybersecurity of technological solution providers who collect and process data on a large scale.<\/p>\n<p>From the patient perspective, trust in the healthcare system remains paramount. The digitalization of healthcare relies on the conviction that health information will be processed securely and confidentially. Every incident concerning medical data weakens this trust, especially since the consequences of disclosing such information can be long-lasting and often irreversible. Therefore, the MyDr case should be an impetus not only for analyzing the causes of the event, but also for further strengthening cybersecurity standards, risk management, and supervision over digital service providers upon whom the security of the entire healthcare sector increasingly depends.<\/p>\n<p>Ewelina Og\u0142ozi\u0144ska, Legal Counsel at SDZLEGAL Schindhelm specializing in personal data protection and new technologies law.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On August 12, 2026, Poland&#8217;s Ministry of Digital Affairs announced that a cybersecurity incident in MyDr systems potentially compromised the medical data of approximately 19 million people. What data leak is involved? The Ministry of Digital Affairs reported on August 12, 2026, that the likely medical data leak related to a cybersecurity incident in MyDr [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":20813,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"wpai_generated_summary":"","footnotes":""},"categories":[44],"tags":[],"class_list":["post-20812","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-culture"],"_links":{"self":[{"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/posts\/20812","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/comments?post=20812"}],"version-history":[{"count":0,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/posts\/20812\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/media\/20813"}],"wp:attachment":[{"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/media?parent=20812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/categories?post=20812"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/tags?post=20812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}