The MyDr data breach may affect 19 million Poles. The data came from the systems of healthcare facilities

A cyberattack on MyDr, a software provider for thousands of medical facilities, may have led to a data breach affecting as many as 19 million Poles, highlighting the scale of the risks associated with the digitization of healthcare.

2 Min Read
Cyberatak cyberbezpieczenstwo

The data breach, which could affect nearly 19 million Poles, stems from an incident at MyDr, a software provider for healthcare facilities. According to Deputy Prime Minister Krzysztof Gawkowski, the stolen database is over 2 TB in size, and the company has confirmed the loss of around 19 million records. Around 12,000 healthcare facilities used its system.

This is significant because MyDr primarily acts as a technological backbone for clinics and medical practices. The software is used, amongst other things, to maintain electronic medical records, manage appointments, and issue e-prescriptions and e-sick notes. In practice, therefore, some patients may have found themselves in the MyDr database, even if they are not familiar with the brand and have only used the services of their own clinic.

Since 2023, MyDr has been part of the Docplanner group, to which ZnanyLekarz also belongs. However, this does not mean that there has been a data breach from the ZnanyLekarz database. According to information provided to CRN, the systems of both services are separate and do not exchange data with one another.

The incident highlights the growing risk of sensitive data being concentrated amongst healthcare technology providers. In 2025, the number of cybersecurity incidents reported in Poland rose by 144 per cent year-on-year.

In the case of MyDr, the consequences could include not only identity theft but also more convincing phishing attacks utilising medical data. For healthcare facilities, this in turn serves as a warning to audit IT suppliers more thoroughly and review how patient data is secured. The government advises those affected by the data breach, first and foremost, to block their PESEL number.

Share This Article