< Back to all clusters
[TECHNOLOGY] · Poland · 4 sources

started · updated

MyDr cyberattack threatens data of 19 million patients

A cyberattack on the MyDr EDM system, which manages electronic medical documentation, has potentially compromised the personal data of nearly 19 million patients in Poland. The system serves approximately 12,000 medical facilities across the country.

Attackers gained access to an archival database copy from April 12, 2024. The breach primarily affects data from before that date, though it may include certain exceptions such as canceled referrals. Compromised information may include names, PESEL numbers, residential addresses, contact details, health status (including ICD-10 disease codes), and medical leaves.

While there have been no confirmed reports of the data being publicly released or misused, experts warn of future risks. Patients are advised to secure their PESEL numbers via the mObywatel app or local government offices to prevent unauthorized financial obligations. Authorities also warn against clicking suspicious links in SMS or email notifications regarding the breach, as some fraudulent messages may be circulating.

Entities

CERT Polska · MyDr · Office for Personal Data Protection