started · updated
Poland introduces ‘Cyber Piątka’ to enhance medical data security
Following a data breach involving the MyDr software that exposed the data of approximately 19 million Poles, the Polish Ministry of Digital Affairs has introduced a legislative package known as ‘Cyber Piątka’. This initiative aims to strengthen the security of medical data through increased oversight and new technical requirements.
The proposed changes include the certification of entities processing medical data and the establishment of minimum technological standards for processing systems. Additionally, patients would be notified when their data is entrusted to external entities, and applications such as mObywatel and mojeIKP would send notifications regarding medical events like prescriptions or procedures.
Under the amended National Cybersecurity System (KSC) Act, the scope of cybersecurity oversight has expanded to include new sectors and categories of entities. Competent authorities (OWcyber), such as relevant ministers or central administration bodies like the Polish Financial Supervision Authority, are responsible for identifying, monitoring, and auditing key and important entities. New requirements will specifically target entities processing data for at least 100,000 individuals or at least 100 administrators.
While the Ministry views these steps as essential, some experts have expressed caution. Aneta Sieradzka of the Social Expert Team at the Personal Data Protection Office noted that ‘paper compliance’ may be insufficient if organizations lack clear visibility into data flows and access, suggesting that true security relies on robust systems and procedures rather than just legislative mandates.
Entities
Ministry of Digital Affairs · MyDr · Personal Data Protection Office