started · updated
Polish Medical Chamber seeks clarity on MyDr data breach obligations
The Polish Medical Chamber (NIL) has requested clarification from the Personal Data Protection Office (UODO) regarding the legal obligations of doctors and dentists following a data breach involving the MyDr electronic medical documentation system.
Confusion arose due to conflicting communications: MyDr informed clients that no immediate action was required, while UODO emphasized the necessity for administrators to conduct risk assessments and evaluate reporting obligations. NIL is specifically seeking guidance on the 72-hour reporting deadline under GDPR, particularly when a system provider has not yet confirmed which specific facilities were affected.
In a new development, MyDr has begun sending individual notifications to patients whose data may have been compromised in the August cyberattack. These automated emails identify the specific medical facility associated with the patient's data, such as OpenMed Centrum Medyczne in Warsaw. The potential breach includes a wide range of sensitive information, including names, addresses, PESEL numbers, health and social insurance data, and employer details.
Entities
MyDr · Naczelna Izba Lekarska · OpenMed Centrum Medyczne · Urząd Ochrony Danych Osobowych