← Blog

MyDr Breach: Poland Confirms ~19M Records

Share on X

August 12, 2026: Poland’s Digital Affairs Minister Krzysztof Gawkowski confirmed an “unprecedented” MyDr electronic patient-records breach after the company itself acknowledged about 19 million records (~2 TB) were stolen—including prescriptions, appointments, medications, and documents patients showed doctors. Earlier actor claims cited 18,814,422 unique PESELs. Canonical record: mydr-poland2026.

If your doctor or clinic uses MyDr for visits, e-prescriptions, or documentation, treat this as a live healthcare-identity risk—even before a personal letter arrives. Canonical BreachHistory record: mydr-poland2026.

What happened: timeline of the MyDr data breach probe

On or around August 5, 2026, actors reportedly messaged MyDr’s ownership with a password-protected PDF framed as an offer to “buy security-audit results,” according to Zaufana Trzecia Strona. Researchers say the same actors later approached the outlet claiming they had extracted more than 18 million unique PESEL numbers from medical systems tied to MyDr and roughly 2.5 TB of XML/JSON material.

MyDr’s public portal statement is careful but unambiguous: the firm is running an incident-response investigation covering a data-related incident on parts of its MyDr systems, has engaged external cybersecurity experts and legal counsel, and has notified law-enforcement authorities. It has not, at this stage, confirmed the actor headcount, named a ransomware brand, or published a field-by-field inventory of what left the environment.

Digital Affairs Minister Krzysztof Gawkowski publicly noted that much indicates an unauthorized person may have obtained access to the data—language that raises the political temperature without substituting for a forensic census. That ministerial acknowledgement is why this story moved from niche security blogs into mainstream Polish risk coverage within days.

For patients, the practical timeline looks like this: actor outreach in early August, researcher validation attempts mid-window, company portal notice, then a slower wave of clinic-level letters if controllers are told their tenancies are in scope. Expect staggered notices rather than a single national SMS blast.

What data may be involved in the MyDr Poland breach

Actor claims and researcher spot-checks described patient-style rows with PESEL, full name, date of birth, telephone numbers, NFZ region, and prescription-related metadata. Samples provided for a high-profile politician and for the reporting journalist matched PESEL/DOB/region where independently checkable; prescription drug names were not independently verified. Actors also showed screenshots from internal tooling (including Jira) as proof of deeper access, and a list of prescription numbers allegedly tied to the politician’s identity.

MyDr has not attested those categories or the 18.8 million figure. BreachHistory therefore indexes recordsAffected 18,814,422 as the actor-cited unique-PESEL count while labeling it unverified relative to a company or regulator census. That is the same discipline used for other vendor incidents where company confirmation of an investigation coexists with an unconfirmed criminal tally.

What makes a PESEL dump dangerous is structural: Poland’s national identification number is permanent, widely used across banking, telecom, e-government, and healthcare, and hard to “rotate” the way a password can be. Paired with clinic context—visit history hints, NFZ region, prescription numbers—it enables medical-identity fraud, forged e-prescription narratives, insurance abuse stories, and highly personalized phishing that cites a real clinic name.

Comment threads around the Zaufana Trzecia Strona piece also floated the possibility that multi-year clinical histories sit inside the alleged 2.5 TB corpus. That remains an actor assertion, not a MyDr confirmation. Still, EMR platforms that handle visits and e-prescriptions at MyDr’s claimed monthly volume inevitably store more than a phone book. Patients should plan for identity fraud first and clinical-privacy harm second—not the reverse.

How the attack is described (and what is still unknown)

Open reporting does not yet detail the initial access path—no confirmed VPN zero-day write-up, no named ransomware affiliate, no public IOC package from CERT Polska tied to a finished report. Researchers describe an extortion-style outreach to leadership and a corpus large enough that a statistical PESEL lookup experiment returned matches for a majority of voluntarily tested subjects—suggestive, not definitive, of breadth.

Unknowns that matter for patients and clinics:

  • Whether the claimed 2.5 TB includes multi-year clinical notes, imaging metadata, or only demographic/admin tables
  • Which clinic tenancies and years are in scope
  • Whether data was only accessed, or also copied and retained offline
  • Whether a public leak or dark-web sale will follow if negotiations fail
  • How quickly MyDr can map processor logs to controller-specific patient sets for lawful notification

Until MyDr and controllers publish scoped notices, assume attackers who already demonstrated PESEL matches can craft convincing “your clinic / e-recepta / NFZ” lures. The MyDr data breach story is therefore both a forensics problem and a mass-phishing forecast.

Who is at risk after the MyDr cyberattack claims

Patients of clinics using MyDr. MyDr markets itself as a major EDM provider handling on the order of 3 million visits and 2.7 million e-prescriptions per month across thousands of facilities. Many patients never see the MyDr brand—their GP or specialist does—so the first signal may be a clinic SMS or letter weeks later. If you have visited private practices or networks that digitize charts through third-party EMR SaaS in Poland, ask which vendor they use.

Clinic operators and doctors. Under GDPR, MyDr is typically a processor; healthcare facilities remain controllers. That split slows centralized “check if I was breached” portals: MyDr cannot casually dump victim lists to CERT for a public lookup without a legal basis. Clinics should expect processor notifications, DPIA updates, and patient-communication duties if their rows are confirmed. Front-desk staff need scripts now for patients who already read the headlines.

Public figures and high-sensitivity patients. Sample validation against a politician’s PESEL/phone shows why medical-platform breaches become national news: identity plus prescription context is leverage for blackmail and political ops, not only credit fraud.

Secondary victims. Family members whose phones appear on patient cards, employers listed in occupational-health contexts, and anyone who reuses emails or passwords across health portals and consumer apps.

Banks and telecom KYC desks. Secondary institutions will see a rise in PESEL-backed social engineering even if they were never MyDr customers. Fraud teams should treat August 2026 as a elevated-risk window for Polish identity proofs.

Industry and campaign context: why health IT vendors keep dominating 2026 breach lists

Europe’s 2026 healthcare breach wave has repeatedly hit the software layer between clinics and national e-health rails—billing platforms, EMR SaaS, and prescription gateways—rather than a single hospital EHR. France’s Cegedim Santé administrative-dossier incident, U.S. RCM breaches such as Unlimited Technology Systems and MCBS, and insurer-adjacent dental/PHI thefts like DentaQuest all illustrate the same pattern: compromise one widely deployed vendor, and the patient census jumps into the millions overnight.

Poland’s PESEL-centric identity stack raises the stakes relative to jurisdictions where medical record numbers are local to a provider. A stolen PESEL is reusable across sectors; a stolen U.S. MRN often is not. That is why this MyDr data breach story is being watched beyond healthcare IT circles—banks, telecom KYC desks, and e-government portals all inherit residual risk if the actor corpus is real.

Another recurring theme is processor opacity. Patients search “was I affected” and hit a wall because the brand on the clinic door is not the brand that hosts the database. BreachHistory indexes the vendor row so searchers who later learn their clinic used MyDr can find a canonical timeline, source links, and action items in one place.

Minister confirms ~19 million records

At an August 12 press conference, Digital Affairs Minister (and deputy prime minister) Krzysztof Gawkowski said the MyDr platform—one of Poland’s largest electronic patient-record providers—suffered an extraordinary leak affecting nearly 19 million people. Quoting company confirmation, he said about 19 million records containing various linkable data types were stolen, totaling more than 2 terabytes. Coverage from TVP World and Polskie Radio relays that prescriptions, scheduled appointments, prescribed medications, and documents patients presented to doctors were among the categories described. Roughly 12,000 medical facilities were being notified while clinics continued operating. Authorities said they saw no signs of a foreign-state attack and urged citizens to reserve PESEL via mObywatel; a public check mechanism was promised.

What MyDr and officials have said

MyDr’s portal FAQ (Polish) tells customers that investigation scope and impact are still being determined; that no customer action is required yet; that the platform remains operational; and that MyDr will contact affected clinics/patients directly if personal data is confirmed in scope. It emphasizes cooperation with law enforcement and external experts. That “no action required yet” line is legally cautious—and practically incomplete if phishing has already started.

Zaufana Trzecia Strona’s reporting fills the gap MyDr will not: actor claims, sample validation attempts, the August 5 leadership PDF, and the practical warning that patients cannot easily self-check via bezpiecznedane.gov.pl because MyDr is not the controller for most records. DataBreaches.net’s August 12 summary brought the same facts to an English-language audience.

BreachHistory treats the MyDr investigation notice as company-confirmed and the 18.8 million PESEL figure as an actor claim pending census. Update the catalog row if UODO, CERT Polska, or MyDr publish an attested count or if a leak site publishes bulk files that researchers can fingerprint.

Was I affected? What to do after a MyDr breach notice

There is no reliable public “search your PESEL in the MyDr dump” tool from the company at indexing time. Practical steps for people asking what to do after a possible MyDr PESEL exposure:

  1. Ask your clinic whether it uses MyDr and whether it has received a processor notification about this incident.
  2. Reserve / restrict PESEL via official government channels if you use that service—it will not erase leaked copies, but it can blunt some new-credit and contract fraud.
  3. Ignore unexpected “MyDr / e-recepta / NFZ / clinic” messages asking you to “confirm PESEL,” click a link, or install an app. Call the clinic using a number you already trust.
  4. Watch bank and telecom accounts for new loans, SIM swaps, or KYC resets that cite your PESEL.
  5. Enable MFA on email and any patient portals; change reused passwords.
  6. Keep written records of any clinic notice dates for insurers or complaints to UODO.
  7. Clinics: inventory MyDr processing agreements, freeze unnecessary exports, brief front-desk staff on phishing scripts that cite this incident, and coordinate counsel on patient notification timing.
  8. Doctors and staff: rotate MyDr and related admin passwords; assume internal ticket screenshots in actor packs mean helpdesk social engineering is next.
  9. Parents and caregivers: children’s PESEL numbers in family clinic files deserve the same caution as adult IDs—fraudsters open accounts in minors’ names too.

Phishing and secondary fraud to expect

When a MyDr breach headline hits national media, criminal call centers do not wait for a confirmed census. Expect:

  • SMS claiming your e-prescription is blocked until you “verify PESEL”
  • Emails with clinic logos asking you to download a “secure results viewer”
  • Voice calls referencing a real doctor’s name scraped from public directories plus a PESEL last digits the caller already knows
  • Fake UODO or CERT messages urging immediate password resets via a phishing domain

The tell is urgency plus a request for secrets the real clinic already holds or should never ask for over SMS. Hang up and redial using the number on your last visit confirmation, not the number in the suspicious message.

Regulator and insurer angles

UODO scrutiny is inevitable once controllers confirm patient data left a processor environment at this scale. Clinics should document when they learned of the MyDr incident, what MyDr told them, and when patient notices went out. Insurers writing cyber policies for Polish medical practices will ask the same questions. A clean timeline beats a scramble when class-action style claims or administrative fines arrive months later.

National e-health operators should also revisit whether PESEL continues to be over-collected in clinic SaaS forms. Every optional PESEL field that was never needed for a given workflow is another column in someone else’s breach spreadsheet. Boards that treat “we use a certified EMR” as a residual-risk zero are learning the hard lesson of 2026: certification is not containment, and a processor incident is still a controller notification problem.

For journalists and researchers, stick to primary sources—MyDr’s portal text, Zaufana Trzecia Strona’s methodology notes, and any later UODO or CERT Polska advisories—rather than recycled social posts that inflate the 18.8 million claim into “all of Poland’s medical history leaked” without evidence. Precision protects patients: overstating what is confirmed makes real notices harder to trust when they finally arrive.

How this compares to related healthcare breaches

Unlike a closed hospital ransomware event with a tidy HHS OCR number, the MyDr Poland breach is still in the investigation + actor-claim phase. That resembles early Exact Sciences / Abbott coverage before HIBP loads, or vendor breaches where the processor confirms an incident while controllers still count patients. It differs from pure unverified leak-site marketing because MyDr itself acknowledged a serious incident and engaged authorities.

If the actor tally holds, this would rank among the largest European health-IT exposures of 2026 by unique national IDs—comparable in order of magnitude to major French and U.S. vendor incidents BreachHistory already tracks under Cegedim Santé, DentaQuest, and Unlimited Technology Systems. Those rows are useful comparators for clinics writing board briefings: same vendor-concentration risk, different national ID regimes.

One distinction worth stressing for SEO readers searching “MyDr data breach 2026”: this is not a consumer app you installed. It is infrastructure your clinician uses. Searching only “my clinic breach” may miss the MyDr story entirely until your facility names the vendor in a letter.

Canonical record and sources

Canonical BreachHistory page: 2026 MyDr (Poland) — company investigating serious incident; actors claim ~18.8M unique PESELs.

Related catalog context: Cegedim Santé, Unlimited Technology Systems, DentaQuest, Xsolis.

Sources: MyDr portal notice, Zaufana Trzecia Strona, DataBreaches.net.

Updated 2026-08-13 after Minister Gawkowski’s confirmation that MyDr acknowledged ~19M records stolen. Earlier indexing (Aug 12) covered the investigation notice and actor PESEL tally.