Poland is investigating a cyberattack on healthcare software provider MyDr that may have exposed historical patient and medical-facility data tied to nearly 19 million people and more than 12,000 providers. Authorities say attackers accessed data held in MyDr systems through April 2024; no CVE, software version, or intrusion method has been disclosed. As a precaution, Poland’s e-Health Center is rotating digital certificates used by medical systems to connect to the national P1 e-health platform.
Why it matters: This could affect a very large number of patients, clinics, and doctors even if the national P1 system itself was not breached. Healthcare organizations using MyDr should treat this as urgent: coordinate with MyDr and Polish health authorities, rotate or replace relevant credentials and certificates, review logs for unauthorized access, and prepare for patient notification and follow-on phishing risk.
2026.08.17
100% relevant
This article is the first tracked item here establishing the MyDr breach as a major standalone incident, with national authorities confirming scope, investigation, and precautionary certificate replacement tied to Poland’s healthcare infrastructure.
← Back to all stories