Security1 distinct publisher3 min readUpdated
Polish authorities are investigating a compromise at clinical software supplier MyDr that may have exposed data on nearly 19 million people and more than 12,000 medical facilities.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Polish authorities are investigating a compromise at clinical software supplier MyDr that may have exposed data on nearly 19 million people and more than 12,000 medical facilities.
Polish authorities are investigating a cyberattack on MyDr, a privately owned Polish company that supplies software to doctors, clinics and other healthcare providers, in an incident that may have exposed data belonging to nearly 19 million people and more than 12,000 medical facilities [1][2]. The records sat in MyDr's systems, not in the clinics' own networks, which is the whole point: in healthcare the practical blast radius is the integrator's perimeter [1][5].
The arithmetic is worth stating plainly. Nearly 19 million people across more than 12,000 facilities works out to roughly 1,580 patients per facility [1]. No individual practice in that set could have been breached at anything like this scale on its own.
MyDr said on Friday that it had identified and removed the cause of the incident and added security measures, without describing the vulnerability or how the attackers got in [3]. The week before, it had characterised the event as "external, intentional criminal activity" [4]. Polish authorities say the attackers reached historical data held in MyDr systems through April 2024, and that not all MyDr customers or their patients are necessarily involved [5]. The company says it has found no evidence so far that the data has been published or otherwise made public [6].
The interesting remediation is not MyDr's. MyDr's software connects providers to P1, Poland's nationwide electronic health platform behind electronic prescriptions and referrals, and the company also builds practice management and electronic medical record tools [7]. Digital Affairs Minister Krzysztof Gawkowski said on Friday that the country's e-Health Center was replacing, as a precaution, the digital certificates that medical systems use to connect to P1 [8]. According to Gawkowski there is no evidence the certificates were stolen or misused; the rotation is meant to stop potentially compromised certificates being used later [9]. Officials said patients should not see disruption to prescriptions or referrals [10]. Read that as a state operator deciding it cannot verify what a private supplier lost, and rotating trust across an entire national ecosystem rather than waiting to find out.
The official line is that the state platform held. Health Minister Jolanta Sobieranska-Grenda said Monday that the incident posed no threat to Poland's public healthcare systems and that P1 remained secure [11], and MyDr has said its systems remain operational and safe for doctors and patients [12]. Both can be true while 19 million people's records are still at risk, because the exposure was never in P1.
On the contents, be careful. Poland's Personal Data Protection Office plans to inspect MyDr and security agencies are working to identify those responsible, Gawkowski said last week, adding that the company will face legal consequences if the investigation finds it failed to follow proper procedures or protect its systems [13][14]. No threat actor has been named [15]. Polish outlet Zaufana Trzecia Strona reported that people claiming responsibility contacted it with purported evidence, including a screenshot containing information on a prominent Polish politician [16], and claims and samples reported by Polish cybersecurity media suggest the material could include names, dates of birth, identification numbers, some prescription data and other medical records [17]. Those claims have not been independently verified [17].
What to watch: whether the data protection office's inspection produces findings on MyDr's controls [13], whether the certificate replacement completes without breaking clinic connectivity [8][10], and whether any of the claimed samples is verified [17]. Note also that convenience chain Zabka disclosed this month that attackers reached its internal systems through a third-party contractor account [18]. Two Polish incidents, both entering through someone else's access; no link between them has been established [19].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Polish authorities are investigating a cyberattack targeting healthcare software provider MyDr that may have exposed data belonging to nearly 19 million people and more than 12,000 medical facilities.
Polish Digital Affairs Minister Krzysztof Gawkowski said on Friday that, as a precaution, the country's e-Health Center was replacing digital certificates used by medical systems to connect to P1.
Gawkowski said authorities found no evidence the certificates were stolen or misused in the MyDr attack, and that the replacement is intended to prevent potentially compromised certificates being used later for unauthorized access.
Officials said the certificate replacement should not disrupt services for patients, including electronic prescriptions and referrals.
MyDr is a privately owned Polish company that supplies software to doctors, clinics and other healthcare providers.
MyDr said on Friday it had identified and removed the cause of the incident and introduced additional security measures, and did not provide details about the vulnerability or how attackers gained access.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named officials on the record, but no technical forensics and a single publisher
The account rests on attributable statements from the digital affairs minister, the health minister, and the company, plus a specific data-access window (through April 2024) and a concrete countermeasure (P1 certificate rotation). Against that, the vulnerability and intrusion path are undisclosed, the nearly 19 million figure is unsourced in method and explicitly caveated as possibly not covering all customers or patients, the data categories come from unverified attacker-supplied samples, and there is no attribution. Only one publisher is in the cluster, so nothing here is corroborated independently.
Real production footprint and a live national countermeasure, not a pilot
This is not a speculative technology story: MyDr software is in production across more than 12,000 medical facilities and functions as the link to P1, Poland's nationwide e-health platform, and the state's e-Health Center has already begun rotating P1 connection certificates in response. The score is held below high because the population figure is a potential-exposure estimate rather than a verified customer or patient count, and no per-facility deployment or notification data is given.
Headline scale runs ahead of verified impact
The nearly 19 million figure anchors the story while officials caveat that not all customers or patients may be involved, the vendor reports no evidence the data has been published, ministers state P1 remained secure, and the sensitive record-type detail comes from unverified attacker claims. The overstatement is moderate rather than severe because the underlying breach, the bounded access window and the national certificate rotation are all officially confirmed.
Self-interested vendor and government statements plus publicity-seeking claimants
Nearly every load-bearing statement comes from a party with a stake in the narrative: MyDr, a privately held vendor facing a data protection office inspection and explicit ministerial warnings of legal consequences, asserts its systems are safe and the cause is removed; ministers simultaneously reassure the public that the national P1 platform is secure while announcing precautionary certificate rotation; and people claiming responsibility for the intrusion approached a cybersecurity outlet with proof-of-breach material, including a politician's data, which is a publicity-driven channel. These incentives are visible in the supplied text rather than inferred.
Moderate: attributable and specific, but uncorroborated and still under investigation
Confidence is mid-range. The narrative spine — a confirmed vendor compromise, a bounded historical-data window, an active regulator inspection and a national certificate rotation — is stated by named officials and the company. But the cluster has one publisher, the scale figure and record types are unconfirmed, attribution is absent, and an ongoing inspection could materially revise the picture.
security
CareCloud's Breach Went From 350,000 to 3.7 Million, and the State Filings Still Say 350,0003 distinct publishers
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
security
The aim point was a peripheral: how US operators blinded Iran's air defenses1 distinct publisher
invest
NYDFS says a vendor's flaw reached its banks, and there is no regulator for the vendor1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 17, 2026