Skip to content

Security1 publisher3 min readPublished

One vendor, 19 million patients: the MyDr breach is a lesson in whose perimeter matters

Polish authorities are investigating a compromise at clinical software supplier MyDr that may have exposed data on nearly 19 million people and more than 12,000 medical facilities.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying One vendor, 19 million patients: the MyDr breach is a lesson in whose perimeter matters
Generated illustration

What happened

  • Polish authorities are investigating a cyberattack targeting healthcare software provider MyDr that may have exposed data belonging to nearly 19 million people and more than 12,000 medical facilities.
  • MyDr is a privately owned Polish company that supplies software to doctors, clinics and other healthcare providers.
  • MyDr said on Friday it had identified and removed the cause of the incident and introduced additional security measures, and did not provide details about the vulnerability or how attackers gained access.
  • MyDr disclosed the previous week that parts of its systems had been affected by what it described as "external, intentional criminal activity."
  • Polish authorities said hackers obtained unauthorized access to historical data held in MyDr systems through April 2024, but that it may not involve all MyDr customers or their patients.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Polish authorities are investigating a cyberattack on MyDr, a privately owned Polish company that supplies software to doctors, clinics and other healthcare providers, in an incident that may have exposed data belonging to nearly 19 million people and more than 12,000 medical facilities [1][2]. The records sat in MyDr's systems, not in the clinics' own networks, which is the whole point: in healthcare the practical blast radius is the integrator's perimeter [1][5].

The arithmetic is worth stating plainly. Nearly 19 million people across more than 12,000 facilities works out to roughly 1,580 patients per facility [1]. No individual practice in that set could have been breached at anything like this scale on its own.

MyDr said on Friday that it had identified and removed the cause of the incident and added security measures, without describing the vulnerability or how the attackers got in [3]. The week before, it had characterised the event as "external, intentional criminal activity" [4]. Polish authorities say the attackers reached historical data held in MyDr systems through April 2024, and that not all MyDr customers or their patients are necessarily involved [5]. The company says it has found no evidence so far that the data has been published or otherwise made public [6].

The interesting remediation is not MyDr's. MyDr's software connects providers to P1, Poland's nationwide electronic health platform behind electronic prescriptions and referrals, and the company also builds practice management and electronic medical record tools [7]. Digital Affairs Minister Krzysztof Gawkowski said on Friday that the country's e-Health Center was replacing, as a precaution, the digital certificates that medical systems use to connect to P1 [8]. According to Gawkowski there is no evidence the certificates were stolen or misused; the rotation is meant to stop potentially compromised certificates being used later [9]. Officials said patients should not see disruption to prescriptions or referrals [10]. Read that as a state operator deciding it cannot verify what a private supplier lost, and rotating trust across an entire national ecosystem rather than waiting to find out.

The official line is that the state platform held. Health Minister Jolanta Sobieranska-Grenda said Monday that the incident posed no threat to Poland's public healthcare systems and that P1 remained secure [11], and MyDr has said its systems remain operational and safe for doctors and patients [12]. Both can be true while 19 million people's records are still at risk, because the exposure was never in P1.

On the contents, be careful. Poland's Personal Data Protection Office plans to inspect MyDr and security agencies are working to identify those responsible, Gawkowski said last week, adding that the company will face legal consequences if the investigation finds it failed to follow proper procedures or protect its systems [13][14]. No threat actor has been named [15]. Polish outlet Zaufana Trzecia Strona reported that people claiming responsibility contacted it with purported evidence, including a screenshot containing information on a prominent Polish politician [16], and claims and samples reported by Polish cybersecurity media suggest the material could include names, dates of birth, identification numbers, some prescription data and other medical records [17]. Those claims have not been independently verified [17].

What to watch: whether the data protection office's inspection produces findings on MyDr's controls [13], whether the certificate replacement completes without breaking clinic connectivity [8][10], and whether any of the claimed samples is verified [17]. Note also that convenience chain Zabka disclosed this month that attackers reached its internal systems through a third-party contractor account [18]. Two Polish incidents, both entering through someone else's access; no link between them has been established [19].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories