Hackers claim to have stolen medical data of 18.8 million Poles from MyDr system
The perpetrators of the cyber attack claim to have obtained data on almost 19 million patients from the MyDr company system. Digitalisation Minister Gawkowski confirmed that the authorities are conducting intensive investigation activities.

Cyber attack on MyDr: authorities investigating possible data breach affecting millions of patients
Hackers claim to have stolen medical data of 18.8 million Polish men and women from the systems of MyDr – a supplier of software for managing electronic medical records (EMR). According to rynekzdrowia.pl, deputy prime minister and digitalisation minister Krzysztof Gawkowski confirmed that the relevant authorities are conducting intensive activities to establish the circumstances of the incident.
Gawkowski stated on the X platform that the authorities "have been informed of a cybersecurity incident that occurred in the systems and data of the MyDr company" and are actively supporting the company in the measures it is taking. He added that MyDr is continuously providing the authorities with verified information related to the matter.
Customers of the company – medical facilities and doctors – have been informed of the identification of potential unauthorised access to the systems.
The case was first described by the portal Zaufana Trzecia Strona, to which the alleged perpetrators of the attack came forward. To substantiate their activities, the hackers sent the service a screenshot containing data of one of Poland's leading politicians. The screenshot showed: full name, date of birth, PESEL number, telephone numbers and a prescription with a prescribed medication.
MyDr announced that it is investigating a serious security incident on its network.
Minister Gawkowski acknowledged that "at this stage of proceedings, it is not possible to definitively confirm a data breach, however, much suggests that an unauthorised person may have gained access to it". He assured that the public will be kept up to date on further steps.
Gawkowski reminded about basic cybersecurity hygiene principles: registering a PESEL number – for example through the mObywatel application – using strong passwords and two-factor authentication for login.
Source: Onet