Polish medical data breaches: Minister Gawkowski announces new regulations
A series of cyberattacks on Polish medical facilities has prompted the digitalisation minister to call for enhanced protective measures and announce mandatory certification requirements.

Further hacking attacks on Poland's medical sector
According to businessinsider.com.pl, Poland's medical sector is struggling with an intensifying wave of cyberattacks. Deputy Prime Minister and Minister of Digitalisation Krzysztof Gawkowski commented in a Saturday post on the X platform, appealing for enhanced security measures and announcing new regulations concerning the protection of patient data.
Series of breaches in a short timeframe
On Friday, Enel-med Medical Centre reported an IT security breach and data confidentiality incident. A day earlier, a similar incident was recorded at the Addiction and Psychiatric Treatment Centre in Inowrocław — the attack affected the system of Qbusoft, a producer of Medyc software for managing medical documentation. Among the stolen data could have been patients' PESEL numbers and contact information.
The largest breach occurred in August when MyDr was attacked. Hackers stole data on 19 million Poles, including information about medicines and prescriptions from 12,000 medical entities using the platform. All incidents were reported to the Central Bureau for Combating Cybercrime, and inspections were also announced by the president of the Personal Data Protection Office.
CSiRT guidelines and certification announcement
Gawkowski indicated that institutions responsible for the state's cybersecurity regularly provide guidelines regarding the protection of network infrastructure. On 16 September, the CSiRT CeZ (Cyber Security Incident Response Team of the eHealth Centre) developed appropriate recommendations for medical entities.
The document covers access control, multi-factor authentication, event logging and analysis, API security, backup protection, cryptography, key management, and monitoring of unusual operations on data. It is intended to support the assessment of security levels and the detection of system vulnerabilities.
The Ministry of Digitalisation is working on new regulations designed to strengthen the protection of patient information. The planned changes assume the introduction of mandatory certification and limits on the processing of medical data by private entities.
Minister: concealing attacks is the greatest mistake
Gawkowski appealed to all companies to report attacks to the appropriate CSiRT units and reminded them of free tools available at moje.cert.pl, made available by NASK.
"Concealing attacks by companies is the greatest mistake, because they always expose citizens to danger," the minister said. He added that attempts to protect reputation by concealing incidents result in even greater loss of trust.
"State services operate 24/7, pursuing every cybercriminal, and those caught will face criminal consequences," Gawkowski assured. "No one will escape responsibility," he added.
The Deputy Prime Minister emphasised that cybersecurity in healthcare requires cooperation between public institutions, medical entities, and technology providers.
Source: Google News PL