3rd Party Risk Management
,
Data Breach Notification
,
Data Privacy
19M Patients Affected by Data Theft Including National ID Numbers
Marianne Kolbasuk McGee (HealthInfoSec) •
August 17, 2026

A hack on Polish electronic medical documentation software firm MyDr has affected nearly 19 million individuals in Poland, nearly half the country’s population, government officials estimate. (Image: MyDr)
A hack into IT systems of MyDr, a Polish provider of electronic medical documentation software, has affected more than 12,000 healthcare facilities and nearly 19 million people in Poland, about half the country’s population.
See Also: How Data-Centric Security Enables the Agentic Enterprise
Government authorities said they launched an investigation Aug. 12 into the alleged 2.5 terabyte data theft incident, in which cybercriminals appeared to have gained access into MyDr’s IT environment no later than Aug. 6.
Among other sensitive personal and health information, the incident compromised citizens’ PESEL numbers, which are akin to Social Security numbers in the United States – except the PESEL, a unique identifier for an individual’s lifetime, is used more extensively, including for everyday tasks such as rentals and utilities.
“Our investigation indicates that the data involved in the incident is likely historical, dating back to 2024 and earlier. We are continuing to verify the scope of the incident and will provide further information as the investigation progresses,” MyDr said in a statement.
Poland’s Central Bureau for Combating Cybercrime, which is investigating the incident, said an unidentified person obtained unauthorized access through the internet to all or part of the IT system administered by MyDr and information stored on servers that are part of the company’s infrastructure.
That included personal data of patients of healthcare entities that are MyDr clients. Besides patients’ PESEL numbers, affected information includes names, telephone numbers, e-mail addresses and data about health conditions, such as the content of notes from doctor’s visits or information on issued prescriptions.
MyDr in a statement provided to ISMG on Monday said that “as of now,” the company’s systems “are fully operational and secure to use for both patients and doctors.” Investigators are actively monitoring the darkweb and have confirmed that there is no evidence of any MyDr data having been published or publicly available, the statement said.
“We cannot confirm the amount and type of data that has been leaked. We will do it once the forensic investigation is over. At this stage, the full analysis of the incident’s root cause has not yet been completed,” the statement said.
“A detailed investigation is ongoing, including a forensic examination conducted by engaged external experts. Until these activities have been concluded, it would be premature to identify a specific cause of the incident or to determine which of the currently considered hypotheses is supported by the evidence gathered to date.”
Polish officials on Aug. 12 said they estimate the incident may have affected 18.8 million people and over 12,000 medical facilities. Poland’s 2026 total population is about 37.7 million. The incident under investigation is punishable by imprisonment for up to three years, Polish government officials said.
‘An Attractive Target’
MyDr says its flagship all-in-one platform, MyDr EDM, provides a suite of functionalities for the daily work of healthcare facilities, including an electronic health record, scheduling, electronic prescription, e-referral, e-sick leave modules and telemedicine. The software is fully integrated with the Polish government’s P1 Platform, which is the national electronic health system used to collect, analyze and share digital medical data across country.
“While MyDr EDM is not the official electronic health record for Poland, it has been widely adopted by much of the country’s population,” said Damon Small, a board member of security firm Xcape. “Because of the large number of records stored in this system, it is a treasure trove of sensitive information that can be used for extortion and identity theft,” he said.
While MyDr EDM supports multi-factor authentication, it’s not required, Small said.
“Users must manually enable that security feature,” Small said. “This, compounded with the fact that some 12,000 healthcare providers and 47,000 doctors’ offices use this system, making it an aggregation point for millions of Poles and an attractive target.”
Polish cybersecurity company Zaufana Trzecia Strona in an Aug. 10 blog post wrote that the alleged MyDr hackers reached out to the cyber firm claiming they gained access to MyDr’s IT environment via a “remote code execution through an XXE vulnerability in PKCS#12 certificate handling. This allowed the hackers to obtain the GitHub API key, where they in turn found the service’s source code. This allowed them to access the AWS infrastructure.” The security firm added that it has been able to independently verify the hackers’ claims.
But if those claims are true, “the entry bug is a fairly common attack chain these days, and much of this boils down to a very long-lived credential sitting where a compromised application could read it,” Denis Calderone, CTO of security firm Suzu Labs told ISMG.
While the threat actors have not been publicly identified, the incident does not yet appear to be politically motivated, Small said. “The breadth of data exfiltrated suggests opportunistic criminals that will likely use this data for identity theft or to sell to unscrupulous third-party buyers. That data commands a handsome price and can be leveraged for insurance fraud, for example,” he said.
Too Much Data on One Platform?
Some experts said the volume of data stolen and the incident’s impact to so many is especially concerning.
“This event proves that when a healthcare platform centralizes prescriptions, national ID numbers and appointment histories for tens of millions of people, the stakes of a compromise are extraordinary,” said Seemant Sehgal, CEO and founder, security firm BreachLock.
“The question becomes how can one platform come to hold that much sensitive data without adequate guardrails between it and the outside world,” Sehgal said.
“The scale of the reported data and the evidence of access raise serious questions about how long attackers may have been inside the environment and what signals could have been missed along the way,” he said.
Right now, the hack on MyDr in Poland is being compared to similarly large breaches in the U.S. affecting health information – including the 2024 ransomware and data theft incident involving UnitedHealth Group’s Change Healthcare IT services unit.
“Change affected 192.7 million people, close to 57% of the U.S. population, and the MyDr claim works out to roughly half of Poland’s,” Calderon said.
“Where the two countries diverge is regulatory maturity,” he said. “HIPAA has spent more than a decade defining what a business associate owes the providers it serves and putting a clock on breach notification, while Poland only implemented NIS2 into national law on April 3 of this year, and healthcare entities there don’t even have to register until October.”