Security Guides
MyDr Patient Data Breach in Poland (Up to 18.8 Million): PESEL, Health Data and Contacts Exposed — What Affected People Should Do
Patient data from before April 2024 was copied from MyDr's cloud, affecting up to 18.8 million people in Poland. How to check, reserve your PESEL and handle extortion.
For: anyone who has been treated at a healthcare facility in Poland (including foreign residents, past and present), and anyone who provides or uses cloud software for healthcare facilities. This article is based on statements from the Polish government, the data protection authority and MyDr itself, and does not cover attack techniques.
What people who may be affected should do today
Check at bezpiecznedane.gov.pl whether your PESEL is involved
Log in to the government checking site bezpiecznedane.gov.pl with mObywatel (the official government app), Profil Zaufany (the government e-ID login), an electronic ID card (e-dowód) or online banking. It tells you whether your PESEL is linked to this incident.
There is reportedly a queue when traffic is heavy. Type the address yourself, and do not open it from links in emails or text messages.
Reserve your PESEL, whether or not you are on the list
A PESEL reservation (zastrzeżenie PESEL) is a free procedure that marks your PESEL as reserved in a government register. Since June 1, 2024, banks, lenders, notaries, telecom operators issuing duplicate SIM cards and others must check this register before signing a contract.
According to the government, if a loan is granted despite the reservation, the person whose identity was used does not have to repay it. In the mObywatel app, choose "Services" and then "Reserve PESEL". When you need credit yourself, you can lift it temporarily in the app (there is a 30-minute wait between changes).
If you cannot use mObywatel, go to a municipal office
Foreigners who have a PESEL can use the same system. If you cannot log in to the mObywatel app or website, you can reserve your PESEL at any municipal office (urząd gminy).
mObywatel also shows which companies and institutions have checked your PESEL. Look at it now and then for checks you do not recognize.
Do not respond to messages that mention your health and demand payment
The items that may have leaked include health data and prescription information. So you may receive a message that shows knowledge of your illness or medication and demands payment, threatening to tell your family or employer.
Do not reply or pay. Keep screenshots and the messages, and report it to the police. Knowing your diagnosis does not prove that the sender's claims are true, and none of this is your fault.
Verify contacts from clinics, NFZ, the police or banks using numbers you looked up yourself
Polish police warn about contacts that impersonate healthcare facilities, banks or state institutions (including the police and the National Health Fund, NFZ) and use stolen medical data to extract more personal or financial details.
Even if it sounds genuine, hang up and call back on a number from the official website. Suspicious text messages can be forwarded to 8080, run by CERT Polska (Poland's national computer security incident team), and other suspicious contacts can be reported at incydent.cert.pl (see What is phishing?).
Change passwords for health portals and turn on two-step verification
The Ministry of Health and the police recommend changing passwords for medical portals and online health accounts, not reusing them, and turning on two-step verification (multi-factor authentication). If you use the same password elsewhere as on a MyDr patient account, change those too (Choosing a password manager).
For details, ask the healthcare facility you visited
Under the GDPR (the EU's data protection regulation), the healthcare facility is the controller of patient data and MyDr is the processor acting on its behalf. Official notices to patients come from the facility you visited. MyDr has sent facilities lists of affected patients and draft notices prepared in consultation with the authority.
Ask that facility which of your data was included. MyDr has also set up a dedicated contact point for the incident (see its patient page in the sources below).
What happened (from the government, authorities and MyDr)
MyDr sp. z o.o., based in Warsaw, provides MyDr EDM, electronic medical records software for doctors and healthcare facilities. It handles appointments, e-prescriptions, sick-leave certificates and referrals in the cloud. Everything below is as stated by the Ministry of Digital Affairs, the Ministry of Health, the Personal Data Protection Office (UODO) and MyDr.
Aug 10, 2026
MyDr disclosed a data incident affecting part of its systems and began investigating.Aug 12
MyDr confirmed it had been the target of a deliberate external criminal act. The Ministry of Digital Affairs said the company had confirmed unauthorized access to historical data (up to April 2024), potentially affecting up to 18.8 million people and more than 12,000 facilities. The Ministry of Health said central national e-health services were not compromised. UODO decided to inspect the company.Aug 14
The e-Health Centre (CeZ) said the certificates used to communicate with the national e-prescription system had not been compromised, and that it would replace them with MyDr as a precaution.Aug 24
MyDr's chief executive apologized and said the company would notify about 18 million people, deliberately including everyone whose data was in the affected environment.Aug 29
Affected PESEL numbers were added to bezpiecznedane.gov.pl, where people can check them.Sep 2
MyDr said what was copied was data from before April 12, 2024, plus data from cancelled electronic referrals for a limited number of people. It said no evidence of publication had been found.Sep 5–11
Notification of healthcare facilities proceeded in stages, with lists of affected patients, draft reports to the authority and draft notices to patients.
- Who
- Patients of healthcare facilities using MyDr. Mainly historical data from before April 12, 2024; for a limited number of people, also data in cancelled e-referrals issued after that date
- Items
- Name, address, contact details, PESEL (national identification number) and health data, social insurance information, employer details (where provided), other identifying data. The company says not every item applies to every patient
- What was copied
- The contents of a database stored in the company's cloud. Its patient page describes unauthorized access to backup databases and the taking of a backup dated April 12, 2024
- Publication
- The company says no evidence of publication has been found, and that appearing on bezpiecznedane.gov.pl does not mean the data was published online
- Not affected
- Central national e-health services (Ministry of Health). Access to care and prescriptions is unaffected. MyDr says its systems are operating normally
- Cause
- Not disclosed. The Central Cybercrime Bureau (CBZC) is investigating under prosecutorial supervision
- Authorities
- UODO is inspecting the company's technical and organizational measures and whether they were tested regularly. UODO says it had received about 1,000 breach notifications by the end of August
How to read it: 'no evidence of publication' does not mean 'safe'
MyDr says it has found no evidence that the data was published. That means nothing has been found so far, not that the data will never be used.
A PESEL encodes your date of birth and sex and, as a rule, does not change. Neither does your medical history. Plan your precautions in years. A PESEL reservation stays in place until you lift it.
Since August, other medical software vendors and healthcare companies in Poland have also disclosed unauthorized access, and UODO is reported to be stepping up inspections in the healthcare sector.
Why a breach at one software vendor spreads this far
One software vendor (MyDr)
Patient data for every customer facility, in the cloud
↓
Backup dated April 12, 2024
Data over two years old still holds patients' details
↓
12,000+ healthcare facilities
Each, as GDPR controller, reports to the authority and notifies patients
↓
Up to 18.8 million patients
PESEL, health data, contact details and more
In France, a breach disclosed in February 2026 exposed data on about 15 million patients through the MLM software for doctors (the Cegedim Santé patient data breach). It is the same pattern: when one cloud software vendor holds patient data for thousands of facilities, one weakness affects all of them at once.
Two things are specific to this case. First, what was copied was a backup more than two years old. Second, the national identification number and health data sat side by side in the same records.
Poland: PESEL
- Encodes date of birth and sex; as a rule, does not change
- Widely used by healthcare facilities to identify patients
- So medical records and PESEL sit in the same database
- As a countermeasure, a PESEL can be reserved in a national register
Japan: My Number
- Uses are limited by law (the My Number Act)
- Health-insurance checks with the My Number card use the card chip's electronic certificate, not the 12-digit number (Ministry of Health, Labour and Welfare)
- So clinic records are not designed to contain the My Number
- There is no national equivalent of the PESEL reservation
For readers in Japan, the lesson does not end at "the My Number never enters clinic records, so we are fine." Cloud-based electronic medical records are widely used in Japan too, and one vendor holding the patient lists, diagnoses, prescriptions and contact details of thousands of clinics is the same structure as in Poland.
If names, dates of birth, addresses and diagnoses leak, they can fuel health-related threats and identity fraud even without the My Number. Japan has no equivalent of the PESEL reservation, so the main defence against fraudulent contracts there is a fraud alert with the credit bureaus (steps in our article on the Times Car breach).
For those who provide or use cloud software for healthcare facilities
MyDr has not disclosed how the intrusion happened, so this section does not guess at the cause. It starts from the fact the company has published — that a backup database from April 2024 was copied — and lists checks any provider can make.
Make a list of backups and snapshots
List not only the production database but also backups, copies made during migrations and databases cloned for testing: where they are, how many there are and what point in time each holds.
Old backups also contain data on patients removed from production and patients of facilities that have left. A copy that is not on the list cannot be protected.
Protect backups to the same standard as production
Because backups are "only used for restores", their protection tends to be looser than production. Compare these three points with production:
- The number of accounts that can read them (separate from production operations accounts)
- The encryption keys (not stored in the same place as the backup)
- Read logging and alerts (does a bulk read trigger a notification?)
Set a retention limit for backups too
The legal retention period for medical records and the period needed to recover from an outage are different things. Decide how many generations you need for recovery, and make older generations delete automatically. Keep legally required records in a separate store with tighter access.
Facilities using such software: ask the vendor three questions
Under the GDPR, the healthcare facility is the controller of patient data. UODO has reminded controllers that even when a breach happens at a processor, they must report it within 72 hours. Before signing and at each renewal, ask:
- Where are the backups of our patient data, and how many years do they cover?
- If a breach happens, within how many hours, through which contact, and with what information (such as a list of affected patients) will we be told?
- If we cancel, by when will our data, including backups, be deleted?
This site's view: data you thought was deleted is still in the backups
When a patient moves to another clinic or a facility cancels the software, the data disappears from the screen. A backup from two years ago still holds those patients exactly as they were. That is why this incident is described as affecting "historical data up to April 2024".
As production gets better protected, backups remain as the weaker spot. A list of backups, retention limits and alerts on bulk reads are three things even a small provider can start today. The minimum baseline for organizations is covered in The minimum security baseline for organizations.
Sources (public record)
The facts in this article come from the public sources below. Figures and claims from those claiming the intrusion, and undisclosed causes, are not used.
- Poland, Ministry of Digital Affairs, "Komunikat po spotkaniu Połączonego Centrum Operacyjnego Cyberbezpieczeństwa" (August 12, 2026, Polish) — gov.pl
- Poland, Ministry of Health, "Informacja w związku z incydentem dotyczącym firmy MyDr" (August 12, 2026, Polish) — gov.pl
- e-Health Centre (CeZ), "Działania prewencyjne po incydencie dotyczącym firmy MyDr" (August 14, 2026, Polish) — cez.gov.pl
- MyDr, "Incydent MyDr" (timeline for facilities and the September 2 explanation, Polish) — pro.mydr.pl / patient page — pacjent.mydr.pl
- Personal Data Protection Office (UODO), "Administrator musi zgłosić wyciek, do którego doszło w podmiocie przetwarzającym" (August 12, 2026, Polish) — uodo.gov.pl / "Wyciek danych – co dalej?" — uodo.gov.pl
- UODO monthly bulletin, "Podsumowanie miesięcy: lipiec–sierpień 2026 r." (inspection and about 1,000 notifications, Polish) — nowybiuletyn.uodo.gov.pl
- Polish government, "Zastrzeż PESEL i zabezpiecz się przed oszustami. Nowe przepisy od 1 czerwca" (Polish) — gov.pl
- Świdnica County Police, "Komunikat dotyczący wycieku danych pacjentów z systemu informatycznego" (August 19, 2026, warnings about follow-on scams and where to report, Polish) — policja.gov.pl
- Notes from Poland, "Poland hit by theft of 19 million patients' data from medical platform" (August 13, 2026, news report) — notesfrompoland.com
- Japan, Ministry of Health, Labour and Welfare, on using the My Number card as a health insurance card (Japanese) — mhlw.go.jp
Update history
2026-10-03: First version, based on statements from the Ministry of Digital Affairs, the Ministry of Health, CeZ and UODO, and MyDr's timeline (up to September 11). The route of entry and cause have not been disclosed; this article will be updated if they are.
Read next
- The same pattern: the Cegedim Santé patient data breach (French doctors' software, about 15 million) / Aesto Health (US medical data archiving, 9.54 million)
- Healthcare incidents: US healthcare data breaches of 2026 / Hospitals knocked offline by cyberattacks in 2026
- Follow-on scams: What is phishing? / Choosing multi-factor authentication
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat was leaked in the MyDr incident?
According to MyDr's explanation of September 2, 2026, a third party copied the contents of a database stored in the company's cloud, covering data from before April 12, 2024. For a limited number of people, personal data in cancelled electronic referrals (e-skierowanie) issued after that date was also included. The items are name, address, contact details, PESEL (national identification number), health data, social insurance information, employer details (where provided) and other identifying data. The company says not every item applies to every patient.
QHow many people are affected?
Poland's Ministry of Digital Affairs announced on August 12, 2026 that up to 18.8 million people and more than 12,000 healthcare facilities may be affected. On August 24, MyDr said it would notify about 18 million people, deliberately including everyone whose data was in the affected environment as a precaution. Figures published by those claiming the intrusion are not used in this article.
QHow can I check whether I am affected?
Log in to the government site bezpiecznedane.gov.pl with mObywatel (the official government app), Profil Zaufany (the government e-ID login), an electronic ID card or online banking. It shows whether your PESEL is linked to this incident. It reportedly does not show which medical data was included, so ask the healthcare facility you visited for details. MyDr has sent facilities lists of affected patients and draft notices.
QWhat is a PESEL reservation (zastrzeżenie PESEL)?
It is a free procedure that marks your PESEL as reserved in a government register. Since June 1, 2024, banks, lenders, notaries, telecom operators issuing duplicate SIM cards and others must check this register before signing a contract. The government says that if a loan is granted despite a reserved PESEL, the person whose identity was used does not have to repay it. You can do it in the mObywatel app, on the mObywatel website or at any municipal office (urząd gminy), and you can lift it temporarily yourself.
QAre foreign residents of Poland affected too?
If you have a PESEL and have been treated at a healthcare facility in Poland (especially a private clinic using MyDr), you may be affected. The steps for checking and reserving your PESEL are the same as for Polish citizens. If you cannot use mObywatel, you can reserve your PESEL at a municipal office.
QWhat caused the breach?
As of October 3, 2026, the route and method of entry had not been disclosed. MyDr's patient page says it detected unauthorized access to backup databases and that a backup dated April 12, 2024 was obtained. The Central Cybercrime Bureau (CBZC) is investigating under prosecutorial supervision, and the Personal Data Protection Office (UODO) is inspecting the company.