THE QUICK TAKE
  • Poland's Ministry of Digital Affairs confirmed on August 12, 2026 that a breach of MyDr's systems exposed health data linked to nearly 19 million people — about half the country's population, according to PAP.
  • MyDr claims the incident was 'external, intentional criminal activity,' but Polish authorities initially said there was no confirmed evidence of an outside attack, leaving the cause officially unresolved.
  • Security analysts have compared this situation to the 2024 Change Healthcare breach in the U.S., noting a structurally similar single-vendor concentration risk, according to GovInfoSecurity.

What Folks Are Saying Happened

Well, butter my biscuit and call it a crisis — Poland's Ministry of Digital Affairs confirmed on August 12, 2026 that a breach of MyDr, one of the country's biggest electronic medical records software outfits, resulted in the theft of data tied to nearly 19 million Polish citizens, according to Poland's official state news agency PAP. That there figure amounts to roughly half of Poland's population of about 37.7 million souls, which is a heck of a lot of folks who didn't sign up to have their private business aired out.

Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski went on record calling this one of the largest incidents in Poland's history, as reported by PAP and corroborated across multiple independent outlets including Notes from Poland and Xinhua. The stolen haul reportedly includes prescriptions, national identity numbers known as PESEL numbers, phone numbers, and appointment records — the kind of personal medical details that'd make any reasonable person feel about as exposed as a catfish flopping on a dry riverbank.

What Is Actually Confirmed

Multiple independent, trustworthy sources — PAP, Xinhua, The Record from Recorded Future News, GovInfoSecurity, and Notes from Poland — all corroborate the core facts here. The breach touched data from over 12,000 medical facilities that use MyDr's software, according to PAP and GovInfoSecurity, though those facilities have kept right on operating without interruption, which is at least one small mercy in this whole mess.

The breach first came to light on August 10, 2026, when Polish cybersecurity publication Zaufana Trzecia Strona reported it, according to Cybernews and The Record. The attackers reportedly proved their access by sharing a prominent Polish politician's PESEL number, phone numbers, and prescription records with that outlet, as confirmed by Cybernews and Notes from Poland. That's about as brazen as walkin' into church with mud on your boots and daring the preacher to say something.

Deputy PM Gawkowski also confirmed, as reported by Xinhua and Cybernews, that as of August 13 the stolen data was not publicly available or being offered for sale, and that the breach appears financially motivated rather than politically driven. MyDr, for its part, says the company describes the affected data as likely dating from 2024 and earlier, according to The Record.

What Nobody Can Quite Pin Down

Here's where the story gets murkier than ditch water after a thunderstorm. MyDr claims the incident amounted to what the company describes as 'external, intentional criminal activity,' per The Record. But Polish authorities initially stated there was no confirmed evidence that this resulted from an outside attack at all — leaving open the possibility of human error, system failure, insider sabotage, or plain old negligence, according to The Record and PAP. Those two characterizations have not been publicly reconciled, and that gap is wider than a gap oughta be.

The data volume figures also wobble a bit depending on which source you're reading — some outlets cite more than 2 terabytes while attackers and others cite over 2.5 terabytes, and the forensic investigation has not locked that number down, according to reporting across multiple sources. On top of that, nobody has confirmed whether the 19 million records actually represent 19 million distinct individuals; authorities noted the records contain various fragments of information that may be linked to one another, meaning the true count of affected unique persons is still being worked out, per PAP. And no perpetrators have been identified publicly.

The GDPR Wrinkle: Who Has to Tell Patients

Now here's a legal knot that'd tie a squirrel's tail in a bow. Poland's data protection authority, known as UODO, has clarified that the duty to notify patients does not fall on MyDr itself — it lands squarely on the individual healthcare providers that use MyDr's software, according to a legal analysis published by Dudkowiak, a Polish legal and compliance firm. The reasoning is that under GDPR, the healthcare providers are the data controllers and MyDr is merely a processor, so the notification clock starts ticking for each clinic and hospital, not for the software vendor.

That means more than 12,000 medical facilities, confirmed across PAP and GovInfoSecurity, may each face their own compliance obligations. MyDr also says the company describes its platform as processing around 3 million medical visits monthly and issuing roughly 2.7 million prescriptions each month, per the company's own website. With that kind of volume flowing through one vendor's pipes, a whole lot of little operations just got handed a whole lot of homework.

Analysis: The Single-Vendor Concentration Problem

This next part is analysis, not settled reporting, so put on your thinking cap and take it as such. Security analysts quoted by GovInfoSecurity have drawn comparisons between the MyDr situation and the 2024 Change Healthcare breach in the United States, pointing to what they describe as a structurally similar single-vendor failure model — one provider sitting in the middle of a massive chunk of a country's healthcare data like the load-bearing post in a barn. One analyst noted, according to GovInfoSecurity, that the Change Healthcare incident affected roughly 57% of the U.S. population while the MyDr incident appears to have affected roughly half of Poland's.

The analysts' comparison — and this publication's read of it — is that when you funnel a nation's medical records through one software vendor's infrastructure, you are essentially betting the whole farm on that one fence holding. GovInfoSecurity also noted that the U.S. has spent over a decade building out HIPAA rules around what a business associate owes the providers it serves, including breach notification timelines, while Poland only brought its NIS2 national law implementation into force as recently as April 3 of this year. Whether Poland's emerging regulatory framework proves adequate to handle the aftermath here remains an open question worth watching.

What Comes Next

Polish authorities are investigating, and the breach remains an active matter as of the latest reporting from The Record dated August 15, 2026. Given that the perpetrators have not been identified, the attack method remains disputed, and the forensic scope is still being finalized, this situation is about as settled as a screen door in a windstorm. Folks in Poland who have visited a doctor — which, being roughly half the country's population, covers a right wide swath of humanity — would be wise to watch for unusual activity tied to their PESEL numbers and medical records.

Who is doing the hollering

These links show where the chatter came from. A link is attribution, not our endorsement or independent confirmation.

  1. Medical data of 19 million Poles stolen in major breach, minister saysPAP (Polish Press Agency) · primary
  2. Medical data linked to nearly 19 mln Poles leaked in cyberattackXinhua · top tier
  3. Poland probes MyDr healthcare software breach potentially affecting 19 million peopleThe Record from Recorded Future News · specialist
  4. Hack on Med Software Firm Hits Half of Poland's PopulationGovInfoSecurity / ISMG · specialist
  5. Poland hit by theft of 19 million patients' data from medical platformNotes From Poland · top tier
  6. European nation rocked by major hacker attack: 'largest data leak in history'Cybernews · specialist
  7. MyDr Data Breach: What Healthcare Providers Must Do NowDudkowiak (Polish legal/compliance blog) · specialist
  8. A massive data breach in Poland affected nearly 19 million peopleUNN (Ukrainian News Network) · top tier
  9. Hackers claim medical data breach affecting nearly 19 million people in PolandThe IT Nerd · specialist
Revision record

Last checked Aug 24, 2026, 9:07 AM EDT. Talk Around Town: The attack vector and identity of the perpetrators have not been established. Polish authorities initially said there was no confirmed evidence of an external cyberattack, while MyDr later described it as 'external, intentional criminal activity.' The exact scope — whether all 19 million records correspond to distinct individuals — remains under forensic investigation. The data may not cover all MyDr clients or patients.