Reports from Poland indicate a massive data leak from the MyDr electronic healthcare system, which is used by about 12,000 medical institutions and clinics across the country. According to reports, over 2 terabytes of information may have been stolen from the system.

Polish Deputy Prime Minister and Minister of Digitalization, Krzysztof Gawkowski, stated that there are reportedly no signs of an external attack from other states yet. Polish law enforcement agencies and special services are investigating the case.
The stolen database contains about 19 million records. Approximately 3 million doctor visits are processed through the system monthly, so those affected could include both Polish citizens and foreigners who sought medical assistance.
The database may have contained:
- names and surnames;
- dates of birth;
- PESEL numbers;
- contact phone numbers;
- in some cases — medical information, including visit history, diagnoses, and prescribed medications.
Such data could be used by malicious actors for fraud or identity theft.
To further protect themselves, owners of a Polish PESEL number can block it. This can be done through the mObywatel state mobile application by selecting the "Zastrzeż PESEL" function. If necessary, for example before applying for a mortgage, the block can be temporarily removed.
It was also planned to upload the stolen database to the state system Safe Data, so that everyone could check if their data was among the information that fell into the hands of malicious actors. However, due to the large number of simultaneous visitors, the website temporarily stopped working.
Comments