MyDr: 19M health records exposed — third‑party risk hits Europe
Polish health software vendor MyDr suffered a breach disclosed August 12–13, 2026: nearly 19M people and over 12,000 facilities may be affected. Poland’s PM suggested extortion as the motive.
Summary — Poland’s Ministry of Health confirmed a security incident at MyDr, a vendor connected to the national P1 platform. Authorities cite up to 19 million people and over 12,000 facilities potentially impacted; the Prime Minister signaled an extortion attempt.
The facts
On August 12, 2026, Warsaw confirmed a breach at MyDr (e‑prescriptions and referrals via P1). Early assessments indicate sensitive medical data linked to nearly 19 million people across more than 12,000 healthcare entities may have been exfiltrated. On August 13, Prime Minister Donald Tusk said ransom appeared to be the motive. Media coverage underlined the unprecedented scale for Poland.
Legal framework
- GDPR — Security of processing (Art. 32), breach notification (Arts. 33–34), processor and joint‑controller governance (Arts. 28 and 26). See the overview of GDPR obligations for health data and the burden of proof during incidents.
- NIS 2 — Critical digital providers and healthcare entities must manage risks, notify within 24 h/72 h/final report, and undergo national oversight. For context, consult the NIS 2 directive and its requirements.
- Case law — The CJEU (C‑340/21) stresses logging and the ability to investigate/notify as key to demonstrating adequacy of measures.
What this means for Luxembourg companies
- Supply‑chain risk — A single “background” SaaS vendor can massively expose patients/customers across jurisdictions at once. Luxembourg actors in healthcare, insurance, occupational health, and any Art. 9 processing are directly exposed.
- Notification timelines — CNPD notification within 72 h applies to controllers even when incidents occur at foreign processors. NIS 2 entities must also notify the ILR (24 h/72 h/1 month).
- Tangible risks — Data‑leak blackmail, reimbursement fraud, medical e‑prescription impersonation, targeted extortion of high‑risk profiles, and cross‑border disputes.
Concrete actions to take this week
- Map and re‑qualify critical vendors — EHR/ERP, telemedicine, TPAs/insurers, OH systems. Update inventories and records (GDPR Art. 30).
- Demand dated evidence — Latest pentests, audits, secret/API key rotation, prod/test separation, strong IAM (phishing‑resistant MFA, least privilege), logging actionable within 24/72 h.
- Pre‑draft notifications — CNPD (72 h) and ILR (24 h/72 h/1 month) templates, client messaging, 24/7 contacts, ability to isolate a compromised SaaS. A certified DPO mandate can streamline governance and coordination.
- Monitor for leaks — Deploy dark‑web monitoring for your domains and those of critical suppliers, with a legal playbook for controlled IOC/sample acquisition.
- Contract “NIS 2 + GDPR” clauses — 24 h notification, forensics assistance, on‑site/desk audits, right to sponsor security tests, sub‑processor inventory, EU hosting, documented at‑rest/in‑transit encryption.
- Run a “vendor breach – healthcare” exercise — 2‑hour tabletop (DPO, CISO, IT, business, comms) to decide within 6 h on CNPD/ILR notifications.
Sources
- The Record — Poland probes MyDr healthcare software breach potentially affecting 19 million people.
- TVP World — Ransom likely motive in mass breach of Polish medical data: PM.
- Anadolu Agency — Medical records of nearly 19M Poles leaked in major cyber breach.
- Deutschlandfunk — Mehr als 19 Millionen Bürger von Cyberangriff betroffen.
Need operational and regulatory support? Reach out via our contact page.
Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →