Poland is investigating a cyber incident at healthcare-software provider MyDr that authorities say may involve data connected to nearly 19 million people. The government has also begun replacing certificates used by medical systems to connect to the national P1 electronic-health platform, a precaution intended to protect the wider healthcare network rather than evidence that P1 itself was compromised.
The case has put unusually sensitive information at the center of a supplier breach: MyDr software is used by doctors, clinics and other providers, and its systems connect providers to the infrastructure behind electronic prescriptions and referrals. MyDr says it removed the cause of the incident, added security measures and remains operational. Investigators have not publicly identified an attacker, an intrusion method or the final scope of data accessed.
Large figure is not yet a count of affected people
The headline number needs careful reading. In an initial public account on August 12, Digital Affairs Minister Krzysztof Gawkowski said the incident could affect nearly 19 million people. Reporting by UNN said the minister described 19 million records as having been taken and put the volume above 2 terabytes.
A record total is not the same thing as a verified number of unique people. A healthcare-software environment can hold multiple entries for one person, historical records, administrative data and data associated with providers. Authorities have also said the unauthorized access involved historical data held in MyDr systems through April 2024 and may not involve every MyDr customer or patient.
That distinction is more than statistical housekeeping. It means the available information supports describing nearly 19 million as a potential exposure figure, not as proof that the personal data of 19 million distinct Polish residents was stolen. MyDr serves more than 12,000 medical facilities, according to authorities, which explains why an incident at one vendor can produce a national-scale estimate.
People claiming responsibility have separately asserted that they hold data on 18.8 million people and more than 2.5 terabytes of material. Those claims, reported by IT Nerd, have not been independently verified. The difference between the government’s reported volume and the alleged attackers’ larger figure is unresolved.
Possible health and identity data remain under review
Reports based on purported samples supplied by those claiming responsibility suggest that names, dates of birth, Polish identification numbers, prescription details and other medical information may be among the material accessed. But neither the authenticity of the samples nor the full set of affected data fields has been independently established.
MyDr has said it found no evidence that affected data had been published or otherwise made publicly available. That sits uneasily with reports that alleged attackers showed journalists limited evidence, but it does not establish that a complete dataset has been released. A purported sample, even if genuine, cannot by itself show the size, completeness or circulation of a stolen collection.
The cause is similarly unsettled. Gawkowski initially said there were no indications of an external attack and listed possibilities including human error, system failure, sabotage or negligence. By August 14, MyDr had characterized the event as external and intentional criminal activity, according to later reporting. The Record reported that the company said it had identified and removed the cause and was cooperating with authorities. Those accounts establish that the investigation evolved; they do not yet settle how access was gained.
Why Poland is rotating P1 certificates
MyDr’s connection to P1 raised a second operational concern. P1 is Poland’s nationwide electronic-health platform, supporting services including e-prescriptions and electronic referrals. Medical software connects to it using certificates, digital credentials that help a system establish that it is authorized to communicate with the platform.
The e-Health Center is replacing those connection certificates as a precaution. Officials said they had found no evidence that the certificates were stolen or misused, and Health Minister Jolanta Sobierańska-Grenda said P1 remained secure. Authorities also said the replacement should not interrupt patient-facing services such as prescriptions and referrals.
The action is therefore best understood as containment around a trusted connection, not as confirmation that a national platform was breached. Certificate replacement can limit risk if credentials might have been exposed in a vendor environment, while preserving the ability of authorized medical systems to reconnect under new credentials. It does not reveal whether the MyDr incident involved credentials at all.
Regulators and cybercrime investigators take up the case
Poland’s Personal Data Protection Office plans to inspect MyDr, while security agencies and the Central Bureau for Combating Cybercrime are seeking to identify those responsible. The inquiry will need to establish which systems were accessed, whether any data was removed, how many people can be linked to the records and whether affected providers or patients require further notification.
For now, the firmest points are narrower than the most dramatic claims: a major healthcare supplier suffered an incident affecting historical data; the possible scale is substantial but unfinalized; and Poland has protected a linked national-health connection despite saying the P1 platform is secure. The unanswered questions are precisely the ones that will determine the breach’s real impact.
