Major Cyberattack on Polish Healthcare Provider MyDr Exposes Data of 19 Million Individuals
Polish authorities are investigating a significant cyberattack on healthcare software provider **MyDr**, potentially compromising the data of nearly 19 million individuals and over 12,000 medical facilities. The incident has prompted a nationwide response, including proactive security measures to safeguard Poland's electronic health platform.
A cyberattack targeting **MyDr**, a privately-owned Polish company supplying software to doctors, clinics, and other healthcare providers, may have exposed sensitive data for a vast number of Polish citizens. The company disclosed last week that parts of its systems were affected by "external, intentional criminal activity."
**MyDr** announced on Friday that it had identified and remediated the cause of the incident, implementing additional security measures. However, specific details regarding the vulnerability exploited or the attackers' method of entry have not been disclosed.
### Scope of the Breach
Polish authorities confirmed that hackers gained unauthorized access to historical data within **MyDr** systems, spanning up to April 2024. While the full extent is still under investigation, it's believed that not all **MyDr** customers or their patients are affected. The company has stated that, as of now, there is no evidence the compromised data has been published or made publicly available.
**MyDr**'s software is integral to Poland's healthcare infrastructure, connecting providers to **P1**, the national electronic health platform that facilitates services like electronic prescriptions and referrals. The company also develops tools for managing medical practices and electronic medical records.
### Government Response and Proactive Measures
In response to the incident, Polish Digital Affairs Minister **Krzysztof Gawkowski** announced a precautionary measure: the country's e-Health Center is replacing digital certificates used by medical systems to connect to **P1**. This action aims to prevent potentially compromised certificates from being exploited, although authorities have found no evidence of their theft or misuse in the **MyDr** attack.
Health Minister **Jolanta SobieraΕska-Grenda** reassured the public that the incident does not threaten Poland's public healthcare systems and that **P1** remains secure. **MyDr** has also confirmed its systems are operational and safe for use by doctors and patients.
### Investigations Underway
The Polish Personal Data Protection Office plans to conduct an inspection of **MyDr**. Simultaneously, security agencies are actively working to identify the perpetrators of the attack. Minister **Gawkowski** warned that **MyDr** could face legal repercussions if the investigation reveals a failure to adhere to proper procedures or adequately protect its systems.
### Unverified Claims and Potential Data Types
Earlier this month, Polish cybersecurity publication **Zaufana Trzecia Strona** reported that individuals claiming responsibility for the intrusion had contacted them, providing what they asserted was evidence of the breach. This included a screenshot purportedly containing information belonging to a prominent Polish politician.
Claims and samples reported by Polish cybersecurity media suggest the stolen material could encompass names, dates of birth, identification numbers, specific prescription information, and other medical records. These claims, however, have not been independently verified.
### Broader Context of Cyberattacks in Poland
This incident follows closely on the heels of another significant cyberattack in Poland. Convenience store chain **Ε»abka** recently disclosed that attackers gained access to its internal systems via an account belonging to a third-party contractor. **Ε»abka** stated that its transactional systems, consumer services, mobile application data, and business operations remained unaffected. It is currently unclear whether the **MyDr** and **Ε»abka** incidents are connected.