• Sources: primary, discussion
  • Summary: Digitisation Minister Krzysztof Gawkowski stated at a press conference on 2026-08-12, after an emergency meeting of the Joint Cybersecurity Operations Centre, that some 19 million records were stolen from over 12,000 healthcare facilities through MyDr, a provider of Poland's Electronic Medical Records system, and that the company confirmed the breach. He said the records contain personal information that can be linked to individual patients, that there is currently no evidence the incident resulted from an external cyberattack, and that there is no evidence pointing to an attack by a foreign state. The ministry states that day-to-day operations at healthcare providers, including prescription issuance, were not disrupted, and that authorities are moving the affected data into a dedicated database so individuals can check whether their information was exposed.
  • Why it matters: The record count is close to half the country's population and the compromised party is a shared records platform rather than one hospital, so the exposure follows from a single vendor integration rather than from any one facility's security posture.
  • Follow-up: Track publication of the intrusion vector and the timeline, which the account of the responsible minister does not carry.

send feedback on this story