stethoscope
Image: Hush Naidoo Jade Photography via Unsplash

Poland probes MyDr healthcare software breach potentially affecting 19 million people

Polish authorities are investigating a cyberattack targeting healthcare software provider MyDr that may have exposed data belonging to nearly 19 million people and more than 12,000 medical facilities.

MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measures. It did not provide details about the vulnerability or how the attackers gained access.

The company disclosed last week that parts of its systems had been affected by what it described as "external, intentional criminal activity."

Polish authorities said hackers obtained unauthorized access to historical data held in MyDr systems through April 2024, but that it may not involve all MyDr customers or their patients. The company said it had found no evidence so far that the affected data had been published or otherwise made publicly available.

MyDr’s software connects healthcare providers to P1, Poland's nationwide electronic health platform, which supports services including electronic prescriptions and referrals. The company also develops tools for managing medical practices and electronic medical records.

Polish Digital Affairs Minister Krzysztof Gawkowski said on Friday that, as a precaution, the country's e-Health Center was replacing digital certificates used by medical systems to connect to P1.

Authorities have found no evidence that the certificates were stolen or misused in the MyDr attack, Gawkowski said. The measure is intended to prevent potentially compromised certificates from being used later to gain unauthorized access.

Officials said the replacement should not disrupt services for patients, including electronic prescriptions and referrals.

Health Minister Jolanta Sobierańska-Grenda said Monday that the incident did not pose a threat to Poland's public healthcare systems and that P1 remained secure.

MyDr has also confirmed that its systems remain operational and safe for doctors and patients.

Poland's Personal Data Protection Office plans to inspect MyDr, while security agencies are working to identify those responsible for the attack, Gawkowski said last week.

“If the investigation finds that the company failed to follow proper procedures or adequately protect its systems, it will face legal consequences,” he added.

The attack has not been attributed to a specific threat actor.

Earlier this month, Polish cybersecurity publication Zaufana Trzecia Strona reported that people claiming responsibility for the intrusion had contacted the outlet and provided what they said was evidence of the breach, including a screenshot containing information belonging to a prominent Polish politician.

Claims and samples reported by Polish cybersecurity media suggest that the stolen material could include names, dates of birth, identification numbers, certain prescription information and other medical records. Those claims have not been independently verified.

The breach comes shortly after another major Polish company disclosed a cyberattack. Convenience store chain Żabka said earlier this month that attackers gained access to internal company systems through an account belonging to a third-party contractor.

In a statement to Recorded Future News earlier this month, Żabka said its transactional systems, consumer services, mobile application data and business operations were not affected.

It is not clear whether the two incidents are connected.

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.