Poland’s MyDr Healthcare Software Breach Potentially Exposes 19 Million Patient Records
What Happened — A cyber‑attack on MyDr, a Polish provider of electronic health‑record software, resulted in unauthorized access to historical patient data spanning up to 19 million individuals and more than 12 000 medical facilities. The breach was discovered in April 2024; MyDr removed the cause and is rotating digital certificates used to connect to the national e‑Health platform (P1).
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a failure to enforce SOC 2‑aligned access‑control and monitoring safeguards that protect PHI.
- Continuous evidence of data‑handling policies, consent management, and DSAR readiness is essential to demonstrate compliance with GDPR/CCPA and to satisfy audit queries after a breach.
Who Is Affected — Public and private healthcare providers, clinics, and patients in Poland; broadly the health‑life sector.
Recommended Actions
- Map the breach to SOC 2 Security and Privacy criteria (CC6.1, CC6.2) and collect logs as audit evidence.
- Verify and document consent records, update DSAR processes, and ensure privacy notices reflect current data‑processing activities.
- Rotate and re‑issue any digital certificates, enforce MFA for privileged accounts, and conduct a post‑incident risk assessment.
Technical Notes — The exact vulnerability or attack vector was not disclosed; authorities suspect “external, intentional criminal activity.” No evidence of data being publicly released. Replacement of digital certificates is a precautionary measure. Source: The Record