HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Polish Health Software Provider MyDr Breach Exposes Up to 19 Million Patient Records

MyDr, a Polish healthcare‑software vendor, suffered a cyber‑attack that gave attackers unauthorized access to historical data for up to 19 million patients and 12 000 medical facilities. The breach highlights the need for robust SOC 2‑aligned privacy controls, consent management and DSAR readiness.

LiveThreat™ Intelligence · 📅 August 18, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
therecord.media

Poland’s MyDr Healthcare Software Breach Potentially Exposes 19 Million Patient Records

What Happened — A cyber‑attack on MyDr, a Polish provider of electronic health‑record software, resulted in unauthorized access to historical patient data spanning up to 19 million individuals and more than 12 000 medical facilities. The breach was discovered in April 2024; MyDr removed the cause and is rotating digital certificates used to connect to the national e‑Health platform (P1).

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a failure to enforce SOC 2‑aligned access‑control and monitoring safeguards that protect PHI.
  • Continuous evidence of data‑handling policies, consent management, and DSAR readiness is essential to demonstrate compliance with GDPR/CCPA and to satisfy audit queries after a breach.

Who Is Affected — Public and private healthcare providers, clinics, and patients in Poland; broadly the health‑life sector.

Recommended Actions

  • Map the breach to SOC 2 Security and Privacy criteria (CC6.1, CC6.2) and collect logs as audit evidence.
  • Verify and document consent records, update DSAR processes, and ensure privacy notices reflect current data‑processing activities.
  • Rotate and re‑issue any digital certificates, enforce MFA for privileged accounts, and conduct a post‑incident risk assessment.

Technical Notes — The exact vulnerability or attack vector was not disclosed; authorities suspect “external, intentional criminal activity.” No evidence of data being publicly released. Replacement of digital certificates is a precautionary measure. Source: The Record

📰 Original Source
https://therecord.media/poland-probes-mydr-healthcare-software-breach

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →