DistantNews
Support us
Data Theft from MyDr Database Affects 19 Million Poles
๐Ÿ‡ต๐Ÿ‡ฑ Poland /Crime & Justice

Data Theft from MyDr Database Affects 19 Million Poles

From Rzeczpospolita · () Polish

Translated from Polish, summarized and contextualized by DistantNews.

At a glance

News Named sources Outcome reported
  • Data from the MyDr platform, serving 10-12,000 clinics, was stolen, potentially affecting up to 19 million Poles.
  • The breach involves sensitive medical data, raising concerns about increased risks for individuals and businesses processing such information.
  • Experts warn that lessons from previous large-scale data leaks, like the ALAB medical labs incident, have not been learned, highlighting significant legal, reputational, and organizational risks for companies.

A massive data breach originating from the MyDr platform has potentially compromised the personal information of up to 19 million individuals in Poland, affecting approximately half the country's population. The stolen data originates from an estimated 10,000 to 12,000 clinics that utilize the MyDr system. While the full extent of the breach is still being assessed, the compromised data includes sensitive medical records, amplifying concerns for both individuals and the businesses that handle such information.

Mateusz Jankowski, a lawyer at Osborne Clarke, described the incident as one of the largest data leaks in Poland's history, particularly alarming due to the nature of medical data. He noted that such sensitive information can even be weaponized for political purposes, recalling an instance where a minister publicly revealed a doctor's prescription for psychotropic drugs. This breach follows a similar incident in 2023 where hackers stole data from over 50,000 individuals from the ALAB medical laboratories network.

Jankowski expressed concern that the short three-year interval between these major leaks indicates a failure to learn from past events. He stated that a repeat of such a large-scale breach so soon suggests that adequate lessons have not been absorbed. The MyDr platform is part of the DocPlanner group, which also operates the popular service Znany Lekarz. In 2023, DocPlanner reported collaborating with 47,000 doctors and serving 10-12,000 clinics, both commercial and those funded by the National Health Fund (NFZ).

The incident highlights the substantial losses data leaks can inflict on businesses. Jankowski outlined three primary risks for companies using such platforms: legal repercussions, reputational damage, and organizational disruption. While legal penalties might be the least concerning, the reputational damage is already significant, and many businesses historically neglected to prioritize data security when building systems. This large-scale breach serves as a stark example of the vulnerabilities and potential consequences.

Musimy tu mรณwiฤ‡ wล‚aล›nie o dwรณch pล‚aszczyznach. Przede wszystkim to jest pล‚aszczyzna przedsiฤ™biorcy i przedsiฤ™biorcรณw, ktรณrzy korzystali z tego rozwiฤ…zania MyDr, czyli de facto zewnฤ™trznego dostawcy IT. Moลผemy mรณwiฤ‡ o trzech ryzykach. Pierwsze, moim zdaniem, to jest najmniejsze zmartwienie tych przedsiฤ™biorcรณw, czyli ryzyko prawne, potencjalne kary administracyjne. Moim zdaniem ryzyko prawne nie jest wcale najpowaลผniejsze, bo moลผemy mรณwiฤ‡ jeszcze co najmniej o dwรณch: ryzyku wizerunkowym i organizacyjnym.

โ€” Mateusz JankowskiThe lawyer outlined the primary risks for businesses following the MyDr data breach, including legal, reputational, and organizational challenges.
DistantNews Editorial

Originally published by Rzeczpospolita in Polish. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.