Polish clinics face penalties after 19 million medical records leak from MyDr system
Translated from Polish, summarized and contextualized by DistantNews.
At a glance
- A data breach at MyDr, a medical documentation system provider, exposed approximately 19 million records and over 2 terabytes of data.
- Polish health facilities using the MyDr system, including clinics and independent practices, are responsible as data administrators and must assess the risk to patients.
- The head of Poland's data protection office (UODO) reminded these administrators of their obligation to notify affected patients about the breach, especially given the sensitive nature of health data and PESEL numbers.
A massive data breach at MyDr, a provider of medical documentation software, has potentially exposed the personal information of nearly 19 million Poles. The compromised data may include PESEL numbers, prescription details, medication information, and records of medical visits.
In connection with media reports regarding the leak of personal data of almost 19 million Poles from the provider of the MyDr Electronic Medical Documentation system, the President of UODO reminds data administrators who entrusted personal data processing to MyDr of the obligation to conduct an analysis of the risk of infringement of the rights or freedoms of natural persons, necessary to assess whether a personal data breach has occurred.
While MyDr is the processor of this data, the responsibility ultimately lies with the healthcare providers, clinics and individual doctors, who used the system. These entities are considered the data administrators and are now required by Poland's Office for the Protection of Personal Data (UODO) to conduct risk assessments. The UODO has emphasized that these administrators must inform their patients about the potential threat posed by the breach.
The obligation to notify individuals affected by the data leak rests with the administrators who used MyDr's services.
Experts highlight that the responsibility for data security does not transfer entirely to the software provider. Healthcare facilities must not only choose a reliable processor but also actively supervise them. Dr. hab. Dominik Lubasz, a professor at the University of ลรณdลบ, explained that clinics need to determine the extent of their data's involvement in the breach and then evaluate the risk to patients. Given the sensitive nature of health data and PESEL numbers, arguing a low risk is likely untenable. Failure to document risk assessments and oversight could lead to significant penalties, as seen in previous cases.
Essentially, entrusting data processing does not transfer responsibility to the provider. The clinic remains the administrator and is solely responsible for choosing the processing entity and supervising it.
Originally published by Rzeczpospolita in Polish. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.