Imagine visiting a doctor, providing your personal information, receiving treatment and leaving the office.
For you, it is routine.
Behind the scenes, however, your information may be stored in software used by the medical practice:
- your name,
- identification details,
- medical history,
- consultation notes, prescriptions and treatment information.
Now imagine that the system storing that information is compromised.
This is no longer a theoretical scenario.
In August 2026, Polish authorities reported a major cyberattack involving MyDr, a software provider used by doctors and medical facilities.
According to official information, the incident may affect 18.8 million people and more than 12,000 medical facilities.
The scale is enormous.
But the number itself is not the most important part.
The real question for businesses is simple:
If your technology provider is attacked tomorrow, how prepared are you?
What Happened in the Cyberattack in Poland?
The incident involved MyDr, a provider of software used by medical professionals and healthcare facilities.
Authorities reported that attackers gained unauthorised access to historical data stored in the company’s systems.
Key facts include:
- 18.8 million potentially affected individuals
- 12,000+ medical facilities
- data stored up to April 2024
- involvement of relevant Polish authorities
- no shutdown of ongoing medical services
A crucial distinction:
This does not mean Poland’s entire healthcare system was breached.
The incident involved MyDr’s infrastructure and the data stored within it.
System availability and data confidentiality are not the same thing.
Why Medical Data Is Particularly Sensitive
A name or email address is personal data.
Health information is different.
Under Article 9 GDPR, data concerning health is classified as special category data, requiring enhanced protection.
The consequences of unauthorised disclosure can be severe:
- discrimination
- social stigma
- privacy violations
- fraud
- targeted phishing
- blackmail
- reputational harm
- manipulation using highly personal information
An attacker who knows your name has one piece of information.
An attacker who knows your name, phone number, address, medical history and treatment details has a powerful tool for social engineering.
This is why protecting health data cannot be treated as a paperwork exercise.
The Problem Is Not Only the Attack — It Is Data Concentration
When a single incident can affect almost 19 million people, one question becomes obvious:
How did so much information end up in the same digital ecosystem?
The answer lies in modern digital infrastructure:
- healthcare providers rely on external platforms
- businesses use cloud services
- companies use CRM systems
- HR departments use SaaS applications
- accounting is outsourced
- backups are managed externally
- email is hosted by third parties
Each relationship introduces another layer of risk.
“The Data Is with Our Provider, So It’s Their Problem” — A Dangerous Assumption
Many organisations believe that responsibility shifts entirely to the provider.
“Our provider handles security. We have a GDPR contract.”
This is incorrect.
GDPR distinguishes between:
- controller
- processor
Processors have their own obligations.
But controllers remain responsible for choosing providers that offer sufficient guarantees.
Before signing a contract, businesses should understand:
- where data is stored
- who has access
- who has administrative access
- how authentication is protected
- how backups are secured
- how vulnerabilities are managed
- how incidents are detected
- how quickly they will be notified
- which subprocessors are involved
- what happens to data when the relationship ends
A good data processing agreement matters.
But a contract does not secure a server.
What Real GDPR Compliance Looks Like
A serious GDPR programme begins with a basic question:
What personal data do we have, and what could happen if someone gained unauthorised access?
Where Is Your Data?
Personal data may exist in:
- main databases
- email accounts
- Excel files
- shared folders
- employee laptops
- mobile devices
- cloud storage
- backups
- external platforms
- supplier systems
If you do not know where your data is, you cannot protect it.
Who Has Access?
Common issues include:
- active accounts of former employees
- departments with unnecessary access
- shared accounts
- unrestricted administrator access
Depending on risk, organisations may need:
- MFA
- individual accounts
- role‑based access control
- least privilege
- periodic access reviews
- privileged access management
- logging and monitoring
People should have access only to what they need — nothing more.
Security Is Not Just Antivirus Software
Article 32 GDPR requires appropriate technical and organisational measures.
Depending on context, these may include:
MeasurePurposeEncryptionReduce impact of unauthorised accessMFAStrengthen account securityBackupsEnable recovery after incidentsNetwork segmentationLimit attack propagationPatch managementReduce vulnerabilitiesLoggingSupport detection and investigationAccess controlsRestrict unnecessary accessRecovery testingEnsure backups actually work
GDPR does not prescribe a universal technology stack.
Controls must match the level of risk.
What Happens When a Data Breach Occurs?
Organisations often lose valuable time.
The first question should not be:
“Who is responsible?”
It should be:
“What happened, and what data may be affected?”
A practical incident‑response process includes:
detection → containment → investigation → identification → risk assessment → GDPR decision → notification → remediation → documentation
Under Article 33 GDPR, breaches likely to result in risk must be reported within 72 hours.
Under Article 34 GDPR, high‑risk breaches may require communication to affected individuals.
Not every incident must be reported.
Risk must be assessed first.
How Much Can a Data Breach Really Cost?
Fines are only one part of the picture.
ConsequencePotential ImpactRegulatory investigationInternal time and resourcesIncident responseTechnical and forensic costsOperational disruptionLost productivity and revenueCustomer notificationAdministrative and communication costsLitigationLegal expenses and claimsReputation damageLoss of customer trustInfrastructure recoveryUnplanned investment
And the hardest cost to measure:
Trust.
Customers want to know whether you took reasonable steps before the attack.
The Real Problem: GDPR Compliance on Paper
Some organisations still believe GDPR means:
- privacy policy
- records
- procedures
- contracts
Good — but insufficient.
If:
- access rights are not reviewed
- suppliers are not assessed
- backups are not tested
- employees do not know how to report incidents
- IT systems do not match documented procedures
Then you have documentation, not compliance.
GDPR is built on accountability.
You must demonstrate that your measures exist and work.
What Should Businesses Check in 2026?
- Do we know what personal data we hold?
- Do we know where it is stored?
- Do we know who can access it?
- Do we maintain an updated list of processors?
- Are our DPAs current?
- Do we assess vendors for security?
- Do we have a breach‑response procedure?
- Do we know who decides if an incident is reportable?
- Can we identify affected data quickly?
- Are backups protected and tested?
- Are access rights reviewed?
- Are employees trained?
- Are website and cookie mechanisms configured correctly?
- Does documentation match reality?
If several answers are “we don’t know”, you have identified a risk.
The Polish Attack Is Not Just About Poland
It is easy to dismiss the incident:
“It’s Poland.”
“It’s healthcare.”
“It’s a large provider.”
“We are a small business.”
But the mechanism is the same everywhere:
- data is collected
- data is stored
- data is shared
- third parties gain access
- employees use systems
- vulnerabilities exist somewhere in the chain
GDPR compliance is not a set of documents.
It is how an organisation controls and protects the personal data entrusted to it.
Security does not begin when the attack starts.
It begins long before.
Is Your Organisation Actually Prepared?
A serious GDPR assessment must go beyond checking documents.
It must examine:
- data flows
- processors
- access controls
- technical measures
- retention practices
- incident‑response procedures
- gaps between policy and reality
Because the real question is not whether your company could be attacked.
The real question is: if the attack happens tomorrow, how prepared are you to protect the people whose data you hold?