RO EN
← Back to Blog The Cyberattack in Poland and the Medical Data of 19 Million People: What It Means for Data Protection

The Cyberattack in Poland and the Medical Data of 19 Million People: What It Means for Data Protection

Published on: 17.08.2026  ·  Views: 146

Imagine visiting a doctor, providing your personal information, receiving treatment and leaving the office.

For you, it is routine.

Behind the scenes, however, your information may be stored in software used by the medical practice:


Now imagine that the system storing that information is compromised.

This is no longer a theoretical scenario.

In August 2026, Polish authorities reported a major cyberattack involving MyDr, a software provider used by doctors and medical facilities.

According to official information, the incident may affect 18.8 million people and more than 12,000 medical facilities.

The scale is enormous.

But the number itself is not the most important part.

The real question for businesses is simple:

If your technology provider is attacked tomorrow, how prepared are you?

What Happened in the Cyberattack in Poland?

The incident involved MyDr, a provider of software used by medical professionals and healthcare facilities.

Authorities reported that attackers gained unauthorised access to historical data stored in the company’s systems.

Key facts include:


A crucial distinction:

This does not mean Poland’s entire healthcare system was breached.

The incident involved MyDr’s infrastructure and the data stored within it.

System availability and data confidentiality are not the same thing.

Why Medical Data Is Particularly Sensitive

A name or email address is personal data.

Health information is different.

Under Article 9 GDPR, data concerning health is classified as special category data, requiring enhanced protection.

The consequences of unauthorised disclosure can be severe:


An attacker who knows your name has one piece of information.

An attacker who knows your name, phone number, address, medical history and treatment details has a powerful tool for social engineering.

This is why protecting health data cannot be treated as a paperwork exercise.

The Problem Is Not Only the Attack — It Is Data Concentration

When a single incident can affect almost 19 million people, one question becomes obvious:

How did so much information end up in the same digital ecosystem?

The answer lies in modern digital infrastructure:


Each relationship introduces another layer of risk.

“The Data Is with Our Provider, So It’s Their Problem” — A Dangerous Assumption

Many organisations believe that responsibility shifts entirely to the provider.


“Our provider handles security. We have a GDPR contract.”

This is incorrect.

GDPR distinguishes between:


Processors have their own obligations.

But controllers remain responsible for choosing providers that offer sufficient guarantees.

Before signing a contract, businesses should understand:


A good data processing agreement matters.

But a contract does not secure a server.

What Real GDPR Compliance Looks Like

A serious GDPR programme begins with a basic question:

What personal data do we have, and what could happen if someone gained unauthorised access?


Where Is Your Data?

Personal data may exist in:


If you do not know where your data is, you cannot protect it.


Who Has Access?

Common issues include:


Depending on risk, organisations may need:


People should have access only to what they need — nothing more.

Security Is Not Just Antivirus Software

Article 32 GDPR requires appropriate technical and organisational measures.

Depending on context, these may include:

MeasurePurposeEncryptionReduce impact of unauthorised accessMFAStrengthen account securityBackupsEnable recovery after incidentsNetwork segmentationLimit attack propagationPatch managementReduce vulnerabilitiesLoggingSupport detection and investigationAccess controlsRestrict unnecessary accessRecovery testingEnsure backups actually work



GDPR does not prescribe a universal technology stack.

Controls must match the level of risk.

What Happens When a Data Breach Occurs?

Organisations often lose valuable time.

The first question should not be:


“Who is responsible?”

It should be:

“What happened, and what data may be affected?”

A practical incident‑response process includes:

detection → containment → investigation → identification → risk assessment → GDPR decision → notification → remediation → documentation

Under Article 33 GDPR, breaches likely to result in risk must be reported within 72 hours.

Under Article 34 GDPR, high‑risk breaches may require communication to affected individuals.

Not every incident must be reported.

Risk must be assessed first.

How Much Can a Data Breach Really Cost?

Fines are only one part of the picture.

ConsequencePotential ImpactRegulatory investigationInternal time and resourcesIncident responseTechnical and forensic costsOperational disruptionLost productivity and revenueCustomer notificationAdministrative and communication costsLitigationLegal expenses and claimsReputation damageLoss of customer trustInfrastructure recoveryUnplanned investment



And the hardest cost to measure:

Trust.

Customers want to know whether you took reasonable steps before the attack.

The Real Problem: GDPR Compliance on Paper

Some organisations still believe GDPR means:


Good — but insufficient.

If:


Then you have documentation, not compliance.

GDPR is built on accountability.

You must demonstrate that your measures exist and work.

What Should Businesses Check in 2026?

If several answers are “we don’t know”, you have identified a risk.

The Polish Attack Is Not Just About Poland

It is easy to dismiss the incident:

“It’s Poland.”

“It’s healthcare.”

“It’s a large provider.”

“We are a small business.”

But the mechanism is the same everywhere:


GDPR compliance is not a set of documents.

It is how an organisation controls and protects the personal data entrusted to it.

Security does not begin when the attack starts.

It begins long before.

Is Your Organisation Actually Prepared?

A serious GDPR assessment must go beyond checking documents.

It must examine:

Because the real question is not whether your company could be attacked.

The real question is: if the attack happens tomorrow, how prepared are you to protect the people whose data you hold?


Share: Facebook LinkedIn