Skip to content
iOchronaSecurity Architect
PL
Security library

Digital security

Medical data breaches. What should you do and check?

A medical data breach can raise concerns about privacy, money and your family. Start by establishing what is actually known, then choose actions that fit your situation rather than trying to work through dozens of unrelated tips.

01

What is known about the MyDr incident

On 12 August 2026, Poland’s Ministry of Digital Affairs reported unauthorised access to historical information in the systems of medical software supplier MyDr. Its notice stated that the incident could affect 18.8 million people and more than 12,000 healthcare providers. This is a potential scale, not an identical set of exposed data for every individual.

The Warsaw District Prosecutor’s Office listed identification and contact details as well as information about health, appointments and prescriptions in its 13 August statement. On 12 August, the Ministry of Health stated that central e-health services had not been breached. Individual impact needs confirmation from the relevant data controller.

This article uses official notices checked on 11 September 2026. Their August publication dates matter: a later patient notification does not by itself indicate a new attack.

02

Does this mean my phone or email was accessed?

A breach at a separate provider does not establish that somebody signed in to your email or accessed your phone. Those are separate questions. An assessment should consider the notice and any unfamiliar sign-ins or changes on your accounts.

Exposed information can nevertheless help someone convincingly impersonate a clinic, bank or other institution. A caller knowing real details about you does not establish their identity.

03

Start by verifying the information

Read the clinic’s official notice. Contact it through a known channel found independently, rather than a link or number supplied in an unexpected message.

  • Establish which categories of your data were affected and what the controller recommends.
  • Keep the notification so you can refer to it later.
  • Do not share passwords or sign-in codes or approve operations you did not request.
  • Review activity on important accounts. Contact your bank promptly through an official channel if you notice an unauthorised transaction.

04

Restricting PESEL is one part of protection

Where your Polish PESEL identification number is involved, use the official restriction service, for example through mObywatel. Specified organisations check the register before certain activities.

Restriction does not erase information already obtained by an unauthorised person or replace account security. Treat it as part of the response rather than the end of the matter.

05

Passwords and account recovery need separate attention

Where a password was exposed, change it in that service and wherever it was reused. Use distinct passwords and additional sign-in verification for important accounts. Exposure of medical information alone does not prove that your email password leaked.

During the review I also examine less visible settings: recovery methods, active sessions, app permissions and document sharing. A password change is one possible action, not a replacement for assessing the situation.

06

What I can take care of for you

The Executive Digital Risk Review starts with your situation: what happened, which information concerns you and which accounts and devices you use. I assess the agreed scope and explain the findings in plain language.

I consider basic protection alongside details that are easy to overlook: email access, account recovery, preparation for a lost phone and file-sharing arrangements. You receive a report and priorities for seven and 30 days.

The review costs PLN 6,900 including VAT for private clients. Implementation has a separately agreed scope, responsibility and price. I handle the work personally; tasks requiring a different specialism have an agreed provider.

The aim is to reduce risk on your side and prepare a proportionate response. A review does not give control over a separate clinic’s systems or guarantee removal of stolen data. Reviewing a doctor’s or clinic owner’s personal accounts also differs from auditing the whole practice.

07

A few sentences are enough to start

Explain what concerns you and whether you have received an official notice. Leave passwords, codes, PESEL numbers and medical records out of the first message. We agree how to share any necessary information before work begins.

Initial qualification is free. I will explain whether a review, a shorter consultation or urgent contact with another organisation is appropriate. Paid work begins only after scope, timing and price are confirmed.

Decision

Which service fits the situation

Situation

You want to review account, phone and data security.

Useful first step: Executive Digital Risk Review

What you receive: Assessment of agreed areas and a report with seven- and 30-day priorities.

You have one notice and need to establish a first step.

Useful first step: A short description to iOchrona and initial qualification

What you receive: A proportionate proposal before commissioning a review.

An account takeover is ongoing or you see an unauthorised transaction.

Useful first step: Urgent contact with the account provider or bank; contact the police if you suspect a crime

What you receive: The appropriate response rather than waiting for a routine review.

Related services