Secretus logo

MyDr Cyberattack: 19 Million Records and the Cost of Permanent Copies

·9 min read

Polish authorities say attackers exfiltrated roughly 19 million records, totaling more than two terabytes, from MyDr, a major provider of electronic medical record software. The incident reaches far beyond one clinic: Poland's digital affairs minister said about 12,000 healthcare facilities used the software.

The confirmed scale makes this a national healthcare incident. It does not make every early claim about the stolen material true. The investigation is still defining the exact fields, access path and chronology, and those boundaries matter when people must decide what to protect next.

What is confirmed as of August 13

Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski said the stolen database contained information connected to nearly 19 million people and that MyDr had confirmed the loss of approximately 19 million records. He described more than two terabytes of exfiltrated data and said law enforcement, CERT Polska and Poland's data-protection authority were involved.

MyDr told the Polish Press Agency that its security, engineering and infrastructure teams, supported by external specialists, were investigating the nature, chronology and potential scope of unauthorized access. The company said it was cooperating with government institutions and could not yet publish further technical detail.

On August 13, Gawkowski added an important distinction: the stolen information was not visible in public circulation, offered for sale or being used in a public pressure campaign according to the authorities' monitoring at that time. Exfiltrated does not automatically mean publicly leaked, although the risk remains until the investigation and notification process are complete.

What the 19 million figure does not tell us

A record count is not necessarily a count of unique people, files or complete medical histories. Early reporting referenced PESEL identifiers and attackers reportedly used a public figure's identifying and prescription information as proof, but the public evidence reviewed here does not establish that every affected record contains the same fields.

The initial access method, dwell time, complete data schema and attribution remain unknown. It would therefore be premature to label the event ransomware, identify a specific group or claim that the full clinical history of every affected person was taken. Those may become answerable questions; they are not confirmed answers today.

Why medical context changes the risk

A password can be rotated. A PESEL number, diagnosis, prescription history or contact relationship with a clinic may remain useful to an attacker for years. Even partial records can make a fraudulent call credible: the caller can name the clinic, reference a real treatment context and request a payment, identity check or account recovery.

Polish officials advised people to reserve their PESEL, a control available through the mObywatel service or a municipal office. That is a concrete identity-fraud safeguard, but it does not prevent targeted phishing or erase medical information. People should use official clinic and government channels, not links or phone numbers supplied in an unexpected message about the incident.

For healthcare organizations: map the copies, not only the database

  1. Identify affected workflows. Determine which clinics, accounts, integrations and periods used MyDr, and preserve relevant logs and notices before making assumptions about exposure.
  2. Separate confirmed scope from provisional scope. Track what MyDr or authorities confirm, what your organization can prove locally and what remains an external claim. Do not turn a national record estimate into a local patient count.
  3. Inventory exported copies. Look beyond the primary platform to spreadsheets, email attachments, support tickets, shared drives, backups and local downloads. A secure system cannot expire copies exported into uncontrolled channels.
  4. Reset the recovery boundary. Review privileged accounts, active sessions, integration credentials, API keys and help-desk identity checks. Prioritize credentials that can reach multiple facilities or patient repositories.
  5. Prepare for impersonation. Give patients and staff one verified place for updates and state what the organization will never request by email, SMS or telephone.

Keep incident-room secrets out of the incident record

A large investigation creates a second copying problem. Teams exchange emergency administrator passwords, database credentials, recovery codes, forensic exports and identity documents under time pressure. Putting those materials into the same chat, ticket or email thread that coordinates the incident creates durable replicas and expands access far beyond the people who need the secret.

Keep operational context in the approved case system, but use a separate, verified and short-lived path for a credential or recovery value. Confirm the recipient through an independent channel, set the shortest practical expiry, record that a transfer happened without copying the plaintext into the audit trail, and revoke the value after the task.

Secretus can reduce plaintext copies during that narrow transfer. It cannot protect a compromised endpoint, replace a clinical-record system or make broad medical exports appropriate. Data minimization begins before encryption: do not send an entire patient file when a redacted excerpt or a reference number is sufficient.

A practical response checklist

  • Reserve the affected person's PESEL through an official Polish channel.
  • Verify MyDr and clinic notices directly; distrust unsolicited links and callers.
  • Review privileged identities, integrations and recovery paths tied to MyDr.
  • Remove patient data and secrets from incident chats once retention rules allow.
  • Use redacted evidence and time-limited transfers for external responders.
  • Update the scope when MyDr or Polish authorities publish confirmed details.

Clinical records have legal and operational retention requirements. The lesson is to stop every necessary record from generating five unnecessary copies, and to keep credentials and recovery material on a separate, revocable path.

Sources

Share a secret the safe way

Start a 14-day trial to send; recipients open one-time links without an account.

Try Secretus