A cyberattack on MyDr, medical scheduling software used by 12,000 Polish clinics, exposed close to 19 million PESEL numbers plus visit and prescription histories.
Why It Matters
MyDr is exactly the kind of vendor a small clinic, dental practice or wellness business runs on: one login, one shared database, no in-house security team watching it. The government confirmed the breach on 12 August and is telling every affected person to freeze their PESEL number through mObywatel. If your business hands client or patient data to a single specialist SaaS tool, this is what the failure mode looks like at scale.
What To Do About It
Ask every vendor who holds your clients' PESEL, health or ID data one question this week: what happens to that data if you get breached, and how fast do we hear about it. If the answer is vague, get it in writing or start pricing a replacement.
Related Signals
Sąd potwierdził karę prawie 52 tys.
31 Aug 2026Norweski regulator ochrony danych nakazał sieci siłowni SATS zaniechać obowiązkowego fotografowania klientów przy wejściu -- zdjęcie nie było warunkiem koniecznym umowy członkowskiej.
28 Aug 2026Wyciek z platformy MyDr ujawnił dane niemal 19 mln pacjentów -- kary grożą nie tylko dostawcy oprogramowania, ale każdej z około 12 tys.
28 Aug 2026