A cyberattack on MyDr, medical scheduling software used by 12,000 Polish clinics, exposed close to 19 million PESEL numbers plus visit and prescription histories.
Why It Matters
MyDr is exactly the kind of vendor a small clinic, dental practice or wellness business runs on: one login, one shared database, no in-house security team watching it. The government confirmed the breach on 12 August and is telling every affected person to freeze their PESEL number through mObywatel. If your business hands client or patient data to a single specialist SaaS tool, this is what the failure mode looks like at scale.
What To Do About It
Ask every vendor who holds your clients' PESEL, health or ID data one question this week: what happens to that data if you get breached, and how fast do we hear about it. If the answer is vague, get it in writing or start pricing a replacement.
Related Signals
Poland's data protection authority fined a door-to-door sales partner of Energa-Obrot for letting reps trade customer contract scans over personal WhatsApp with no oversight.
7 Aug 2026Germany's BSI set 31 July 2026 as a de facto NIS2 registration deadline, with only about 18,500 of an estimated 29,000 to 40,000 affected companies registered by late May.
28 Jul 2026
OpenAI reportedly lost 1.5 million subscribers in under 48 hours after agreeing to let the US Department of Defense use its AI models.
5 Mar 2026