01Summary
Digital Affairs Minister Krzysztof Gawkowski revealed on 12 August 2026 that data on nearly 19 million people had been stolen from MyDr, software used by about 12,000 doctors' practices and clinics. The more than 2 TB of data covers prescriptions, appointments, medication records and patient-submitted documents, with historical data up to April 2024. MyDr blamed "external, intentional criminal activity". Authorities also examined whether human error or negligence was involved. The company said it had removed the cause and added security measures.
02Victims and impact
Additional victims
- About 12,000 medical facilities using MyDr
Countries affected
- Poland
03Data exposed
Data types
- Prescriptions
- Medical appointments
- Medication records
- Patient-submitted documents
- Personal identifiers
04Timeline
- 2026-08-07MyDr discloses that parts of its systems were affected by criminal activity (week before the minister's statement).
- 2026-08-12Minister Gawkowski announces the scale: about 19 million people.
05Reaction and fallout
Political impact
Called one of the largest data leaks in Polish history.
06Disclosure and media
Publishing organisations
- The Record
- Notes From Poland
- PAP
- Cybernews
07Sources
References
- [1]The Record: https://therecord.media/poland-probes-mydr-healthcare-software-breach
- [2]Notes From Poland: https://notesfrompoland.com/2026/08/13/poland-hit-by-theft-of-19-million-patients-data-from-medical-platform/
- [3]PAP: https://www.pap.pl/en/news/medical-data-19-million-poles-stolen-major-breach-minister-says









