MyDr: Poland probes MyDr healthcare software breach potentially affecting 19 million people

MyDr: Poland probes MyDr healthcare software breach potentially affecting 19 million people

Polish Healthcare Software Provider MyDr Hit by Cyberattack Affecting Millions

Polish authorities are investigating a cyberattack on MyDr, a healthcare software provider, that may have exposed data belonging to nearly 19 million people and over 12,000 medical facilities. The company, which supplies software to doctors, clinics, and healthcare providers, confirmed on Friday that it had mitigated the incident and implemented additional security measures but did not disclose how attackers gained access.

The breach, described as "external, intentional criminal activity," involved unauthorized access to historical data stored in MyDr’s systems up to April 2024. While the company found no evidence that the stolen data had been published, Polish cybersecurity media reported that unidentified threat actors had contacted a local outlet, claiming responsibility and providing a screenshot of data linked to a prominent politician. The alleged stolen material may include names, dates of birth, identification numbers, prescription details, and medical records, though these claims remain unverified.

MyDr’s software integrates with Poland’s nationwide e-health platform (P1), which supports electronic prescriptions and referrals. As a precaution, the Polish e-Health Center is replacing digital certificates used by medical systems to connect to P1, though officials stated there was no evidence the certificates were compromised in the attack. Health Minister Jolanta Sobierańska-Grenda assured that the incident posed no threat to Poland’s public healthcare systems, and P1 remained secure.

The Polish Personal Data Protection Office plans to inspect MyDr, while security agencies work to identify the attackers. Digital Affairs Minister Krzysztof Gawkowski warned that the company could face legal consequences if found negligent in protecting its systems. The attack has not been attributed to any specific threat actor.

This incident follows another recent cyberattack on Polish convenience store chain Żabka, where attackers breached internal systems via a third-party contractor. No connection between the two incidents has been established.

Source: https://therecord.media/poland-probes-mydr-healthcare-software-breach

MyDr cybersecurity rating report: https://www.rankiteo.com/company/mydredm

"id": "MYD1786983836",
"linkid": "mydredm",
"type": "Cyber Attack",
"date": "4/2024",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Nearly 19 million people and '
                                              'over 12,000 medical facilities',
                        'industry': 'Healthcare',
                        'location': 'Poland',
                        'name': 'MyDr',
                        'type': 'Healthcare Software Provider'}],
 'data_breach': {'data_exfiltration': 'Unverified claims of data exfiltration',
                 'number_of_records_exposed': 'Nearly 19 million people',
                 'personally_identifiable_information': 'Names, dates of '
                                                        'birth, identification '
                                                        'numbers',
                 'sensitivity_of_data': 'High (PII, medical records)',
                 'type_of_data_compromised': 'Personal and medical data'},
 'date_publicly_disclosed': '2024-06-07',
 'description': 'Polish authorities are investigating a cyberattack on MyDr, a '
                'healthcare software provider, that may have exposed data '
                'belonging to nearly 19 million people and over 12,000 medical '
                'facilities. The breach involved unauthorized access to '
                'historical data stored in MyDr’s systems up to April 2024. '
                'The company confirmed mitigating the incident and '
                'implementing additional security measures but did not '
                'disclose how attackers gained access.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage to MyDr '
                                       'and Polish healthcare sector',
            'data_compromised': 'Names, dates of birth, identification '
                                'numbers, prescription details, medical '
                                'records',
            'identity_theft_risk': 'High',
            'legal_liabilities': 'Possible legal consequences if negligence is '
                                 'found',
            'operational_impact': 'Digital certificates for medical systems '
                                  'connecting to P1 replaced as precaution',
            'systems_affected': 'MyDr’s healthcare software systems, '
                                'integration with Poland’s e-health platform '
                                '(P1)'},
 'initial_access_broker': {'data_sold_on_dark_web': 'Unverified claims of data '
                                                    'being offered'},
 'investigation_status': 'Ongoing',
 'motivation': 'Criminal',
 'post_incident_analysis': {'corrective_actions': 'Replacement of digital '
                                                  'certificates, additional '
                                                  'security measures'},
 'references': [{'source': 'Polish cybersecurity media'}],
 'regulatory_compliance': {'legal_actions': 'Possible legal consequences if '
                                            'negligence is found',
                           'regulatory_notifications': 'Polish Personal Data '
                                                       'Protection Office '
                                                       'inspection planned'},
 'response': {'communication_strategy': 'Public disclosure, assurances from '
                                        'Health Minister',
              'containment_measures': 'Mitigated the incident, implemented '
                                      'additional security measures',
              'incident_response_plan_activated': 'Yes',
              'law_enforcement_notified': 'Yes (Polish authorities)',
              'remediation_measures': 'Replacement of digital certificates for '
                                      'medical systems connecting to P1'},
 'stakeholder_advisories': 'Health Minister assured no threat to public '
                           'healthcare systems; Digital Affairs Minister '
                           'warned of potential legal consequences',
 'title': 'Polish Healthcare Software Provider MyDr Hit by Cyberattack '
          'Affecting Millions',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.