Poland probes MyDr healthcare software breach potentially affecting 19 million people
Poland investigates a breach at healthcare software firm MyDr potentially exposing data of nearly 19 million people and over 12,000 medical facilities.
Polish healthcare software provider MyDr disclosed a cyberattack that may have exposed personal and medical data belonging to nearly 19 million people and more than 12,000 medical facilities. Hackers obtained unauthorized access to historical data held through April 2024, but the company has found no evidence the data has been published. As a precaution, Poland's e-Health Center is replacing digital certificates used by medical systems to connect to the national P1 e-health platform. The Personal Data Protection Office plans to inspect MyDr and security agencies are working to identify those responsible; no threat actor has been attributed.
- Unverified claims to Polish media suggest stolen data includes names, birth dates, ID numbers and prescription information.
- The e-Health Center is rotating digital certificates for P1 connections even though no certificate theft was found.
- Officials say P1 and Poland's public healthcare systems remain secure and operational.
- Separately, convenience chain Żabka disclosed an intrusion via a third-party contractor account; a connection to MyDr is unclear.
Full article570 words · extracted from therecord.media · click to collapse
Polish authorities are investigating a cyberattack targeting healthcare software provider MyDr that may have exposed data belonging to nearly 19 million people and more than 12,000 medical facilities. MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measures. It did not provide details about the vulnerability or how the attackers gained access. The company disclosed last week that parts of its systems had been affected by what it described as "external, intentional criminal activity." Polish authorities said hackers obtained unauthorized access to historical data held in MyDr systems through April 2024, but that it may not involve all MyDr customers or their patients. The company said it had found no evidence so far that the affected data had been published or otherwise made publicly available. MyDr’s software connects healthcare providers to P1, Poland's nationwide electronic health platform, which supports services including electronic prescriptions and referrals. The company also develops tools for managing medical practices and electronic medical records. Polish Digital Affairs Minister Krzysztof Gawkowski said on Friday that, as a precaution, the country's e-Health Center was replacing digital certificates used by medical systems to connect to P1. Authorities have found no evidence that the certificates were stolen or misused in the MyDr attack, Gawkowski said. The measure is intended to prevent potentially compromised certificates from being used later to gain unauthorized access. Officials said the replacement should not disrupt services for patients, including electronic prescriptions and referrals. Health Minister Jolanta Sobierańska-Grenda said Monday that the incident did not pose a threat to Poland's public healthcare systems and that P1 remained secure. MyDr has also confirmed that its systems remain operational and safe for doctors and patients. Poland's Personal Data Protection Office plans to inspect MyDr, while security agencies are working to identify those responsible for the attack, Gawkowski said last week. “If the investigation finds that the company failed to follow proper procedures or adequately protect its systems, it will face legal consequences,” he added. The attack has not been attributed to a specific threat actor. Earlier this month, Polish cybersecurity publication Zaufana Trzecia Strona reported that people claiming responsibility for the intrusion had contacted the outlet and provided what they said was evidence of the breach, including a screenshot containing information belonging to a prominent Polish politician. Claims and samples reported by Polish cybersecurity media suggest that the stolen material could include names, dates of birth, identification numbers, certain prescription information and other medical records. Those claims have not been independently verified. The breach comes shortly after another major Polish company disclosed a cyberattack. Convenience store chain Żabka said earlier this month that attackers gained access to internal company systems through an account belonging to a third-party contractor. In a statement to Recorded Future News earlier this month, Żabka said its transactional systems, consumer services, mobile application data and business operations were not affected. It is not clear whether the two incidents are connected.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/poland-probes-mydr-healthcare-software-breach