KG LEGAL \ INFO
BLOG

The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms

Publication date: September 07, 2026

What happened

On 10 August 2026, MyDr, one of Poland’s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million individuals and more than 12,000 healthcare facilities, and that the exfiltrated database exceeds 2 terabytes.

The attackers supplied the security portal Zaufana Trzecia Strona with a data sample suggesting that they hold PESEL numbers (Polish national identification numbers) and at least fragments of prescription information.

More

Act on the national cybersecurity certification system – for whom cybersecurity certificates will be needed.

Publication date: September 16, 2025

Cybersecurity certifications are designed for IT professionals, including system and network administrators, security specialists, engineers, and those aspiring to these roles, to validate their knowledge and practical skills in protecting against digital threats. The certification also covers ICT products, services, and processes, and aims to inform consumers about the level of digital security and support Polish companies in European markets.

More

New provisions on cybersecurity certification in Poland

Polish Act on the national cybersecurity certification system

Publication date: August 31, 2025

On August 28, 2025, the Polish Act of June 25, 2025, on the national cybersecurity certification scheme, entered into force, implementing Regulation (EU) 2019/881 of the European Parliament and of the Council of April 17, 2019, on ENISA (the European Union Agency for Cybersecurity) and cybersecurity certification in information and communication technologies and repealing Regulation (EU) No 526/2013 ( Cybersecurity Act ) (OJ L 151, 7.06.2019, p. 15 and OJ L 2025/37, 15.01.2025).

More

UP