The data breach from MyDr systems could affect up to millions of patients. The problem is particularly significant because the exposed information may include not only identifying information, such as PESEL numbers, but also health data, doctor visits, prescriptions, and medication information.
What should we do if we used a medical facility operated by MyDr?
1. Check your data on the website bezpieczdane.gov.pl
The basic tool for checking whether data has been included in the disclosed database is the government website bezpieczdane.gov.pl.
As of August 14, 2026, data related to the MyDr incident had not yet been added to this database. This means that the absence of a search result does not currently indicate that our data was not affected by the breach.
It is therefore worth checking again after the official announcement of the addition of data from the MyDr incident.
2. Check messages from your medical facility
If the breach may result in a high risk to the rights or freedoms of the patient, the facility acting as the data controller should inform the patient of the incident.
It is therefore worth paying attention to e-mails, text messages and correspondence sent by clinics and other medical facilities that we have used.
The lack of a MyDr account does not mean that our data is secure. MyDr provides IT systems to medical facilities, so the patient may not even be aware that their data was being processed using this software.
3. Ask the facility if the leak concerns your data
If we have any doubts, it is worth contacting the medical facility directly and asking:
- whether she used MyDr systems,
- whether our data was processed there,
- whether the facility has received information that our data has been affected by the incident,
- what specific categories of data may have been disclosed.
You can also exercise your right of access to data under Article 15 of the GDPR.
4. Restrict your PESEL number
If there is a risk that your PESEL number has been leaked, it is worth blocking it.
This can be done free of charge, among others, in the mObywatel application or website .
Blocking your PESEL number limits the risk of your data being used to obtain credit or loans, among other things. However, it does not prevent normal use of your PESEL number, such as when visiting a doctor, filling a prescription, or handling official matters.
5. Check who verified your PESEL number
In mObywatel you can also check the PESEL number verification history.
If a bank, lending company or other entity with which we have had no contact appears there, it is worth clarifying the situation immediately.
This may be a signal that someone has tried to use our data.
6. Beware of fake calls and messages
After major data breaches, the number of phishing attempts often increases.
Be especially careful of people who call or write claiming to be:
- medical facility,
- National Health Fund,
- bank,
- insurer,
- office,
- security department employee.
A criminal with our real data can use it to make the conversation credible.
Do not provide SMS codes, passwords, login details or install software indicated by the person contacting you by phone.
7. Change passwords and enable two-factor authentication
If you also use the same email address or password on other websites, it is worth changing your passwords.
Safest:
- use a different password for each account,
- use a password manager,
- enable two-factor authentication,
- do not use login links received in suspicious messages.
8. Keep documents about the spill
If we have received information from a facility that our data has been disclosed, it is worth keeping it.
You should also secure:
- suspicious text messages and emails,
- information about attempts to incur liabilities,
- correspondence with banks or branches,
- screenshots,
- information about unknown PESEL verifications.
Such materials may be of evidentiary significance if the data is used or we wish to assert our rights.
9. What to do if the data has already been used?
If someone has tried to take out a loan, enter into a contract or otherwise impersonate us using our details, we should act immediately.
In such a situation, it is worth:
- block the PESEL number,
- contact the bank or other institution where the attempt to use the data took place,
- secure documentation,
- consider notifying the police or prosecutor's office,
- report unauthorized use of data,
- in appropriate cases, consider filing a complaint with the President of the Personal Data Protection Office or pursuing civil claims.
Data leak – the most important actions
If you suspect that the MyDr leak may also affect you, first of all block your PESEL number, monitor bezpieczdane.gov.pl, check your PESEL verification history and be particularly careful with phone calls and messages using information about your health or doctor's visits.
In the case of such a widespread incident, the lack of suspicious activity immediately after the leak doesn't mean the data won't be used later. Therefore, it's worth protecting yourself before the first consequences arise. Organizations should be prepared for the new regulations – from audits, through implementation, to ongoing incident management.
This article is for informational purposes only and does not constitute legal advice.
The facts regarding the incident involving MyDr are based on media reports from August 12–13, 2026 and are subject to change.
Author:
