PrivacySignal
Healthcare

A serious incident occurred at MyDr, a Polish healthcare system provider

DataBreaches.net · · International · Healthcare Privacy

MyDr, one of Poland's largest healthcare system providers, is investigating a security breach after attackers claimed to have accessed patient data from multiple Polish clinics. The alleged hackers say they obtained nearly 18.8 million unique PESEL numbers, Poland's national identification numbers used across government and financial services.

Why this matters: A PESEL number is not like a password you can reset. It is a permanent national ID tied to your identity in Poland — used for healthcare, banking, taxes, and government services. Nearly 19 million of them potentially in criminal hands is a serious problem. People whose records were held by clinics using MyDr did not choose a tech vendor. They just went to the doctor. Now they may be exposed to fraud and identity theft with no real way to change the identifier that follows them everywhere.

Who should care: Healthcare professionals · Privacy officers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Healthcare
HIPAA Journal · · US Federal

Critical Vulnerabilities Identified in Popular Consumer Fertility Device

Security researchers have identified critical vulnerabilities in the Mira Hormone Monitor, a consumer fertility tracking device. The findings were reported by The HIPAA Journal, suggesting the flaws carry potential health data privacy implications.

Who should care: Healthcare professionals · Privacy officers · Compliance · Cybersecurity

#healthcare#surveillance#security Read original →
Healthcare
HIPAA Journal · · US Federal

Data Breaches Announced by Five Small Healthcare Organizations

Five small healthcare organizations have disclosed security incidents that exposed patient data, according to reporting by The HIPAA Journal. The organizations were not named in the excerpt beyond one partial reference, but all involve breaches of protected health information.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Data Breaches Reported by Sunshine Health; Health Payment Systems

Sunshine Health, a Florida-based Medicaid and health insurance agency, has reported a data breach involving the theft of protected health information following a vishing attack. Health Payment Systems has also disclosed a separate breach.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
Nextgov/FCW · · US Federal

Federal agencies quietly joined health data superhighway governing council

Federal agencies have quietly joined the governing council of TEFCA, a national health data exchange network that connects thousands of hospitals, clinics, and other medical providers. The move gives federal agencies a formal role in a system designed to move health records digitally across the country.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
EFF — Deeplinks · · International

Meta Must Stop Silencing Reproductive Health Information

The Electronic Frontier Foundation has filed a public comment with Meta's Oversight Board challenging the company's removal of posts about prescription medication, abortion care, and personal medical experiences on Instagram and other Meta platforms.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Data Breaches Announced by Loma Linda University Health & UCLA Health

Loma Linda University Health and UCLA Health have both disclosed data security incidents. Details of the scope, affected individuals, and nature of the breaches have not been specified in available reporting.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →